DDR4 memory chips remain vulnerable to RowHammer attacks, despite added protections

A group of researchers from the Free University of Amsterdam, the Swiss Federal Institute of Technology Zurich, and Qualcomm conducted conducted a study on the effectiveness of the protections used in modern DDR4 memory chips against RowHammerattacks that allow the modification of the contents of individual bits in dynamic random-access memory (DRAM). The results were discouraging, and DDR4 chips from major manufacturers remain remain vulnerable (CVE-2020-10255).

The RowHammer vulnerability allows the distortion of the contents of individual memory bits by repeatedly reading data from adjacent memory cells. Since DRAM memory consists of a two-dimensional array of cells, each containing a capacitor and a transistor, continuous reading of the same memory area leads to voltage fluctuations and anomalies that cause a small charge loss in neighboring cells. If the read intensity is high enough, a cell may lose a significant amount of charge, and the subsequent regeneration cycle may not restore its initial state, resulting in a change in the value of the data stored in the cell.

To block this effect, modern DDR4 chips employ a technology called TRR (Target Row Refresh), designed to prevent cell distortion during a RowHammer attack. The problem is that there is no unified approach to implementing TRR, and each CPU and memory manufacturer interprets TRR in their own way, applying their own variants of protection and not disclosing implementation details.
Studying the methods employed by manufacturers to block RowHammer has made it easy to find ways to bypass the protection. Testing revealed that the principle of “security by obscurity during the implementation of TRR helps only for protection in specific cases, covering typical attacks that manipulate the charge changes in one or two adjacent rows.

The tool developed by researchers allows for checking the susceptibility of chips to multi-faceted RowHammer attack variants, where an attempt to influence the charge is made simultaneously for several rows of memory cells. Such attacks can bypass the TRR protection implemented by some manufacturers and result in memory bit distortion even on new hardware with DDR4 memory.
Out of 42 studied DIMM modules, 13 modules were found to be vulnerable to non-standard RowHammer attack variants, despite the claimed protection. The problematic modules were produced by SK Hynix, Micron, and Samsung, whose products account for 95% of the DRAM market.

In addition to DDR4, chips used in mobile devices, such as LPDDR4, were also studied and found sensitive to extended RowHammer attack variants. In particular, the memory used in Google Pixel smartphones, Google Pixel 3, LG G7, OnePlus 7, and Samsung Galaxy S10 was affected.

Researchers were able to reproduce several exploitation techniques on the problematic DDR4 chips. For example, using RowHammer-of the exploit for PTE (Page Table Entries) required an attack duration of between 2.3 seconds and three hours and fifteen seconds to gain kernel privileges, depending on the tested chips. Attack The damage to the stored RSA-2048 public key in memory took between 74.6 seconds and 39 minutes and 28 seconds. Attack The bypassing of authorization checks by modifying the sudo process memory took 54 minutes and 16 seconds.

An application has been released to check the DDR4 memory chips used by users, TRRespass. For a successful attack, information about the physical address layout in relation to banks and memory cell rows used in the memory controller is required. To determine this layout, an additional tool has been developed, drama, which needs to be run with root privileges. An application for testing smartphone memory will also be published soon. is planned It is advised to use error-correcting code (ECC) memory, memory controllers supporting Maximum Activate Count (MAC), and to employ an increased refresh rate for protection. However, researchers believe that for chips already released, there is no solution for guaranteed protection against RowHammer, and the implementation of ECC and increased memory refresh rates have proven ineffective. For example, a suggestion was previously made.

Companies Intel and AMD It was recommended to use error-correcting code (ECC) memory, memory controllers supporting Maximum Activate Count (MAC), and to apply increased refresh rates for protection. However, researchers believe that there is no foolproof solution for guaranteed protection against Rowhammer for already released chips, and the use of ECC along with increased refresh rates has proven to be ineffective. For instance, it was previously suggested method attacks on DRAM memory that bypass ECC protection, and it also demonstrates the possibility of attacking DRAM through local network, from the guest system and with the help of running JavaScript in the browser.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster