iDEV: exploring and exploiting semantic deviations in ARM instruction processing
Shisong Qin, Chao Zhang, Kaixiang Chen, Zheming Li
摘要
ARM has become the most competitive processor architecture. Many platforms or tools are developed to execute or analyze ARM instructions, including various commercial CPUs, emulators, and binary analysis tools. However, they have deviations when processing the same ARM instructions, and little attention has been paid to systematically analyze such semantic deviations, not to mention the security implications of such deviations. In this paper, we conduct an empirical study on the ARM Instruction Semantic Deviation (ISDev) issue. First, we classify this issue into several categories and analyze the security implications behind them. Then, we further demonstrate several novel attacks which utilize the ISDev issue, including stealthy targeted attacks and targeted defense evasion. Such attacks could exploit the semantic deviations to generate malware that is specific to certain platforms or able to detect and bypass certain detection solutions. We have developed a framework iDEV to systematically explore the ISDev issue in existing ARM instructions processing tools and platforms via differential testing. We have evaluated iDEV on four hardware devices, the QEMU emulator, and five disassemblers which could process the ARMv7-A instruction set. The evaluation results show that, over six million instructions could cause dynamic executors (i.e., CPUs and QEMU) to present different runtime behaviors, and over eight million instructions could cause static disassemblers yielding different decoding results, and over one million instructions cause inconsistency between dynamic executors and static disassemblers. After analyzing the root causes of each type of deviation, we point out they are mostly due to ARM unpredictable instructions and program defects.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper3
- NCScope: hardware-assisted analyzer for native code in Android appsHao Zhou, Shuohan Wu, Xiapu Luo, Ting Wang 等ISSTA 2022 · 被引用 16 次
- DiffTest-H: Toward Semantic-Aware Communication in Hardware-Accelerated Processor VerificationKunlin You, Yinan Xu, Kehan Feng, Luoshan Cai 等MICRO 2025 · 被引用 1 次
- MorFuzz: Fuzzing Processor via Runtime Instruction Morphing enhanced Synchronizable Co-simulationJinyan Xu, Yiyuan Liu, Sirui He, Haoran Lin 等USENIX Security 2023
相关 Paper
- An empirical study on ARM disassembly toolsMuhui Jiang, Yajin Zhou, Xiapu Luo, Ruoyu Wang 等ISSTA 2020 · 被引用 34 次
- D-ARM: Disassembling ARM Binaries by Lightweight Superset Instruction Interpretation and Graph ModelingYapeng Ye, Zhuo Zhang, Qingkai Shi, Yousra Aafer 等S&P 2023
- InstrSem: Automatically and Generically Inferring Semantics of (Undocumented) CPU InstructionsLorenz Hetterich, Fabian Thomas, Tristan Hornetz, Michael SchwarzUSENIX Security 2026
- InSPECtor: Improving SLEIGH Specification Veracity via ProxyMichael Chesser, Paul Quirk, Douglas Cooke, Guy Farrelly 等USENIX Security 2026
- Leaky MDU: ARM Memory Disambiguation Unit Uncovered and Vulnerabilities ExposedChang Liu, Yongqiang Lyu, Haixia Wang, Pengfei Qiu 等DAC 2023 · 被引用 5 次
