SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    Introducing Half-Double: New Hammering Technique for DRAM Rowhammer Bug
Date    Wednesday May 26 2021, @05:42AM
Author    martyb
Topic   
from the if-i-had-a-(row)-hammer dept.
https://soylentnews.org/article.pl?sid=21/05/26/0155202

upstart writes in with an IRC submission for AzumaHazuki:

Introducing Half-Double: New hammering technique for DRAM Rowhammer bug:

Today, we are sharing details around our discovery of Half-Double, a new Rowhammer technique that capitalizes on the worsening physics of some of the newer DRAM chips to alter the contents of memory.

[...] As DDR4 became widely adopted, it appeared as though Rowhammer had faded away thanks in part to these built-in defense mechanisms. However, in 2020, the TRRespass paper showed how to reverse-engineer and neutralize the defense by distributing accesses, demonstrating that Rowhammer techniques are still viable. Earlier this year, the SMASH research went one step further and demonstrated exploitation from JavaScript, without invoking cache-management primitives or system calls.

Traditionally, Rowhammer was understood to operate at a distance of one row: when a DRAM row is accessed repeatedly (the "aggressor"), bit flips were found only in the two adjacent rows (the "victims"). However, with Half-Double, we have observed Rowhammer effects propagating to rows beyond adjacent neighbors, albeit at a reduced strength. Given three consecutive rows A, B, and C, we were able to attack C by directing a very large number of accesses to A, along with just a handful (~dozens) to B. Based on our experiments, accesses to B have a non-linear gating effect, in which they appear to "transport" the Rowhammer effect of A onto C. Unlike TRRespass, which exploits the blind spots of manufacturer-dependent defenses, Half-Double is an intrinsic property of the underlying silicon substrate. This is likely an indication that the electrical coupling responsible for Rowhammer is a property of distance, effectively becoming stronger and longer-ranged as cell geometries shrink down. Distances greater than two are conceivable.


Original Submission

Links

  1. "upstart" - https://soylentnews.org/~upstart/
  2. "Introducing Half-Double: New hammering technique for DRAM Rowhammer bug" - https://security.googleblog.com/2021/05/introducing-half-double-new-hammering.html
  3. "Half-Double" - https://github.com/google/hammer-kit/blob/main/20210525_half_double.pdf
  4. "TRRespass" - https://www.vusec.net/projects/trrespass/
  5. "SMASH" - https://www.vusec.net/projects/smash/
  6. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=48871

© Copyright 2023 - SoylentNews, All Rights Reserved

printed from SoylentNews, Introducing Half-Double: New Hammering Technique for DRAM Rowhammer Bug on 2023-06-18 16:43:27