SCRUTINIZER: Towards Secure Forensics on Compromised TrustZone
Yiming Zhang
Network and Distributed System Security (NDSS) Symposium 2025 · Day 2 · Trusted Hardware and Execution
Overview
The talk "SCRUTINIZER: Towards Secure Forensics on Compromised TrustZone," presented by Fung Jan, delves into the critical challenge of performing secure and reliable forensics on Trusted Execution Environments (TEEs), specifically ARM TrustZone, after they have been compromised. TEEs are fundamental security components in modern computing, designed to protect sensitive data and operations from the potentially compromised rich operating system. However, despite their robust design, TrustZone implementations have accumulated a significant number of vulnerabilities over the years, making them susceptible to attack.
Key moments
- 0:00 Introduction and the critical need for TE forensics
- 2:00 Motivation and challenges for secure TE forensics
- 3:00 Introducing ARM CCA and Scrutinizer's architecture
- 4:40 Addressing memory acquisition challenges in TrustZone
- 6:20 Optimizing memory acquisition with page table grafting
- 7:00 Implementing fine-grain memory access traps for forensics
SCRUTINIZER: Towards Secure Forensics on Compromised TrustZone
Speakers: Yiming Zhang
Conference: NDSS Symposium
YouTube: https://www.youtube.com/watch?v=TFEiSf2V21A
Overview
The talk "SCRUTINIZER: Towards Secure Forensics on Compromised TrustZone," presented by Fung Jan, delves into the critical challenge of performing secure and reliable forensics on Trusted Execution Environments (TEEs), specifically ARM TrustZone, after they have been compromised. TEEs are fundamental security components in modern computing, designed to protect sensitive data and operations from the potentially compromised rich operating system. However, despite their robust design, TrustZone implementations have accumulated a significant number of vulnerabilities over the years, making them susceptible to attack.
The core motivation behind SCRUTINIZER is to address the pressing need for effective introspection and forensic capabilities within these highly privileged and isolated environments. Traditional forensic methods are often inadequate for TEEs due to their inherent isolation properties, which prevent external access, or their lack of fine-grained control for internal analysis. This talk introduces SCRUTINIZER, a novel framework that leverages the advanced hardware features of ARM Confidential Computing Architecture (CCA) to establish an independent, isolated, and highly performant forensic environment capable of inspecting a compromised TrustZone without being subverted by it.
This research is particularly significant because it tackles a long-standing problem in TEE security: how to trust the integrity of an environment that is designed to be self-protective but might have been breached. By demonstrating a practical and secure method for post-compromise analysis, SCRUTINIZER empowers security researchers and incident responders with the tools necessary to understand the extent of a TEE breach, recover critical evidence, and develop more resilient security measures. The work represents a substantial step forward in securing the foundational layers of modern computing systems, which increasingly rely on TEEs for everything from mobile device security to cloud confidential computing.
Background
▶ Watch: Introduction and the critical need for TE forensics (0:00)
Trusted Execution Environments (TEEs) have become a cornerstone of modern cybersecurity, providing a hardware-isolated environment to protect sensitive data and code from the main operating system and other applications. ARM TrustZone, introduced around 2004, is one of the most widely adopted TEEs, found in virtually every smartphone, and increasingly utilized in cloud computing, GPUs, and other embedded systems. Its fundamental principle is to create a "Secure World" alongside the "Normal World," with hardware mechanisms ensuring strict isolation and controlled communication between them.
Despite its ubiquity and critical role, TrustZone has not been immune to security vulnerabilities. The speaker highlights that across various TrustZone vendors, a total of approximately 207 vulnerabilities have been identified. These vulnerabilities underscore a significant problem: if a TrustZone system is compromised, there is a fundamental lack of effective tools and methodologies for introspection and forensic analysis. The very isolation that makes TEEs secure also makes them opaque to inspection, especially when the secure environment itself is under attacker control.
Prior attempts and challenges in TEE forensics face several limitations. Introspection from outside the TEE is inherently blocked by its isolation design. Attempting introspection from within the TEE, while theoretically possible, struggles with maintaining the necessary isolation for the forensic tools themselves, as a compromised TEE could subvert these tools. Existing hardware features like TrustZone Controllers (TZC) are designed for memory region protection, not for the dynamic, fine-grained introspection required for forensics.
The advent of ARM Confidential Computing Architecture (CCA), available in ARM v9.2-A and later architectures, presents a paradigm shift. ARM CCA introduces new hardware features that fundamentally alter the privilege model, particularly at Exception Level 3 (EL3), the highest privilege level on ARM systems. Crucially, it introduces the concept of a "root world" at EL3, distinct from the traditional EL3 monitor, providing a hypervisor-like capability at the deepest hardware level. This new architectural layer offers the primitives necessary to build a truly isolated and privileged environment for forensic tools, capable of inspecting both the Normal World and the Secure World (TrustZone) without being compromised by them. SCRUTINIZER capitalizes on these novel hardware capabilities to overcome the long-standing challenges in secure TrustZone forensics.
Key Findings
▶ Watch: Introducing ARM CCA and Scrutinizer's architecture (3:00)
SCRUTINIZER's primary contribution is the development of a secure and efficient framework for performing forensics on compromised ARM TrustZone systems. The research identifies and addresses several critical challenges, leveraging the new hardware features introduced by ARM CCA to achieve its goals.
Firstly, SCRUTINIZER demonstrates that secure introspection of a compromised TrustZone is indeed possible by establishing a forensic environment in the ARM CCA root world. This environment is inherently isolated from both the Normal World and the Secure World, ensuring that forensic operations cannot be detected or tampered with by a compromised TEE. This isolation is a cornerstone of the framework's security guarantees.
Secondly, the framework introduces novel techniques to optimize both the Trusted Computing Base (TCB) size and the performance of memory acquisition. By decoupling the introspection agent from the minimal root world code and employing a technique called grafting for efficient memory mapping, SCRUTINIZER significantly reduces the overhead typically associated with highly privileged operations and large-scale memory analysis. This is crucial for practical deployment, as large TCBs increase the attack surface, and slow performance impedes effective incident response.
Thirdly, SCRUTINIZER provides fine-grain memory access traps, a capability essential for precise debugging and forensic analysis. While ARM CCA's Granular Page Protection (GPC) offers page-level traps, the research identifies the need for instruction-level precision. By combining GPC with the Performance Monitoring Unit (PMU), SCRUTINIZER achieves this granular control, allowing forensic agents to stop execution at specific instructions within a compromised TEE.
Finally, the research confirms the effectiveness and efficiency of SCRUTINIZER through rigorous evaluation. The framework achieves substantial performance improvements, specifically demonstrating a 20 times performance improvement over state-of-the-art transparent tracing and debugging solutions like INA (USENIX Security 2017). Furthermore, its memory trap overhead is reduced by approximately 50%. These results validate SCRUTINIZER as a practical and superior solution for secure TrustZone forensics.
Technical Deep Dive
▶ Watch: Addressing memory acquisition challenges in TrustZone (4:40)
The SCRUTINIZER architecture is meticulously designed to leverage ARM CCA's new hardware features to create an isolated and performant forensic environment. The system comprises multiple key components working in concert: a memory acquisition agent, memory traps, instruction tracing (though not detailed in the presentation, it's part of the paper), and isolated control mechanisms. These components utilize specific ARM hardware features such as Memory Management Units (MMU), Performance Monitoring Units (PMU), Generic Interrupt Controllers (GIC), and critically, the new Granular Page Protection (GPC) feature from ARM CCA.
The primary target for introspection is the Secure World of TrustZone. SCRUTINIZER operates from the root world at Exception Level 3 (EL3), which in ARM CCA provides the highest privilege and isolation.
Memory Acquisition
Memory acquisition from a compromised TrustZone presents two main challenges:
- Enlarging the Root World Code Base (TCB): Placing a full introspection agent directly in the root world would significantly increase its size, thereby expanding the Trusted Computing Base (TCB) and potentially introducing new vulnerabilities.
- Solution 1: Decoupling the Introspection Agent. SCRUTINIZER addresses this by decoupling the introspection agent. A minimal code base is maintained within the root world (EL3), while the bulk of the introspection logic resides in an "upper layer" agent. This agent still operates under the root world's control but is not part of its most critical, minimal TCB. To ensure isolation between this agent and the potentially malicious TrustZone, SCRUTINIZER utilizes GPC (Granular Page Protection). GPC allows the root world to define protection attributes for memory pages, preventing the TrustZone from accessing the agent's memory or code.
- Performance Slowdown due to Address Translation: When the root world needs to access memory within the TrustZone, it typically involves extensive address translation from virtual to physical addresses, and then creating new mappings from EL3 to those physical locations. This process can introduce significant performance overhead.
- Solution 2: Grafting. To optimize memory access performance, SCRUTINIZER employs a technique called grafting. Instead of creating entirely new page tables for every memory access, the root world only creates a new first-level page table. The subsequent, lower-level page tables (which contain more detailed mappings) are "grafted" or linked directly to the original page tables used by the TrustZone. This allows the forensic agent to leverage the existing, pre-configured page table structures of the TrustZone, significantly reducing the overhead of address translation and mapping creation.
Memory Traps (Fine-Grain Access Traps)
For precise forensic analysis and debugging, the ability to stop program execution at specific memory addresses or instructions is crucial.
- Challenge with GPC: While GPC provides a mechanism to generate a page fault when the CPU attempts to execute an instruction within a marked page, its granularity is at the page level. This is insufficient for stopping at a specific instruction within a page.
- Solution: PMU-based Fine-Grain Traps. SCRUTINIZER implements a two-stage approach for fine-grain memory access traps:
- Page-Level Trap (using GPC): Initially, the target page containing the desired instruction is marked as non-accessible using GPC. When the program counter (PC) enters this page, a page fault is generated, trapping execution.
- Instruction-Level Trap (using PMU): Once the execution is trapped at the page level, the page is temporarily made accessible. Then, the Performance Monitoring Unit (PMU) is configured. The PMU is set up with a counter (e.g., for "retired instructions") and an overflow value. By setting the overflow value to trigger after a specific number of instructions (e.g., 2,000 instructions, or a calculated value to reach the target instruction), the PMU can generate an interrupt (overflow) precisely when the target instruction is about to be executed or has just been executed. This allows SCRUTINIZER to achieve instruction-level precision for memory traps.
Isolation Control for Hardware Features
A critical security aspect is ensuring that the compromised TrustZone cannot tamper with the forensic tools themselves, including the hardware features they rely on.
- Problem: Hardware features like PMU and GIC, essential for SCRUTINIZER's operation, could potentially be accessed and manipulated by a malicious TrustZone.
- Solution: GPC for Hardware Isolation. SCRUTINIZER again leverages GPC to prevent this. GPC is used to protect the access to the control registers and memory regions associated with PMU and GIC, ensuring that the compromised TrustZone cannot interfere with the forensic agent's use of these critical hardware resources.
Instruction Tracing
Although not extensively detailed in the presentation due to time constraints, the paper also includes a module for instruction tracing. For ARM V8/V9 systems, ARM provides hardware-based tracing techniques. SCRUTINIZER utilizes ET (Embedded Trace), a newer hardware tracing feature, to trace the execution within the TrustZone, similar to how ETM (Embedded Trace Macrocell) was used in earlier ARM V8 architectures. This capability provides a comprehensive log of instruction execution, invaluable for understanding attack flows.
Demo / Proof of Concept
▶ Watch: Optimizing memory acquisition with page table grafting (6:20)
The SCRUTINIZER project validated its design and implementation through two distinct prototypes, demonstrating both functional correctness and performance superiority.
- Functional Prototype:
- Platform: ARM FVP (Fixed Virtual Platform) emulator.
- Configuration: This emulator was chosen because it provides the most recent ARM hardware features, including ARM CCA and TrustZone capabilities.
- Purpose: The functional prototype was primarily used to verify that SCRUTINIZER's mechanisms – memory acquisition, fine-grain traps, and isolation – worked as intended within an environment that accurately models the target hardware. This ensured the core logic and interaction with CCA features were sound.
- Performance Prototype:
- Platform: A real ARM development board, specifically the ARM V8 Juno.
- Configuration Challenge: The ARM V8 Juno board, being an older architecture, does not natively support the newer GPC and CCA hardware features.
- Solution: To overcome this, the research team implemented emulation or analog mechanisms for these missing hardware features on the Juno board. This allowed them to measure the performance impact of SCRUTINIZER's techniques in a real hardware environment, even if the underlying CCA-specific features were simulated.
- Metrics: Performance was evaluated based on metrics such as instruction counts and execution time.
Comparative Evaluation:
SCRUTINIZER's performance was rigorously compared against INA, a state-of-the-art work published at USENIX Security 2017, titled "INA: Towards Transparent Tracing and Debugging on ARM TrustZone." This comparison provided a benchmark against a relevant and respected prior solution.
Key Results:
- Overall Performance Improvement: SCRUTINIZER demonstrated a significant performance improvement, achieving 20 times faster execution compared to INA. This substantial gain highlights the efficiency of SCRUTINIZER's optimized memory acquisition and trap mechanisms.
- Memory Trap Overhead Reduction: The overhead associated with SCRUTINIZER's memory traps was reduced by approximately 50%. This indicates the effectiveness of the PMU-based fine-grain trapping technique in minimizing performance impact while maintaining precision.
The source code for SCRUTINIZER is made available on GitHub, allowing other researchers and practitioners to inspect, reproduce, and build upon this work.
Defensive Implications
▶ Watch: Implementing fine-grain memory access traps for forensics (7:00)
The development of SCRUTINIZER carries significant implications for defenders operating in environments that utilize ARM TrustZone, which encompasses a vast array of devices from mobile phones to cloud servers. Understanding and potentially adopting the principles behind SCRUTINIZER can fundamentally change how organizations approach the security of TEEs.
- Enhanced Incident Response for TEEs: SCRUTINIZER provides a blueprint for building robust, post-compromise forensic capabilities for TrustZone. Defenders can no longer assume that a TEE breach is an unrecoverable "black box" event. Instead, tools inspired by SCRUTINIZER can enable detailed memory acquisition, execution tracing, and state analysis of a compromised Secure World, allowing for thorough root cause analysis and impact assessment.
- Proactive Monitoring of Critical Assets: For organizations deploying confidential computing solutions on ARM CCA-enabled platforms, the existence of tools like SCRUTINIZER underscores the importance of integrating TEE-level monitoring into their security operations. While SCRUTINIZER focuses on post-compromise forensics, its underlying principles for isolated introspection could be adapted for continuous integrity monitoring, detecting subtle deviations in TEE behavior that might indicate an ongoing attack.
- Understanding the Attack Surface of New Hardware: The reliance on ARM CCA's new "root world" and GPC features highlights a crucial defensive strategy: leveraging the deepest hardware-level security primitives available. Defenders need to be aware of how these new architectural capabilities can be used not only by attackers but also by defenders to establish a more trustworthy security foundation. This necessitates a deeper understanding of ARM v9.2-A and future architectures.
- Minimizing TCB and Performance Overhead: SCRUTINIZER's techniques for decoupling the introspection agent and using grafting for memory acquisition offer valuable lessons in designing secure and efficient forensic tools. Defenders should prioritize solutions that minimize the TCB of their security agents and optimize performance to ensure that forensic activities do not inadvertently introduce new vulnerabilities or unacceptable operational overheads.
- Addressing Persistent Vulnerabilities: The statistic of 207 TrustZone vulnerabilities underscores the ongoing need for robust security measures. SCRUTINIZER offers a powerful tool for analyzing these vulnerabilities in the wild, helping developers and security researchers understand exploitation techniques and develop more effective patches and mitigations.
In essence, SCRUTINIZER moves the needle from "TrustZone is compromised, we're blind" to "TrustZone is compromised, we can now see what happened." This shift empowers defenders to confront TEE attacks with greater clarity and effectiveness.
Key Takeaways
- TrustZone Vulnerabilities Demand Robust Forensics: Despite their critical role in security, ARM TrustZone implementations have accumulated numerous vulnerabilities (over 200), creating a pressing need for effective introspection and forensic capabilities on compromised TEEs.
- ARM CCA is a Game-Changer for TEE Security: The new hardware features introduced by ARM Confidential Computing Architecture (CCA), particularly the "root world" at EL3 and Granular Page Protection (GPC), provide the necessary primitives to build truly isolated and secure forensic environments.
- SCRUTINIZER Enables Secure and Performant TEE Forensics: The SCRUTINIZER framework leverages ARM CCA to establish an isolated forensic agent capable of inspecting a compromised TrustZone without being subverted, addressing long-standing challenges in TEE security.
- Optimized Memory Acquisition and Fine-Grain Traps are Key: Techniques like "grafting" for memory mapping and a PMU-based approach for fine-grain memory access traps are crucial for achieving high performance and precise control during forensic analysis within TEEs.
- Isolation of Forensic Tools is Paramount: SCRUTINIZER ensures the forensic agent and its utilized hardware features (PMU, GIC) are isolated from the compromised TrustZone using GPC, preventing attackers from tampering with the investigative process.
- Significant Performance Gains Over Prior Art: SCRUTINIZER demonstrates substantial performance improvements, achieving 20 times faster execution and a 50% reduction in memory trap overhead compared to existing state-of-the-art solutions, making it a practical tool for real-world scenarios.
About the Speaker(s)
The talk "SCRUTINIZER: Towards Secure Forensics on Compromised TrustZone" was presented by Fung Jan. The research itself is a collaborative effort, described as "joint work with multiple authors from multiple institutes," and the listed speaker for the conference is Yiming Zhang. No further biographical details, titles, or company affiliations were provided in the transcript or metadata for either individual.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Solid systems security research that solves a real, under-addressed problem: how do you forensically analyze a TEE that's already compromised and designed to resist inspection? The ARM CCA root-world angle is timely and the technical contributions — grafting for page table reuse, PMU-assisted instruction-level traps, GPC-enforced hardware isolation — are concrete and non-trivial. The 20x performance gain over INA is the kind of benchmark that makes a paper credible.
Heather Calloway (CISO) — WEAK
Technically credible systems research on a real and underserved problem — forensics inside compromised TEEs. But it never crosses the gap from academic contribution to operational relevance, and the defensive implications section reads like it was written to check a box rather than inform anyone with actual decision authority.
→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025
All talks from Network and Distributed System Security (NDSS) Symposium 2025