Breaking Kernel Address Space Layout Randomization with Intel TSX
Yeongjin Jang, Sangho Lee, Taesoo Kim
Abstract
Kernel hardening has been an important topic since many applications and security mechanisms often consider the kernel as part of their Trusted Computing Base (TCB). Among various hardening techniques, Kernel Address Space Layout Randomization (KASLR) is the most effective and widely adopted defense mechanism that can practically mitigate various memory corruption vulnerabilities, such as buffer overflow and use-after-free. In principle, KASLR is secure as long as no memory leak vulnerability exists and high entropy is ensured. In this paper, we introduce a highly stable timing attack against KASLR, called DrK, that can precisely de-randomize the memory layout of the kernel without violating any such assumptions. DrK exploits a hardware feature called Intel Transactional Synchronization Extension (TSX) that is readily available in most modern commodity CPUs. One surprising behavior of TSX, which is essentially the root cause of this security loophole, is that it aborts a transaction without notifying the underlying kernel even when the transaction fails due to a critical error, such as a page fault or an access violation, which traditionally requires kernel intervention. DrK turned this property into a precise timing channel that can determine the mapping status (i.e., mapped versus unmapped) and execution status (i.e., executable versus non-executable) of the privileged kernel address space. In addition to its surprising accuracy and precision, DrK is universally applicable to all OSes, even in virtualized environments, and generates no visible footprint, making it difficult to detect in practice. We demonstrated that DrK can break the KASLR of all major OSes (i.e., Windows, Linux, and OS X) with near-perfect accuracy in under a second. Finally, we propose potential countermeasures that can effectively prevent or mitigate the DrK attack. We urge our community to be aware of the potential threat of having Intel TSX, which is present in most recent Intel CPUs-100% in workstation and 60% in high-end Intel CPUs since Skylake-and is even available on Amazon EC2 (X1).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ef6f7de9-9733-4e37-b61e-5047b5810a61Cited by top-tier papers55
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch ShadowingSangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim et al.USENIX Security 2017 · 536 citations
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck et al.CCS 2019 · 464 citations
- Translation Leak-aside Buffer: Defeating Cache Side-channel Protections with TLB AttacksBen Gras, Kaveh Razavi, Herbert Bos, Cristiano GiuffridaUSENIX Security 2018 · 357 citations
- Telling Your Secrets without Page Faults: Stealthy Page Table-Based Attacks on Enclaved ExecutionJo Van Bulck, Nico Weichbrodt, Rüdiger Kapitza, Frank Piessens et al.USENIX Security 2017 · 316 citations
Builds on6
- Prefetch Side-Channel Attacks: Bypassing SMAP and Kernel ASLRDaniel Gruss, Clémentine Maurice, Anders Fogh, Moritz Lipp et al.CCS 2016 · 278 citations
- Dedup Est Machina: Memory Deduplication as an Advanced Exploitation VectorErik Bosman, Kaveh Razavi, Herbert Bos, Cristiano GiuffridaS&P 2016 · 252 citations
- Enforcing Kernel Security Invariants with Data Flow IntegrityChengyu Song, Byoungyoung Lee, Kangjie Lu, William Harris et al.NDSS 2016 · 141 citations
- How to Make ASLR Win the Clone Wars: Runtime Re-RandomizationKangjie Lu, Wenke Lee, Stefan Nürnberger, Michael BackesNDSS 2016 · 96 citations
- Leakage-Resilient Layout Randomization for Mobile DevicesKjell Braden, Lucas Davi, Christopher Liebchen, Ahmad-Reza Sadeghi et al.NDSS 2016 · 90 citations
Related papers
- The Guard's Dilemma: Efficient Code-Reuse Attacks Against Intel SGXAndrea Biondo, Mauro Conti, Lucas Davi, Tommaso Frassetto et al.USENIX Security 2018 · 126 citations
- ASLR on the Line: Practical Cache Attacks on the MMUBen Gras, Kaveh Razavi, Erik Bosman, Herbert Bos et al.NDSS 2017 · 276 citations
- Whisper: Timing the Transient Execution to Leak Secrets and Break KASLRYu Jin, Chunlu Wang, Pengfei Qiu, Chang Liu et al.DAC 2024 · 1 citation
- ExpRace: Exploiting Kernel Races through Raising InterruptsYoochan Lee, Changwoo Min, Byoungyoung LeeUSENIX Security 2021 · 40 citations
- SGX-Shield: Enabling Address Space Layout Randomization for SGX ProgramsJaebaek Seo, Byoungyoung Lee, Seong-Min Kim, Ming-Wei Shih et al.NDSS 2017 · 227 citations
