Rowhammer Attacks in Dynamic Random-Access Memory and Defense Methods

Author:

Kim Dayeon1,Park Hyungdong1,Yeo Inguk1,Lee Youn Kyu1ORCID,Kim Youngmin2ORCID,Lee Hyung-Min3ORCID,Kwon Kon-Woo1ORCID

Affiliation:

1. Department of Computer Engineering, Hongik University, Seoul 04066, Republic of Korea

2. School of Electronic and Electrical Engineering, Hongik University, Seoul 04066, Republic of Korea

3. School of Electrical Engineering, Korea University, Seoul 02841, Republic of Korea

Abstract

This paper provides a comprehensive overview of the security vulnerability known as rowhammer in Dynamic Random-Access Memory (DRAM). While DRAM offers many desirable advantages, including low latency, high density, and cost-effectiveness, rowhammer vulnerability, first identified in 2014, poses a significant threat to computing systems. Rowhammer attacks involve repetitive access to specific DRAM rows, which can cause bit flips in neighboring rows, potentially compromising system credentials, integrity, and availability. The paper discusses the various stages of rowhammer attacks, explores existing attack techniques, and examines defense strategies. It also emphasizes the importance of understanding DRAM organization and the associated security challenges.

Funder

Military Crypto Research Center

Defense Acquisition Program Administration

Agency for Defense Development

Ministry of Science and ICT

National Research Foundation of Korea

Hongik University

Publisher

MDPI AG

Subject

Electrical and Electronic Engineering,Biochemistry,Instrumentation,Atomic and Molecular Physics, and Optics,Analytical Chemistry

Reference87 articles.

1. Flipping bits in memory without accessing them: An experimental study of DRAM disturbance errors;Kim;ACM SIGARCH Comput. Archit. News,2014

2. Kwong, A., Genkin, D., Gruss, D., and Yarom, Y. (2020, January 18–21). Rambleed: Reading bits in memory without accessing them. Proceedings of the 2020 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA.

3. Exploiting the DRAM rowhammer bug to gain kernel privileges;Seaborn;Black Hat,2015

4. Kaveh, R., Gras, B., Bosman, E., Preneel, B., Giuffrida, C., and Bos, H. (2016, January 10–12). Flip feng shui: Hammering a needle in the software stack. Proceedings of the 25th USENIX Security Symposium (USENIX Security 16), Austin, TX, USA.

5. Yuan, X., Zhang, X., Zhang, Y., and Teodorescu, R. (2016, January 10–12). One bit flips, one cloud flops:{Cross-VM} row hammer attacks and privilege escalation. Proceedings of the 25th USENIX Security Symposium (USENIX Security 16), Austin, TX, USA.

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3