Understanding the Security of ARM Debugging Features
Zhenyu Ning, Fengwei Zhang
摘要
Processors nowadays are consistently equipped with debugging features to facilitate the program analysis. Specifically, the ARM debugging architecture involves a series of CoreSight components and debug registers to aid the system debugging, and a group of debug authentication signals are designed to restrict the usage of these components and registers. Meantime, the security of the debugging features is under-examined since it normally requires physical access to use these features in the traditional debugging model. However, ARM introduces a new debugging model that requires no physical access since ARMv7, which exacerbates our concern on the security of the debugging features. In this paper, we perform a comprehensive security analysis of the ARM debugging features, and summarize the security and vulnerability implications. To understand the impact of the implications, we also investigate a series of ARM-based platforms in different product domains (i.e., development boards, IoT devices, cloud servers, and mobile devices). We consider the analysis and investigation expose a new attacking surface that universally exists in ARM-based platforms. To verify our concern, we further craft Nailgun attack, which obtains sensitive information (e.g., AES encryption key and fingerprint image) and achieves arbitrary payload execution in a high-privilege mode from a low-privilege mode via misusing the debugging features. This attack does not rely on software bugs, and our experiments show that almost all the platforms we investigated are vulnerable to the attack. The potential mitigations are discussed from different perspectives in the ARM ecosystem.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- simTPM: User-centric TPM for Mobile DevicesDhiman Chakraborty, Lucjan Hanzlik, Sven BugielUSENIX Security 2019 · 被引用 26 次
- HyperDbg: Reinventing Hardware-Assisted DebuggingMohammad Sina Karvandi, MohammadHosein Gholamrezaei, Saleh Khalaj Monfared, Soroush Meghdadi Zanjani 等CCS 2022 · 被引用 10 次
- ISA-Grid: Architecture of Fine-grained Privilege Control for Instructions and RegistersShulin Fan, Zhichao Hua, Yubin Xia, Haibo Chen 等ISCA 2023 · 被引用 9 次
- FortifyPatch: Towards Tamper-Resistant Live Patching in Linux-Based HypervisorZhenyu Ye, Lei Zhou, Fengwei Zhang, Wenqiang Jin 等ISSTA 2024 · 被引用 1 次
- SCRUTINIZER: Towards Secure Forensics on Compromised TrustZoneYiming Zhang, Fengwei Zhang, Xiapu Luo, Rui Hou 等NDSS 2025
它引用的顶会 Paper11
- ARMageddon: Cache Attacks on Mobile DevicesMoritz Lipp, Daniel Gruss, Raphael Spreitzer, Clémentine Maurice 等USENIX Security 2016 · 被引用 451 次
- kAFL: Hardware-Assisted Feedback Fuzzing for OS KernelsSergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel 等USENIX Security 2017 · 被引用 324 次
- Hey, My Malware Knows Physics! Attacking PLCs with Physical Model Aware RootkitLuis Garcia, Ferdinand Brasser, Mehmet Hazar Cintuglu, Ahmad-Reza Sadeghi 等NDSS 2017 · 被引用 205 次
- SoK: The Challenges, Pitfalls, and Perils of Using Hardware Performance Counters for SecuritySanjeev Das, Jan Werner, Manos Antonakakis, Michalis Polychronakis 等S&P 2019 · 被引用 163 次
- vTZ: Virtualizing ARM TrustZoneZhichao Hua, Jinyu Gu, Yubin Xia, Haibo Chen 等USENIX Security 2017 · 被引用 136 次
相关 Paper
- iDEV: exploring and exploiting semantic deviations in ARM instruction processingShisong Qin, Chao Zhang, Kaixiang Chen, Zheming LiISSTA 2021 · 被引用 7 次
- Tiktag: Breaking ARM's Memory Tagging Extension with Speculative ExecutionJuhee Kim, Jinbum Park, Sihyeon Roh, Jaeyoung Chung 等S&P 2025
- Ninja: Towards Transparent Tracing and Debugging on ARMZhenyu Ning, Fengwei ZhangUSENIX Security 2017 · 被引用 62 次
- Hardware-Backed Heist: Extracting ECDSA Keys from Qualcomm's TrustZoneKeegan RyanCCS 2019 · 被引用 90 次
- Return-to-Non-Secure Vulnerabilities on ARM Cortex-M TrustZone: Attack and DefenseZheyuan Ma, Xi Tan, Lukasz Ziarek, Ning Zhang 等DAC 2023 · 被引用 8 次
