Cache-in-the-Middle (CITM) Attacks: Manipulating Sensitive Data in Isolated Execution Environments

Cache-in-the-Middle (CITM) Attacks: Manipulating Sensitive Data in Isolated Execution Environments
复制标题

DOI:
10.1145/3372297.3417886
复制
发表时间:
2020-10
期刊:
Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Jie Wang;Kun Sun;Lingguang Lei;Shengye Wan;Yuewu Wang;Jiwu Jing
Jie Wang;Kun Sun;Lingguang Lei;Shengye Wan;Yuewu Wang;Jiwu Jing
中科院分区:
其他
文献类型:
--
作者:
Jie Wang;Kun Sun;Lingguang Lei;Shengye Wan;Yuewu Wang;Jiwu Jing

文献摘要

相似文献

ARM TrustZone的传统用法在解决制造商和第三方应用开发者之间的冲突方面存在困难。制造商希望通过限制在安全世界中安装第三方应用来最小化可信计算基,而第三方应用开发者则更倾向于拥有将其应用安装到安全世界的自由。为了解决这个问题,研究人员提议在普通世界中创建隔离执行环境(称为IEE)以保护对安全敏感的应用。在本文中,我们对IEE数据保护模型和ARM缓存属性进行了系统研究,并发现了三种基于缓存的攻击(称为CITM),可利用这些攻击来操纵在IEE中受保护的敏感数据。具体而言,由于对映射到IEE内存(即指定给IEE的内存)的缓存的安全措施低效且不一致,普通世界中的攻击者可能会在并发执行期间通过操纵IEE内存、在安全敏感应用暂停或结束时绕过强制实施的安全措施,或者在IEE的上下文切换过程中滥用不完整的安全措施,从而危及IEE数据的安全。我们对包括SANCTUARY、Ginseng和TrustICE在内的三个著名的IEE系统进行了CITM攻击的案例研究,以说明在实际硬件测试平台上利用这些攻击的可行性。最后,我们分析了CITM攻击的根本原因,并提出了一种应对措施来抵御它们。实验结果表明我们的防御方案开销较小。
The traditional usage of ARM TrustZone has difficulty on solving the conflicts between the manufacturers that want to minimize the trusted computing base by constraining the installation of third-party applications in the secure world and the third-party application developers who prefer to have the freedom of installing their applications into the secure world. To address this issue, researchers propose to create Isolated Execution Environments (called IEEs) in the normal world to protect the security-sensitive applications. In this paper, we perform a systematic study on the IEE data protection models and the ARM cache attributes, and discover three cache-based attacks called CITM that can be leveraged to manipulate the sensitive data protected in IEEs. Specifically, due to the inefficient and incoherent security measures on the cache that maps to the IEE memory (i.e., memory designated for IEEs), attackers in the normal world may compromise the security of IEE data by manipulating the IEE memory during concurrent execution, bypassing the security measures enforced when a security-sensitive application is suspended or finished, or misusing the incomplete security measures during IEE's context switching processes. We conduct case studies of CITM attacks on three well-known IEE systems including SANCTUARY, Ginseng, and TrustICE to illustrate the feasibility to exploit them on real hardware testbeds. Finally, we analyze the root causes of the CITM attacks and propose a countermeasure to defeat them. The experimental results show that our defense scheme has a small overhead.