Research Article

From Hardware to Operating System: A Static Measurement Method of Android System Based on TrustZone

Table 3

Attack experiment measurement results.

RootkitAttack function categoryMeasurement results of this experimentDIMDroid metric

Rootkit1Modify some bytes of syscall subroutine
Rootkit2Modify some items of syscall
Rootkit3Modify SWI software interrupt jump offset
Rootkit4Inject malicious code into the onTouchEvent() function and elevate the kernel layer permissions to complete attack×
Rootkit5Intercept the proc_lookup function to hide the process