DMA: A Persistent Threat to Embedded Systems Isolation

Jean de Bonfils Lavernelle, Pierre-François Bonnefoi, Benoît Gonzalvo, Damien Sauveron · 2024

In virtualized systems, guest Virtual Machines (VM) often have direct access to I/O devices for performance reasons, rather than using paravirtualized devices. However, this leads to a potential isolation breach due to the Direct Memory Access (DMA) capabilities of I/O devices assigned to these VMs. In such a configuration, a guest VM could instruct one of its DMA-capable I/O devices to transfer data to a memory location that the VM itself is not authorized to access. It is widely acknowledged that this isolation breach can be mitigated thanks to the Input-Output Memory Management Unit (IOMMU), which enforces access control on the DMA-capable peripherals to the main memory. Despite being mentioned for nearly two decades, this threat remains persistent, particularly due to the increasing adoption of virtualization in the field of embedded systems, where the target platforms often have no IOMMU. In addition, even when an IOMMU is present, DMA attacks can still be carried out due to various limitations which depend on the context, the underlying hypervisor, and the platform. This paper aims to raise awareness of the persistence of DMA attack threats within the context of embedded systems virtualization. It discusses why the requirements and constraints in this field make this threat still widespread and effective. It depicts a straightforward DMA attack in a common environment where a VM has direct access to a DMA-capable peripheral, showing the severity, applicability, and ease of implementation of such an attack. This paper also explores the potential ARM-based embedded platforms impacted, along with the available mitigation strategies and their current limitations.

Read the paper · More papers on PaperTik