Hardware-Assisted Transparent Tracing and Debugging on ARM

Hardware-Assisted Transparent Tracing and Debugging on ARM
复制标题

DOI:
10.1109/tifs.2018.2883027
复制
发表时间:
2019-06
影响因子:
6.8
通讯作者:
Zhenyu Ning;Fengwei Zhang
Zhenyu Ning;Fengwei Zhang
中科院分区:
计算机科学1区
文献类型:
--
作者:
Zhenyu Ning;Fengwei Zhang

文献摘要

被引文献

相似文献

现有的恶意软件分析平台留下可检测到的指纹,例如QEMU中的不常见字符串属性,Android Java虚拟机中的签名以及Linux内核配置文件中的伪像。由于这些指纹为恶意软件提供了根据分析系统是否存在分裂其行为的机会,因此现有的分析系统不足以分析复杂的恶意软件。在本文中,我们提出了Ninja,这是一个透明的恶意软件分析框架,在ARM平台上具有低伪像。忍者利用硬件辅助隔离的执行环境信任度带来透明地跟踪和调试目标应用程序,并在绩效监视器单元和嵌入式跟踪麦克罗尔(Trace MacRocell)的帮助下进行调试。这些硬件功能可帮助忍者达到透明度,同时避免高度的开销。 Ninja不会修改系统软件,并且在ARM平台上具有OS-AGNOSTIC。我们实施了忍者的原型(即跟踪和调试子系统),实验结果表明,忍者在恶意软件分析中具有有效且透明。改进的快速系统恢复机制也旨在促进连续的恶意软件分析。
The existing malware analysis platforms leave detectable fingerprints such as uncommon string properties in QEMU, signatures in Android Java virtual machine, and artifacts in Linux kernel profiles. Since these fingerprints provide the malware a chance to split its behavior depending on whether the analysis system is present or not, the existing analysis systems are not sufficient to analyze the sophisticated malware. In this paper, we propose NINJA, a transparent malware analysis framework on the ARM platform with low artifacts. NINJA leverages a hardware-assisted isolated execution environment TrustZone to transparently trace and debug a target application with the help of performance monitor unit and embedded trace macrocell. These hardware features help NINJA to achieve transparency while avoiding heavy performance overhead. NINJA does not modify system software and is OS-agnostic on the ARM platform. We implement a prototype of NINJA (i.e., tracing and debugging subsystems), and the experimental results show that NINJA is efficient and transparent for malware analysis. An improved fast system restoration mechanism is also designed to facilitate the continuous malware analysis.