Run-DMA
Run-DMA
复制标题
DOI:
--
复制
发表时间:
2015-08
期刊:
影响因子:
--
通讯作者:
M. Rushanan;Stephen Checkoway
中科院分区:
文献类型:
--
作者:
M. Rushanan;Stephen Checkoway
Copying data from devices into main memory is a computationally-trivial, yet time-intensive, task. In order to free the CPU to perform more interesting work, computers use direct memory access (DMA) engines -- a special-purpose piece of hardware -- to transfer data into and out of main memory. We show that the ability to chain together such memory transfers, as provided by commodity hardware, is sufficient to perform arbitrary computation. Further, when hardware peripherals can be accessed via memory-mapped I/O, they are accessible to "DMA programs." To demonstrate malicious behavior, we build a proof-of-concept DMA rootkit that modifies kernel objects in memory to perform privilege escalation for target processes.