arrow
返回

CATTmew: Defeating Software-Only Physical Kernel Isolation

delete2021-07-01
delete6
delete
OA
AI
Y
Yueqiang Cheng
Z
Zhi Zhang *
‪
‪Surya Nepal‬
W
Wang, Zhi
DOI:10.1109/TDSC.2019.2946816delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
All the state-of-the-art rowhammer attacks can break the MMU-enforced inter-domain isolation because the physical memory owned by each domain is adjacent to each other. To mitigate these attacks, physical domain isolation, introduced by CATT [7] , physically separates each domain by dividing the physical memory into multiple partitions and keeping each partition occupied by only one domain. CATT implemented physical kernel isolation as the first generic and practical software-only defense to protect kernel from being rowhammered as kernel is one of the most appealing targets. In this paper, we develop a novel exploit that could effectively defeat the CATT implementation and gain both root and kernel privileges, indicating that the physical kernel isolation is not secure in practice. Our exploit can work without exhausting the page cache or the system memory, or relying on the information of the virtual-to-physical address mapping. The exploit is motivated by our key observation that the modern OSes have double-owned kernel buffers (e.g., video buffers and SCSI Generic buffers) owned concurrently by the kernel and user domains. The existence of such buffers invalidates the physical separation enforced by CATT and makes the rowhammer-based attack possible again. Existing conspicuous rowhammer attacks achieving the root/kernel privilege escalation exhaust the page cache or even the whole system memory. Instead, we propose a new technique, named Memory Ambush. It is able to place the hammerable double-owned kernel buffers physically adjacent to the target objects (e.g., page tables) with only a small amount of memory. As a result, our exploit is stealthier and has fewer memory footprints. We also replace the inefficient rowhammer algorithm that blindly picks up addresses to hammer with an efficient one. Our algorithm selects suitable addresses based on an existing timing channel [31] . We implement our exploit on the Linux kernel version 4.10.0. Our experiment results indicate that a successful attack could be done within 1 minute. The occupied memory is as low as 88 MB.
Keyword:
Kernel
Memory management
Random access memory
Memory modules
Linux
Data structures
Streaming media
Rowhammer
physical domain isolation
physical kernel isolation
double-owned buffer
memory ambush
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

IEEE Transactions on Dependable and Secure Computing 封面图
IEEE Transactions on Dependable and Secure Computing
IF:
7.5
论文数:
2.5K
被引数:
9.6K

机构

F
Florida State University
学者数:
1.1W
论文数: 8.6K
被引数: 2.0W
C
引用论文

引用论文

Variation in the Vernalization Response of a Geographically Diverse Collection of Timothy Genotypes
err2011-11-01
err0
PREAI
errAlice Fiil; Louise Bach Jensen; Siri Fjellheim; Thomas Lübberstedt; Jeppe Reitan Andersen
err分享
err收藏
Protocatechuate 3,4-dioxygenase: comparative study of inhibition and active-site interactions of pyridine N-oxides
err2002-05-01
err0
PREAI
errSheldon W. May; Patricia W. Mueller; Charlie D. Oldham; Cynthia K. Williamson; Anne L. Sowell
err分享
err收藏
Comparative study between pulsed and continuous wave lasers for Photofrin® photodynamic therapy
err2005-10-19
err0
PREAI
errMasoud Panjehpour; Bergein F. Overholt; Robert C. Denovo; Mark G. Petersen; Rick E. Sneed
err分享
err收藏
err分享
err收藏
The Environment and the Microbial Ecology of Human Skin
err1977-03-01
err0
errOAAI
errMollie E. McBride; W. Christopher Duncan; J. M. Knox
err分享
err收藏
学者 查看更多内容