TrustDump: Reliable Memory Acquisition on Smartphones
نویسندگان
چکیده
With the wide usage of smartphones in our daily life, new malware is emerging to compromise the mobile OS and steal the sensitive data from the mobile applications. Anti-malware tools should be continuously updated via static and dynamic malware analysis to detect and prevent the newest malware. Dynamic malware analysis depends on a reliable memory acquisition of the OS and the applications running on the smartphones. In this paper, we develop a TrustZone-based memory acquisition mechanism called TrustDump that is capable of reliably obtaining the RAM memory and CPU registers of the mobile OS even if the OS has crashed or has been compromised. The mobile OS is running in the TrustZone’s normal domain, and the memory acquisition tool is running in the TrustZone’s secure domain, which has the access privilege to the memory in the normal domain. Instead of using a hypervisor to ensure an isolation between the OS and the memory acquisition tool, we rely on ARM TrustZone to achieve a hardware-assisted isolation with a small trusted computing base (TCB) of about 450 lines of code. We build a TrustDump prototype on Freescale i.MX53 QSB.
منابع مشابه
New acquisition method based on firmware update protocols for Android smartphones
Android remains the dominant OS in the smartphone market even though the iOS share of the market increased during the iPhone 6 release period. As various types of Android smartphones are being launched in the market, forensic studies are being conducted to test data acquisition and analysis. However, since the application of new Android security technologies, it has become more difficult to acq...
متن کاملSmartphone Volatile Memory Acquisition for Security Analysis and Forensics Investigation
In this paper, we first identify the need to be equipped with the capability to perform raw volatile memory data acquisition from live smartphones. We then investigate and discuss the potential of different approaches to achieve this task on Symbian smartphones. Based on our initial analysis, we propose a simple, flexible and portable approach which can have a full-coverage view of the memory s...
متن کاملEffects of left prefrontal transcranial direct current stimulation on the acquisition of contextual and cued fear memory
Objective(s): Behavioral and neuroimaging studies have shown that transcranial direct current stimulation, as a non-invasive neuromodulatory technique, beyond regional effects can modify functionally interconnected remote cortical and subcortical areas. In this study, we hypothesized that the induced changes in cortical excitability following the application of cathodal or anodal tDCS over the ...
متن کاملMeasurements of Pedestrian’s load Using Smartphones
This paper explores the application of smartphones for human-induced loads measurements. Preliminary tests were carried out to select proper smartphones and data acquisition software. Shaking table tests were then conducted on selected smartphones to measure sinusoidal waves of various frequencies, sinusoidal sweep waves and earthquake waves. Comparison between the smartphones’ measurements and...
متن کاملThe Role of Hippocampal 5HT3 Receptors in Harmaline-Induced Memory Deficit
Introduction: The plethora of studies indicated that there is a cross talk relationship between harmaline and serotonergic (5-HT) system on cognitive and non-cognitive behaviors. Thus, the purpose of this study is to assess the effects of hippocampal 5-HT4 receptor on memory acquisition deficit induced by harmaline. Methods: Harmaline was injected peritoneally, while 5-HT4 receptor ago...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2014