Horizontal Privilege Escalation in Trusted Applications
Darius Suciu, Stephen E. McLaughlin, Laurent Simon, Radu Sion
摘要
Trusted Execution Environments (TEEs) use hardwarebased isolation to guard sensitive data from conventional monolithic OSes. While such isolation strengthens security guarantees, it also introduces a semantic gap between the TEE on the one side and the conventional OS and applications on the other. In this work, we studied the impact of this semantic gap on the handling of sensitive data by Trusted Applications (TAs) running in popular TEEs. We found that the combination of two properties, (i) multi-tenancy and (ii) statefulness in TAs leads to vulnerabilities of Horizontal Privilege Escalation (HPE). These vulnerabilities leaked sensitive session data or provided cryptographic oracles without requiring code execution vulnerabilities in TEE logic. We identified 19 HPE vulnerabilities present across 95 TAs running on three major ARM TrustZonebased trusted OSes. Our results showed that HPE attacks can be used to decrypt DRM protected content, to forge attestations, and to obtain cryptographic keys under all three evaluated OSes. Here, we present HOOPER an automatic symbolic execution based scanner for HPE vulnerabilities, in order to aid manual analysis and to dramatically reduce overall time. In particular, in the Teegris Trusted OS HOOPER is able to identify 19 out of 24 HPE-based attack flows in 24-hours contrasted with our original manual analysis time of approximately four weeks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- HECKLER: Breaking Confidential VMs with Malicious InterruptsBenedict Schlüter, Supraja Sridhara, Mark Kuhne, Andrin Bertschi 等USENIX Security 2024 · 被引用 48 次
- ChainReactor: Automated Privilege Escalation Chain Discovery via AI PlanningGiulio De Pasquale, Ilya Grishchenko, Riccardo Iesari, Gabriel Pizarro 等USENIX Security 2024 · 被引用 15 次
- EL3XIR: Fuzzing COTS Secure MonitorsChristian Lindenmeier, Mathias Payer, Marcel BuschUSENIX Security 2024 · 被引用 10 次
- Return-to-Non-Secure Vulnerabilities on ARM Cortex-M TrustZone: Attack and DefenseZheyuan Ma, Xi Tan, Lukasz Ziarek, Ning Zhang 等DAC 2023 · 被引用 8 次
- GlobalConfusion: TrustZone Trusted Application 0-Days by DesignMarcel Busch, Philipp Mao, Mathias PayerUSENIX Security 2024 · 被引用 4 次
它引用的顶会 Paper1
相关 Paper
- ReZone: Disarming TrustZone with TEE Privilege ReductionDavid Cerdeira, José Martins, Nuno Santos, Sandro PintoUSENIX Security 2022
- SoK: Understanding the Prevailing Security Vulnerabilities in TrustZone-assisted TEE SystemsDavid Cerdeira, Nuno Santos, Pedro Fonseca, Sandro PintoS&P 2020 · 被引用 231 次
- Hardware-Backed Heist: Extracting ECDSA Keys from Qualcomm's TrustZoneKeegan RyanCCS 2019 · 被引用 90 次
- MOLE: Breaking GPU TEE with GPU-Embedded MCUHongyi Lu, Yunjie Deng, J. Sukarno Mertoguno, Shuai Wang 等CCS 2025
- PARTEMU: Enabling Dynamic Analysis of Real-World TrustZone Software Using EmulationLee Harrison, Hayawardh Vijayakumar, Rohan Padhye, Koushik Sen 等USENIX Security 2020
