ZenHammer — an attack method for manipulating memory content on AMD Zen platforms

Researchers from ETH Zurich have developed the ZenHammer attack method, which is a variant of RowHammer attacks aimed at modifying individual bits in dynamic RAM (DRAM), adapted for use on platforms with AMD processors. Previous RowHammer attack methods were limited to Intel-based systems, but the conducted research has shown that memory cell corruption can also be achieved on platforms with AMD memory controllers.

The method has been demonstrated on AMD Zen 2 and Zen 3 systems with DDR4 memory from three leading manufacturers (Samsung, Micron, and SK Hynix). The attack successfully bypasses the TRR (Target Row Refresh) mechanism implemented in memory chips, aimed at protecting against corruption of memory cells in adjacent rows. According to researchers, AMD Zen 3-based systems are more vulnerable than Intel Coffee Lake processor systems, and they are easier and more effective to attack. On AMD Zen 2 systems, cell corruption was achieved for 7 out of the 10 tested DDR4 chips, while on Zen 3 systems, this was the case for 6 out of 10. Researchers also analyzed the possibility of attacking AMD Zen 4 systems with DDR5 memory, but the method developed for DDR4 was successfully reproduced on only 1 out of the 10 tested DDR5 memory chips, while the possibility of an attack is not ruled out, it requires the development of more effective reading patterns suitable for DDR5 devices.

For working with AMD chips, previously developed exploits have been adapted to change the contents of page table entries (PTE) to gain kernel privileges, bypassing password/permissions checks by modifying the memory of the sudo process and corrupting the RSA-2048 public key stored in memory for reconstructing the private key. The memory page attack was reproduced on 7 out of 10 tested DDR4 chips, the RSA key attack was successful on 6 chips, and the sudo attack was successful on 4 chips, with the attack durations being 164, 267, and 209 seconds, respectively.

ZenHammer - an attack method for corrupting memory content on AMD Zen platforms

The method may also be applicable for attacking a system through browsers, allowing for changes from of virtual machines or for organizing a network attack. The source code of the DARE toolkit for reverse engineering address mapping in DRAM memory is available on GitHub under the MIT license, along with two sets of utilities for fuzz testing bit distortion in memory—ddr4_zen2_zen3_pub for DDR4 chips (Zen 2 and Zen 3) and ddr5_zen4_pub for DDR5 chips (Zen 4), which can be used to check systems for vulnerability to attacks.

ZenHammer - an attack method for corrupting memory content on AMD Zen platforms

The RowHammer method is used for bit distortion, based on the fact that in DRAM memory, which is a two-dimensional array of cells consisting of a capacitor and a transistor, continuous reading of the same memory area leads to voltage fluctuations and anomalies that cause a slight loss of charge in neighboring cells. If the reading intensity is high, a neighboring cell may lose enough charge that the next refresh cycle fails to restore its original state, leading to a change in the data value stored in the cell. Researchers have identified characteristics of the mapping mechanisms and synchronization with memory refresh in AMD processors, which allowed for low-level DRAM addressing to be recreated, determination of neighboring cell addresses, development of cache bypass methods, and calculation of patterns and frequencies of operations leading to charge loss.

To protect against RowHammer, chip manufacturers employ the TRR (Target Row Refresh) mechanism, which blocks cell distortion in specific cases but does not safeguard against all possible attack variants. The most effective method of protection remains the use of error-correcting code (ECC) memory, which significantly complicates but does not completely prevent RowHammer attacks. Increasing the memory refresh rate also helps reduce the likelihood of a successful attack.

AMD has published a report on the issue, stating that AMD processors use memory controllers compliant with DDR specifications. Since the success of the attack largely depends on system settings and DRAM memory, inquiries regarding mitigation should be directed to memory and system manufacturers. Among the existing methods to make Rowhammer attacks more difficult are the use of ECC memory, increasing the memory refresh rate, disabling the delayed-refresh mode, and using processors with controllers that support MAC (Maximum Activate Count) mode for DDR4 (1st, 2nd, and 3rd generation AMD EPYC "Naples", "Rome", and "Milan") and RFM (Refresh Management) for DDR5 (4th generation AMD EPYC).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster