arrow
Return

Bypassing software-based remote attestation using debug registers

delete2024-01-25
delete0
delete
OA
AI
Z
Zhang, Zheng
J
Jingfeng Xue
T
Tianshi Mu
K
Kefan Qiu
T
Tian Chen
李元章 cover
李元章 (Yuanzhang Li) *
DOI:10.1080/09540091.2024.2306965delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Remote attestation (RA) is an essential feature in many security protocols to verify the memory integrity of remote embedded devices susceptible to malware infections. The attestation process needs to be consecutive and atomic to prevent a self-relocating malware from evading detection. Most of the prior attestation techniques disable interrupts during execution to prevent another process from interrupting the integrity check. This paper investigates the shortcomings of existing software-based attestation techniques and stresses the threat of debug exceptions to existing software-based attestation. We present Debug Register-based Self-relocating Attack (DRSA), a novel self-relocating malware against software-based attestation based on debug registers. DRSA gains control of the checksum function by raising debug exceptions and erasing itself before the next attestation. We further implement DRSA on commodity OSes and validate its effectiveness based on two existing software-based proposals. Our evaluation demonstrates that DRSA incurs low overhead, and it is extremely difficult for the verifier to detect it. can bypass the attestation with very little attack overhead.
Keywords:
Remote attestation
debug exceptions
indisputable code execution
self-relocating malware

Journal

Connection Science cover
Connection Science
IF:
3.4
Papers:
843
Citations:
1.5K

Organization

B
beijing institute of technology
Scholars:
5.4W
Papers: 3.9W
Citations: 63