论文标题

部分可观测时空混沌系统的无模型预测

SpyHammer: Understanding and Exploiting RowHammer under Fine-Grained Temperature Variations

论文作者

Orosa, Lois, Rührmair, Ulrich, Yaglikci, A. Giray, Luo, Haocong, Olgun, Ataberk, Jattke, Patrick, Patel, Minesh, Kim, Jeremie, Razavi, Kaveh, Mutlu, Onur

论文摘要

Rowhammer是一种DRAM脆弱性,仅通过高温速度访问其相邻的DRAM行,可能会导致受害者DRAM行的位错误。最近的研究表明,新的DRAM设备越来越容易受到Rowhammer的影响,许多作品表明了系统级攻击,以供特权升级或信息泄漏。在这项工作中,我们对Rowhammer和温度之间的相关性进行了第一个严格的细粒度表征和分析。我们表明,即使变化很小(例如,$ \ pm 1 $°C),Rowhammer对温度变化非常敏感。我们利用从分析到DRAM温度间谍的两个关键观察结果:1)随着温度的升高,Rowhammer引起的位错误率一致地增加(或降低),而2)一些容易受到Rowhammer的DRAM细胞仅在特定温度下表现出钻头误差。基于这些观察结果,我们提出了一种新的Rowhammer攻击,称为Spyhammer,该攻击在关键系统(例如工业生产线,车辆和医疗系统)上监视DRAM的温度。 Spyhammer是首次在DRAM温度上监视的实用攻击。我们在受控环境中的评估表明,Spyhammer可以在所有测试温度的第90个百分位数中推断出受害者DRAM模块的温度,而误差小于$ \ pm 2.5 $°C,从四个主要制造商中,有12个真实的DRAM模块(120 DRAM芯片)。

RowHammer is a DRAM vulnerability that can cause bit errors in a victim DRAM row solely by accessing its neighboring DRAM rows at a high-enough rate. Recent studies demonstrate that new DRAM devices are becoming increasingly vulnerable to RowHammer, and many works demonstrate system-level attacks for privilege escalation or information leakage. In this work, we perform the first rigorous fine-grained characterization and analysis of the correlation between RowHammer and temperature. We show that RowHammer is very sensitive to temperature variations, even if the variations are very small (e.g., $\pm 1$ °C). We leverage two key observations from our analysis to spy on DRAM temperature: 1) RowHammer-induced bit error rate consistently increases (or decreases) as the temperature increases, and 2) some DRAM cells that are vulnerable to RowHammer exhibit bit errors only at a particular temperature. Based on these observations, we propose a new RowHammer attack, called SpyHammer, that spies on the temperature of DRAM on critical systems such as industrial production lines, vehicles, and medical systems. SpyHammer is the first practical attack that can spy on DRAM temperature. Our evaluation in a controlled environment shows that SpyHammer can infer the temperature of the victim DRAM modules with an error of less than $\pm 2.5$ °C at the 90th percentile of all tested temperatures, for 12 real DRAM modules (120 DRAM chips) from four main manufacturers.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源