Analyzing PTM attack traces through PageDumper: A case study
Trushna Parida, Suvrojit Das · 2022 IEEE 7th International conference for Convergence in Technology (I2CT) · 2022
Page Table Manipulation (PTM) attack is a type of data only attack that alters memory protection attributes through manipulation of page table data structures. This attack can bypass deployed kernel hardening techniques such as Supervisor Mode Execution Prevention(SMEP) and Write ⊕ Execute (and/or DEP/NX) that are implemented at the page level of abstraction and rely heavily on the integrity of page tables. In turn it enables the attacker to execute code with kernel privileges by disabling memory protection through the manipulation of code pages and/or injection of malicious code. In this paper, we first highlight the impacts of PTM attacks by presenting a case study that bypasses the popular kernel hardening solution SMEP for Linux based systems. Thereafter, we discuss our implementation of an instance of PTM attack, targeting the manipulation of page table attributes. Finally, we present our approach of analysis for the collected PTM attack footprints from runtime system memory using our previously developed tool PageDumper. PageDumper collects such PTM based attack footprints from runtime system memory along with other paging metadata to support an in-depth analysis of Linux volatile memory.