返回
CATTmew: Defeating Software-Only Physical Kernel Isolation
DOI:10.1109/TDSC.2019.2946816.png)
摘要
En 中文
All the state-of-the-art rowhammer attacks can break the MMU-enforced inter-domain isolation because the physical memory owned by each domain is adjacent to each other. To mitigate these attacks, physical domain isolation, introduced by CATT [7] , physically separates each domain by dividing the physical memory into multiple partitions and keeping each partition occupied by only one domain. CATT implemented physical kernel isolation as the first generic and practical software-only defense to protect kernel from being rowhammered as kernel is one of the most appealing targets. In this paper, we develop a novel exploit that could effectively defeat the CATT implementation and gain both root and kernel privileges, indicating that the physical kernel isolation is not secure in practice. Our exploit can work without exhausting the page cache or the system memory, or relying on the information of the virtual-to-physical address mapping. The exploit is motivated by our key observation that the modern OSes have double-owned kernel buffers (e.g., video buffers and SCSI Generic buffers) owned concurrently by the kernel and user domains. The existence of such buffers invalidates the physical separation enforced by CATT and makes the rowhammer-based attack possible again. Existing conspicuous rowhammer attacks achieving the root/kernel privilege escalation exhaust the page cache or even the whole system memory. Instead, we propose a new technique, named Memory Ambush. It is able to place the hammerable double-owned kernel buffers physically adjacent to the target objects (e.g., page tables) with only a small amount of memory. As a result, our exploit is stealthier and has fewer memory footprints. We also replace the inefficient rowhammer algorithm that blindly picks up addresses to hammer with an efficient one. Our algorithm selects suitable addresses based on an existing timing channel [31] . We implement our exploit on the Linux kernel version 4.10.0. Our experiment results indicate that a successful attack could be done within 1 minute. The occupied memory is as low as 88 MB.
Keyword:
Kernel
Memory management
Random access memory
Memory modules
Linux
Data structures
Streaming media
Rowhammer
physical domain isolation
physical kernel isolation
double-owned buffer
memory ambush
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
7.5
论文数:
2.5K
被引数:
9.6K
机构
引用论文
Variation in the Vernalization Response of a Geographically Diverse Collection of Timothy Genotypes
Crop Science
IF0
Protocatechuate 3,4-dioxygenase: comparative study of inhibition and active-site interactions of pyridine N-oxides
Biochemistry
IF0

