Bypassing IOMMU Protection against I/O Attacks

Bypassing IOMMU Protection against I/O Attacks
复制标题

绕过 IOMMU 针对 I/O 攻击的保护

DOI:
10.1109/ladc.2016.31
复制
发表时间:
2016
期刊:
2016 Seventh Latin-American Symposium on Dependable Computing (LADC)
影响因子:
--
通讯作者:
M. Kaâniche
M. Kaâniche
中科院分区:
--
文献类型:
--
作者:
Benoît Morgan;E. Alata;V. Nicomette;M. Kaâniche

文献摘要

被引文献

相似文献

针对计算机系统的攻击变得越来越复杂和各种。其中一些是所谓的I/O攻击,是由恶意外围设备执行的,这些外围设备通过DMA(Direct Memory Access)请求使读取或写入DRAM内存或嵌入其他外围设备中的内存。存在某些面对这些攻击的保护机制,并且已经在现代建筑中实施了几年。一个典型的例子是英特尔提出的IOMMU。但是,这种机制不一定是由固件和操作系统正确配置和使用的。这篇实验论文描述了我们在Intel Iommu Linux驱动程序对Iommu的配置中发现的设计弱点,以及可能允许恶意外围的剥削场景,可以绕过潜在的保护机制。基于Intel规格和Linux源代码分析,使用PCI Express外围FPGA实现了剥削方案。
Attacks targeting computer systems become more and more complex and various. Some of them, so-called I/O attacks, are performed by malicious peripherals that make read or write accesses to DRAM memory or to memory embedded in other peripherals, through DMA (Direct Memory Access) requests. Some protection mechanisms to face these attacks exist and have been implemented for several years now in modern architectures. A typical example is the IOMMU proposed by Intel. However, such mechanisms are not necessarily properly configured and used by the firmware and the operating system. This experimental paper describes a design weakness that we discovered in the configuration of an IOMMU by the Intel IOMMU Linux driver and a possible exploitation scenario that would allow a malicious peripheral to bypass the underlying protection mechanism. The exploitation scenario is implemented with a PCI Express peripheral FPGA, based on Intel specifications and Linux source code analysis.