arXiv (Cornell University) · 2020 · 13 citations · 46 references
Intel's Software Guard Extensions (SGX) introduced new instructions to switch\nthe processor to enclave mode which protects it from introspection. While the\nenclave mode strongly protects the memory and the state of the processor, it\ncannot withstand memory corruption errors inside the enclave code. In this\npaper, we show that the attack surface of SGX enclaves provides new challenges\nfor enclave developers as exploitable memory corruption vulnerabilities are\neasily introduced into enclave code. We develop TeeRex to automatically analyze\nenclave binary code for vulnerabilities introduced at the host-to-enclave\nboundary by means of symbolic execution. Our evaluation on public enclave\nbinaries reveal that many of them suffer from memory corruption errors allowing\nan attacker to corrupt function pointers or perform arbitrary memory writes. As\nwe will show, TeeRex features a specifically tailored framework for SGX\nenclaves that allows simple proof-of-concept exploit construction to assess the\ndiscovered vulnerabilities. Our findings reveal vulnerabilities in multiple\nenclaves, including enclaves developed by Intel, Baidu, and WolfSSL, as well as\nbiometric fingerprint software deployed on popular laptop brands.\n
46
Chi-Keung Luk, Robert Cohn, Robert Muth et al. · ACM SIGPLAN Notices · 2005 · 3.2K citations
Engineering, Computer Architecture, Software Engineering +16
Symbolic execution and program testing
James C. King · Communications of the ACM · 1976 · 2.9K citations · Full text
The geometry of innocent flesh on the bone
Hovav Shacham · 2007 · 1.3K citations
Innovative instructions and software model for isolated execution
Frank Mckeen, Ilya Alexandrovich, Alex Berenzon et al. · 2013 · 1.1K citations