Share E-Book

Reverse Engineering Armv8-A Systems A practical guide to kernel, firmware, and TrustZone analysis (Kim Austin)(Z-Library)

Author

Technology
Language English

Unlock the secrets hidden in binary code without needing the source! Written by a Linux kernel engineer and author with over 14 years of industry experience, this book lays a solid foundation in reverse engineering and takes you from curious analyst to expert. You’ll master advanced techniques to dissect kernel binaries, including kernel module files, vmlinux, and vmcore, giving you the power to analyze systems at their core. This practical, three-part journey starts with the essentials of reverse engineering, introducing the key features of Armv8-A processors and the ELF file format. The second part walks you through the reverse-engineering process, from Arm environment setup to using static and dynamic analysis tools, including innovative methods for analyzing kernel binaries and the powerful debugging tool uftrace. The final part covers security, exploring TrustZone and the latest security techniques to safeguard Arm devices at the hardware level. By the end of this reverse engineering book, you'll have comprehensive Armv8-A expertise and the practical skills to analyze any binary with confidence while leveraging advanced security features to harden your systems.

Format PDF
Size 7.7 MB
3
Views
(First 20 pages)

Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Page 1
(This page has no text content)
Page 2
Reverse Engineering Armv8-A Systems First Edition A practical guide to kernel, firmware, and TrustZone analysis Austin Kim
Page 3
Reverse Engineering Armv8-A Systems First Edition Copyright © 2025 Packt Publishing All rights reserved. No part of this book may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written permission of the publisher, except in the case of brief quotations embedded in critical articles or reviews. Every effort has been made in the preparation of this book to ensure the accuracy of the information presented. However, the information contained in this book is sold without warranty, either express or implied. Neither the author, nor Packt Publishing or its dealers and distributors, will be held liable for any damages caused or alleged to have been caused directly or indirectly by this book. Packt Publishing has endeavored to provide trademark information about all of the companies and products mentioned in this book by the appropriate use of capitals. However, Packt Publishing cannot guarantee the accuracy of this information. Portfolio Director: Rohit Rajkumar Relationship Lead: Tanisha Mehrotra Project Manager: Sandip Tadge Content Engineer: Anuradha Vishwas Joglekar Technical Editor: Tejas Mhasvekar Copy Editor: Safis Editing Indexer: Pratik Shirodkar Proofreader: Anuradha Vishwas Joglekar Production Designer: Pranit Padwal Growth Lead: Namita Velgekar Marketing Owner: Nivedita Pandey First published: August 2025 Production reference: 1170725 Published by Packt Publishing Ltd. Grosvenor House 11 St Paul’s Square Birmingham B3 1RB, UK. ISBN 978-1-83508-892-0 www.packtpub.com
Page 4
To my wife, Helen, for encouraging me when I needed it and for standing by my side throughout my life. – Austin Kim
Page 5
Foreword The era of artificial intelligence (AI) is here, capturing the attention of tech enthusiasts, inno- vators, and students everywhere. With AI at the center of tech discussions, many people, from new developers to experienced professionals, are eager to learn its complexities. But is this the right path? Is AI really the ultimate answer – the “super-hero” of technology? Should every new developer and even those already established focus only on AI? These questions remain as we move through this exciting time. Alongside the AI excitement, another important topic is emerging: protecting personal informa- tion. In our connected world, people highly value their privacy. Yet, everyone knows that once personal data goes to the cloud, it’s no longer fully secure. The best way to keep personal data safe is to store it locally, on embedded devices rather than sending it to the cloud. This reality shows the growing importance of embedded systems, where Arm processors are already the most widely used technology. As the need for secure, local computing grows, Arm processors will become even more common, and the demand for Arm experts will rise. Moreover, while AI is strong in many areas, system software engineering, especially in reverse engineering, where AI often struggles, remains a vital and expanding field. Skills in this area will become even more essential as industries focus on secure, efficient, and reliable embedded solutions. Here enters Austin Kim, a well-known writer in South Korea’s tech community, famous for their insightful books on Arm architecture and the Linux kernel. Having read all of his books, I can say their greatest strength is how easy they are to read. Many technical books, even if full of great information, sit unread because they’re hard to follow. But Kim’s books are engaging and simple to understand. This ease doesn’t mean they lack depth; it helps readers grasp complex ideas ef- fortlessly. When I heard Austin Kim was writing a book in English, I wondered if their clear style would carry over. After reading this new book, I’m happy to say that he has a special talent for writing clearly and engagingly, no matter the language.
Page 6
I strongly recommend this book to anyone wanting to learn more about Arm processors, system software engineering, or embedded systems in today’s AI-driven world. Whether you’re a new developer exploring this field, an experienced engineer shifting to embedded systems, or a profes- sional aiming to stay ahead in a fast-changing industry, this book offers valuable knowledge. This book is a must-read for those eager to master a field that will only grow in importance, delivered with the clarity and engagement that only Kim can provide. Bojun Seo Software Engineer, LG Electronics
Page 7
Contributors About the author Austin Kim has more than 14 years of experience in embedded Linux BSP development. He has worked on many tasks, such as board bring-up, crash and performance troubleshooting, and bootloader development for Arm-based devices. He has strong skills in binary analysis and has analyzed many memory dumps using TRACE32, Crash Utility, and ftrace. He has solved various kernel issues, including crashes, system lockups, and watchdog resets. Currently, he works as a Linux kernel BSP engineer and technical lecturer at LG Electronics. He enjoys sharing practical debugging skills, especially in areas such as Armv8-A architecture and kernel crash analysis. I sincerely thank my wife, Helen Song, for her patience and support. Her dedication gave me the strength to complete this work. I’m also grateful for the guidance from mentors and leaders: Mike Seo, Dr. Reddy, Dr. Namseok Kim, and Dr. Gunho Lee. I also sincerely thank the technical reviewers: Bojun Seo, Rafiuddin Syed, Namhyung Kim, and Youngmin Nam. Lastly, I thank the Packt team, who supported me with great patience and professionalism.
Page 8
About the reviewers Bojun Seo is an open source developer at LG Electronics, developing advanced developer tools leveraging eBPF (extended Berkeley Packet Filter). He has an interest and experience in various fields related to computer science engineering, which include computer architecture, software architecture, parallel computing, General-Purpose Computing on Graphics Processing Units (GPGPU), memory management, algorithms, security, open source culture, and so on. He actively engages with other developers, enjoying presentations on his current tools at C++ Now, LG Soft- ware Developer Conference, and the Korean Linux Kernel Developers Meetup. He lives in Seoul and enjoys traveling around the world. Rafiuddin Syed is an embedded systems engineer with expertise in real-time computing, vir- tualization, and low-level software development. He has held various roles at Texas Instruments, Intel, NVIDIA, Harman, and Drako Motors. His work spans hypervisors, Linux kernel development, PCIe, USB, and secure IPC, with contributions to both industry and open source projects. Namhyung Kim is a staff software engineer at Google. He’s been working on the Linux kernel and other open source projects for more than 15 years. His main interests are low-level infra- structure such as operating systems, toolchains, performance monitoring, tracing, and binary instrumentation. Now he co-maintains the Linux perf tools and uftrace project, and also enjoys traveling all over the world.
Page 9
Youngmin Nam is a seasoned software engineer with over 15 years of experience in embedded systems and low-level software development. At Samsung Electronics, he has led Linux kernel and Android BSP development for ARM-based SoCs, including the Exynos2400 platform used in Galaxy flagship devices. He played a key role in the Google Pixel project, collaborating directly with Google’s Pixel team to bring up essential system drivers and ensure platform stability. More recently, he has been working closely with Google’s kernel team and upstream maintainers to apply Generic Kernel Image (GKI) support to the Exynos kernel. His expertise spans kernel bring-up, memory management, platform integration, and upstream contributions to both Linux and Android kernels. Youngmin is passionate about reverse engineering, debugging complex system-level issues, and contributing to the open source community. I would like to thank my family for their continued support and encouragement throughout my professional journey.
Page 10
Join our community on Discord Join our community’s Discord space for discussions with the authors and other readers: https:// packt.link/embeddedsystems
Page 11
(This page has no text content)
Page 12
(This page has no text content)
Page 13
Table of Contentsxii Key registers related to reverse engineering • 16 Procedure Call Standard for the Arm Architecture (AAPCS) 16 Background • 16 Introduction to AAPCS • 17 Register used for AAPCS • 17 BL instruction • 18 Exception levels 20 Exception levels and privilege levels • 21 EL0 with PL0 • 21 EL1 with PL1 • 22 EL2 with PL2 • 22 EL3 with PL3 • 22 Instructions to switch exception levels • 24 How to determine the current exception level • 26 Example routine to read CurrentEL • 27 Exceptions 28 Key principles of exceptions • 28 Types of exception • 28 Exception vector table • 29 Details of exception vector table • 30 EL1 with SP_EL0 • 31 EL1 (current EL with SPx) • 31 EL0 (AArch64) • 32 EL0 (AArch32) • 32 How an exception is generated with the big picture • 33 Step 1: Indicating the cause of exception • 33 Step 2: Updating registers • 34 Step 3: Switching the exception level • 34 Step 4: Branching to exception vector address • 34 Step 5: Exception handling • 35 How an exception handler works • 35
Page 14
(This page has no text content)
Page 15
(This page has no text content)
Page 16
Table of Contents xv Bit-shift operations 76 The LSL instruction • 76 Examples of the LSL instruction • 77 The LSR instruction • 78 Examples of the LSR instruction • 78 The ASR instruction • 79 The ROR instruction • 80 Case study – bit-shift operations in assembly code • 80 Logical operations 82 The AND instruction • 82 Example of the AND instruction • 83 The ORR instruction • 84 Example of the ORR instruction • 84 The ORN instruction • 85 Example of the ORN instruction • 85 The BIC instruction • 86 Examples of the BIC instruction • 87 The EOR instruction • 88 Examples of the EOR instruction • 88 Practicing logical operations • 89 The AND operation • 90 The OR operation • 90 The XOR operation • 91 Practicing data processing instructions 91 Initializing variables • 92 Checking the state • 93 Clearing a bit • 93 Handling the else part • 94 Summary 94
Page 17
(This page has no text content)
Page 18
Table of Contents xvii CMN instruction example • 121 The TST instruction • 122 TST instruction example • 122 Conditional codes • 123 Introducing conditional codes • 123 Analyzing an example routine with conditional codes • 124 Conditional branch operations 125 The CBZ instruction • 126 The CBNZ instruction • 126 The TBZ instruction • 127 The TBNZ instruction • 128 Analyzing assembly routines for reverse engineering • 129 The CBZ instruction • 130 The CBNZ instruction • 132 The TBZ instruction • 133 System control operations 135 The SVC instruction • 136 The HVC instruction • 137 The SMC instruction • 138 Summary 140 Part 2: Background Knowledge for Binary Analysis 141 Chapter 6: Introducing Reverse Engineering 143 Technical requirements 143 Why reverse engineering is necessary 143 Library and firmware debugging • 144 Legacy systems • 145 Improving debugging skills • 145 Case study – how reverse engineering skills enhance debugging abilities • 146
Page 19
(This page has no text content)
Page 20
(This page has no text content)
The above is a preview of the first 20 pages. Register to read the complete e-book.

Recommended for You

Loading recommended books...
Failed to load, please try again later

Tip the Site

Scan the WeChat Pay or Alipay code to tip. No login required.

WeChat Pay
Alipay
Back to List