当前位置:首页 > 报告详情

您的内存安全吗?揭示汽车微处理器机制中隐藏的漏洞.pdf

上传人: 竿*** 编号:981589 2025-11-29 68页 4.44MB

1、#BHEU BlackHatEventsIs Your Memory Protected?Is Your Memory Protected?Uncovering Hidden Vulnerabilities in Automotive MPUsNimrod Stoler&David Lazar#BHEU BlackHatEventsInformation Classification:GeneralPlaxidityX Cybersecurity Solutions for the Automotive Industry:Comprehensive cybersecurity products

2、 and servicesAutomotive intrusion detection systemsAnti-vehicle theft solutionsVulnerability managementDevSecOpsEmbedded Research TeamSpecializations:Automotive vulnerability research&Penetration testingEmbedded systems&Hardware researchReverse engineeringFuzzingHighlights:Over 250,000 hours of comb

3、ined experience in automotive cybersecurityIn-depth knowledge of the vehicle cybersecurity lifecycleExpertise in automotive architectures,protocols,and standardsProficient in UNR 155&156,ISO 21434,and related incident and vulnerability management and treatment2Who we areWho we areNimrod StolerSecuri

4、ty Researcher PlaxidityXDavid LazarEmbedded Research Team Lead PlaxidityX#BHEU BlackHatEventsInformation Classification:GeneralECUECUECUECUECUECUECUECU Electronic Control Unit3#BHEU BlackHatEventsInformation Classification:GeneralECUECUECUECUECUECUECUECU Electronic Control Unit4#BHEU BlackHatEventsI

5、nformation Classification:GeneralECUECUECUECUECUECUECU Electronic Control Unit5XExecute code from stackXSend messages to ECUsXRead sensitive dataECU#BHEU BlackHatEventsInformation Classification:General6MPUMemory Protection Unit#BHEU BlackHatEventsInformation Classification:General7AgendaAgendaMPU I

6、ntroduction&FunctionalityAnalysis of the vulnerabilities&DemoDisclosure Processes with vendorsMitigations and Concluding remarks#BHEU BlackHatEventsInformation Classification:GeneralMemory Protection UnitProgrammable hardware unit that acts as a gatekeeper of memoryDivides memory into regionsFor eac

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
根据报告的内容,全文主要内容概括如下: 1. **MPU介绍与功能**:MPU(Memory Protection Unit)是保护内存的硬件单元,分为核心内存保护单元(CMPU)和系统内存保护单元(SMPU),用于控制内存访问权限和属性。 2. **硬件漏洞分析**:发现STMicroelectronics和NXP的某些MCU中的SMPU存在漏洞,允许特权攻击者禁用SMPU,从而访问受保护区域。 3. **配置步骤**:详细介绍了如何配置SMPU,包括定义区域描述符、锁定区域描述符、启用SMPU等步骤。 4. **漏洞利用演示**:通过演示,展示了攻击者如何利用SMPU漏洞访问受保护区域。 5. **负责任披露**:与STMicroelectronics和NXP进行了负责任披露,但双方均声称SMPU不是安全机制。 6. **缓解措施**:建议测试数据手册中的声明,使用堆栈破坏防御等缓解措施,并尽可能使用CMPU来阻止访问。
**MPU安全漏洞揭秘** **汽车ECU安全风险分析** **如何加固汽车芯片安全**
客服
商务合作
小程序
服务号
折叠