SysBumps:利用系统调用中的推测执行来破坏 macOS for Apple Silicon 中的 KASLR.pdf

编号:981545 PDF 102页 5.40MB 下载积分:VIP专享
下载报告请您先登录!

1、#BHEU BlackHatEventsSysBumps:Exploiting Speculative Execution in System Calls for Breaking KASLR in macOS for Apple SiliconSpeaker:Hyerean Jang$WhoamiHyerean JangPh.D Student Korea University Email:hr_jangkorea.ac.kr Research interests:Microarchitectural side-channel vulnerability,System security Co

2、ntributorsTaehun KimPh.D Student Korea University Email:taehunkkorea.ac.krYoungjoo ShinProfessor Korea University Email:syoungjookorea.ac.krApple SiliconApples proprietary arm-based processorApple SiliconApples proprietary arm-based processorExploring Microarchitectural Side-Channel Vulnerabilities

3、on macOS for Apple SiliconmacOSWhat is SysBumps Attack?KASLR breaking attack on macOS for Apple siliconWhat is SysBumps Attack?KASLR breaking attack on macOS for Apple siliconSpeculativeExecutionIn system callWhat is SysBumps Attack?KASLR breaking attack on macOS for Apple siliconSpeculativeExecutio

4、nTLB-basedSide-channelIn system callOutline Background Existing Microarchitectural Attack on KASLR Challenges Our Approaches SysBumps Attack Mitigations TakeawayMicroarchitectural Side-Channel Attack Exploit CPU design flaws to extract information through indirect leakages-Cache,TLB,branch predictor

5、s,Kernel Address Space Layout Randomization Load kernel into random location-Prevent attackers from predicting target kernel addresses for exploitsKernelKernelKernelNext bootingNext bootingKernel Address Space Layout Randomization Kernel is loaded within a reserved range of kernel addresses-Aligned

6、address to a specific sizeKernel address rangeAligned addressKernelKernel Address Space Layout Randomization Kernel is loaded within a reserved range of kernel addresses-Aligned address to a specific size Linux :0 xFFFFFFFF 8000 0000 0 xFFFF FFFF C000 0000(16MB aligned)Windows:0 xFFFF F800 0000 0000

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(SysBumps:利用系统调用中的推测执行来破坏 macOS for Apple Silicon 中的 KASLR.pdf)为本站 (竿头日上) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠