Attacking SMM Memory via Intel CPU Cache Poisoning
Attacking SMM Memory via Intel CPU Cache PoisoningRafal Wojtczuk Joanna Invisible Things Lab ]===--- AbstractIn this paper we describe novel practical attacks on SMM Memory (SMRAM) that exploit CPU caching semantics of Intel -based : CPU Cache , System Management Mode, SMM, security, analysis, Management Mode (SMM) is the most privileged CPU operation mode on x86/x86_64 architectures. It can be thought of as of "Ring -2", as the code executing in SMM has more privileges than even hardware hypervisors (VT), which are colloquially referred to as if operating in "Ring -1".The SMM code lives in a specially protected region of system Memory , called SMRAM. The Memory controller offers dedicated locks to limit access to SMRAM Memory only to system firmware (BIOS). BIOS, after loading the SMM code into SMRAM, can (and should) later "lock down" system configuration in such a way that no further access, from outside the SMM mode, to SMRAM is possible, even for an OS kernel (or a hypervisor).
Attacking SMM Memory via Intel ... Windows, also the ability to load and execute arbitrary kernel code3. 1. ... 3 Note that SMRAM memory should normally be protected against accesses from OS kernel, so even the system administrator is not allowed to access SMRAM.
Download Attacking SMM Memory via Intel CPU Cache Poisoning
Information
Domain:
Source:
Link to this page:
Please notify us if you found a problem with this document:
Related search queries
Attacking Hypervisors via Firmware and Hardware, Kernel, Windows, A Guide to Kernel, Attacking, Metasploit Lab: Attacking Windows XP, Observing Linux Behavior, Window s, Internals, Attacking the Windows, One Software Bypass of Windows 8, KQguard: Binary-Centric Defense against Kernel, Over ASLR: Attacking Branch Predictors to Bypass