Droidsentry: Efficient Code Integrity and Control Flow Verification on TrustZone Devices
Darius Suciu, Radu Sion · 2017
The fast evolution of mobile devices has made them the center of attention for not only the research industry, but also malicious actors, as smartphones are used to store, transmit and process sensitive information. The diversity and number of typically installed applications create windows of opportunity for attackers. Attackers can use vulnerable applications to gain control over the device or change the behavior of applications relied on to manage user's finances or store their secret data. Thus, current mobile systems need application execution verification mechanisms. In consequence, we present a framework for current ARM mobile devices that can detect application control flow manipulation attempts by looking at the history of executed control flow altering instructions on the processor. This history examination provides enough information to implement the state-of-the-art fine-grained control policies, without additional binary instrumentation. Moreover, this framework is designed to work with existing hardware and have a minimal impact on performance.