Return-to-Non-Secure Vulnerabilities on ARM Cortex-M TrustZone: Attack and Defense
Zheyuan Ma, Xi Tan, Lukasz Ziarek, Ning Zhang, Hongxin Hu, Ziming Zhao
摘要
ARM Cortex-M is one of the most popular microcontroller architectures designed for embedded and Internet of Things (IoT) applications. To facilitate efficient execution, it has some unique hardware optimization. In particular, Cortex-M TrustZone has a fast state switch mechanism that allows direct control-flow transfer from the secure state program to the non-secure state userspace program. In this paper, we demonstrate how this fast state switch mechanism can be exploited for arbitrary code execution with escalated privilege in the non-secure state by introducing a new exploitation technique, namely return-to-non-secure (ret2ns). We experimentally confirmed the feasibility of four variants of ret2ns attacks on two Cortex-M hardware systems. To defend against ret2ns attacks, we design two address sanitizing mechanisms that have negligible performance overhead.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- SHERLOC: Secure and Holistic Control-Flow Violation Detection on Embedded SystemsXi Tan, Ziming ZhaoCCS 2023 · 被引用 13 次
- SoK: Integrity, Attestation, and Auditing of Program ExecutionMahmoud Ammar, Adam Caulfield, Ivan De Oliveira NunesS&P 2025
- 'We just did not have that on the embedded system': Insights and Challenges for Securing Microcontroller Systems from the Embedded CTF CompetitionsZheyuan Ma, Gaoxiang Liu, Alex Eastman, Kai Kaufman 等CCS 2025
- TZ-DATASHIELD: Automated Data Protection for Embedded Systems via Data-Flow-Based CompartmentalizationZelun Kong, Minkyung Park, Le Guan, Ning Zhang 等NDSS 2025
- XCFI: Comprehensive Control-Flow Integrity for Arm TrustZone-MYunju Gu, Jaeyeol Park, Donghyun KwonUSENIX Security 2026
它引用的顶会 Paper5
- A Tale of Two Worlds: Assessing the Vulnerability of Enclave Shielding RuntimesJo Van Bulck, David F. Oswald, Eduard Marin, Abdulla Aldoseri 等CCS 2019 · 被引用 159 次
- Protecting Bare-Metal Embedded Systems with Privilege OverlaysAbraham A. Clements, Naif Saleh Almakhdhub, Khaled Saab, Prashast Srivastava 等S&P 2017 · 被引用 122 次
- BOOMERANG: Exploiting the Semantic Gap in Trusted Execution EnvironmentsAravind Machiry, Eric Gustafson, Chad Spensky, Christopher Salls 等NDSS 2017 · 被引用 119 次
- ACES: Automatic Compartments for Embedded SystemsAbraham A. Clements, Naif Saleh Almakhdhub, Saurabh Bagchi, Mathias PayerUSENIX Security 2018 · 被引用 89 次
- Horizontal Privilege Escalation in Trusted ApplicationsDarius Suciu, Stephen E. McLaughlin, Laurent Simon, Radu SionUSENIX Security 2020
相关 Paper
- ReZone: Disarming TrustZone with TEE Privilege ReductionDavid Cerdeira, José Martins, Nuno Santos, Sandro PintoUSENIX Security 2022
- M-Step: A Single-Stepping Framework for Side-Channel Analysis on TrustZone-MCristiano Rodrigues, Marton Bognar, Sandro Pinto, Jo Van BulckUSENIX Security 2026
- BUSted!!! Microarchitectural Side-Channel Attacks on the MCU Bus InterconnectCristiano Rodrigues, Daniel Oliveira, Sandro PintoS&P 2024 · 被引用 15 次
- µRAI: Securing Embedded Systems with Return Address IntegrityNaif Saleh Almakhdhub, Abraham A. Clements, Saurabh Bagchi, Mathias PayerNDSS 2020
- CLKSCREW: Exposing the Perils of Security-Oblivious Energy ManagementAdrian Tang, Simha Sethumadhavan, Salvatore J. StolfoUSENIX Security 2017
