On the (in)security of Memory Protection Units : A Cautionary Note

Michele Grisafi, Mahmoud Ammar, Bruno Crispo · 2022

The Memory Protection Unit (MPU) is an optional component in many embedded devices where it can be used to protect the device memory from unwanted access by potentially malicious software. Unfortunately, the correct configuration of the MPU relies entirely on the application programmer, who has to make security-aware executive decisions to offer the desired level of security guarantees. This task is complicated and error-prone, and any configuration mistake could allow malicious software to completely breach the system, e.g., disabling the MPU. The MPU protection could also be voided by malicious software leveraging specific device features, e.g., interrupts.In this paper, we share our experiences in analyzing the security of MPUs. We first highlight the bad practices when configuring the MPU for securing the device memory. We then demonstrate the possibility of exploiting the raised issues, targeting two well-known architectures, namely MSP430 and ARMv7-M. We conclude with a set of recommendations for the correct usage of MPUs.

Read the paper · More papers on PaperTik