SMEP (Supervisor Mode Execution Prevention) is a mitigation that aims to prevent the CPU from running code from user-mode while in kernel-mode, however this post (Windows 8 Kernel Memory Protections Bypass) presents a generic technique for exploiting kernel vulnerabilities with bypassing SMEP. Unlike my previous post (Page Table Structure Corruption Attacks - How to Mitigate it?) that presented a mitigation to that attack, this post will present a solution to detect such a ret2usr attack due to MMU paging structure corruption.
Showing posts with label SMEP. Show all posts
Showing posts with label SMEP. Show all posts
Monday, December 15, 2014
Tuesday, November 18, 2014
Page Table Structure Corruption Attacks - How to Mitigate it?
On x86 and many other processor architectures (with MMU), page tables are critical data structures for address translations. And many hardware-based page level protection technologies in my previous post, like SMEP, XD/DEP, highly depend on correct page table settings. so what if page tables are controlled by an attacker? ...At the end of this post, I will propose an extra solution to mitigate page table structure attacks.
Monday, November 17, 2014
Implement software-based SMEP with Non-Execute (NX) bit in page tables to secure kernel/user virtual memory address space.
In my previous post, I talked about how to implement a software-based SMEP (Supervisor Mode Execution Protection) with virtualization/hypervisor for fun. In this post, I'm going to detail yet another solution to implement software-based SMEP without virtualization technology.
Wednesday, November 12, 2014
How to Implement a software-based SMEP(Supervisor Mode Execution Protection) with Virtualization/Hypervisor Technology
As my previous post indicated, SMEP is a powerful security feature, and easy to deploy in modern commodity OS. However this feature requires H/W processor's support, for those processors that are not SMEP-capable, this post presents a software-based solution to emulate SMEP functionality with the help of Virtualization/Hypervisor technology.
Tuesday, May 06, 2014
Introduction to Processor Hardware Security Features in x86 & ARM Architectures
x86 and ARM processors both provide many hardware enforced security features, e.g. NX (No-eXecute) for executable space protection, to help system software engineers to build a secure computing environment.
This article summaries those security features for both x86/Intel and ARM architectures, and explains how are they used by Operating System.
This article summaries those security features for both x86/Intel and ARM architectures, and explains how are they used by Operating System.
Subscribe to:
Posts (Atom)