The new RowHammer attack technique on DRAM memory

Google has introduced 'Half-Double,' a new technique for RowHammer class attacks, which enables the alteration of individual bits in dynamic random-access memory (DRAM). This attack can be reproduced on some modern DRAM chips, where manufacturers have minimized cell geometry.

As a reminder, RowHammer class attacks allow the corruption of individual bits of memory by cyclically reading data from adjacent memory cells. Since DRAM memory is structured as a two-dimensional array of cells, each comprising a capacitor and a transistor, continuous reading of the same memory area leads to voltage fluctuations and anomalies that cause a slight loss of charge in neighboring cells. If the read intensity is sufficiently high, a neighboring cell can lose a significant amount of charge, and the subsequent refresh cycle may not restore its original state, resulting in a change in the data stored in that cell.

To guard against RowHammer, chip manufacturers have implemented the TRR (Target Row Refresh) mechanism, which protects against corruption of cells in neighboring rows. The Half-Double method can bypass this protection by exploiting the fact that corruptions are not limited to neighboring rows and spread to other rows of memory, albeit to a lesser degree. Google's engineers demonstrated that for consecutive memory rows 'A,' 'B,' and 'C,' it is possible to attack row 'C' with very intense access to row 'A' and minimal activity touching row 'B.' Accessing row 'B' during the attack activates nonlinear charge leakage, enabling row 'B' to act as a conduit for transmitting the Rowhammer effect from row 'A' to 'C.'

The new RowHammer attack technique on DRAM memory

Unlike the TRRespass attack, which manipulates flaws in various implementations of the cell corruption prevention mechanism, the Half-Double attack is based on the physical properties of the silicon substrate. Half-Double indicates that the effects leading to Rowhammer are likely a function of distance rather than direct adjacency of cells. As cell geometries decrease in modern chips, the radius of distortion influence also increases. It is possible that the effect will be observed at distances greater than two rows.

It is noted that together with the JEDEC association, several proposals have been developed analyzing possible ways to block such attacks. The information about the method has been disclosed, as Google believes that the conducted research significantly enhances the understanding of the Rowhammer phenomenon and emphasizes the importance of collaborative efforts among researchers, chip manufacturers, and other stakeholders in developing a comprehensive and long-term solution for protection.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster