arrow
返回

Implicit Hammer: Cross-Privilege-Boundary Rowhammer Through Implicit Accesses

delete2023-09-01
delete1
PRE
AI
Z
Zhi Zhang
H
He Wei
Y
Yueqiang Cheng
W
Wenhao Wang
高
高艳松 (Yansong Gao) *
刘东喜 封面图
刘东喜 (Dongxi Liu)
K
Kang Li
‪
‪Surya Nepal‬
A
Anmin Fu
Y
Yi Zou
DOI:10.1109/TDSC.2022.3214666delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Rowhammer is a hardware vulnerability in DRAM memory, where repeated access to hammer rows can induce bit flips in neighboring victim rows. Rowhammer attacks have enabled privilege escalation, sandbox escape, cryptographic key disclosures, etc. A key requirement of all existing rowhammer attacks is that an attacker must have access to at least part of an exploitable hammer row. We term such rowhammer attacks as Explicit Hammer. Recently, several proposals leverage the spatial proximity between the accessed hammer rows and the location of the victim rows for a defense against rowhammer. These all aim to deny the attacker's permission to access hammer rows near sensitive data, thus defeating explicit hammer-based attacks. In this paper, we question the core assumption underlying these defenses. We present Implicit Hammer, a confused-deputy attack that causes accesses to hammer rows that the attacker is not allowed to access. It is a paradigm shift in rowhammer attacks since it crosses privilege boundary to stealthily rowhammer an inaccessible row by implicit DRAM accesses. Such accesses are achieved by abusing inherent features of modern hardware and/or software. We propose a generic model to rigorously formalize the necessary conditions to initiate implicit hammer and explicit hammer, respectively. Compared to explicit hammer, implicit hammer can defeat the advanced software-only defenses, stealthy in hiding itself and hard to be mitigated. To demonstrate the practicality of implicit hammer, we have created two implicit hammer's instances, called PThammer and SyscallHammer.
Keyword:
Random access memory
Kernel
Hardware
Program processors
Software
Microarchitecture
Memory management
Rowhammer
DRAM
cross-privilege-boundary
page table walk
system call handler

期刊

IEEE Transactions on Dependable and Secure Computing 封面图
IEEE Transactions on Dependable and Secure Computing
IF:
7.5
论文数:
2.5K
被引数:
9.6K

机构

U
university of chinese academy of sciences, cas
学者数:
4.1W
论文数: 3.8W
被引数: 75
C
I
institute of information engineering, cas
学者数:
477
论文数: 469
被引数: 0
C
chinese academy of sciences
学者数:
56.7W
论文数: 45.0W
被引数: 704
学者 查看更多机构
引用论文

引用论文

A novel exon generates ubiquitously expressed alternatively spliced new transcript of mouse Abcc4 gene
errGene
IF0
err2016-12-01
err0
PREAI
errSayeed Ur Rehman; Hassan Mubarak Ishqi; Mohammed Amir Husain; Tarique Sarwar; Mohammad Tabish
err分享
err收藏
Protocatechuate 3,4-dioxygenase: comparative study of inhibition and active-site interactions of pyridine N-oxides
err2002-05-01
err0
PREAI
errSheldon W. May; Patricia W. Mueller; Charlie D. Oldham; Cynthia K. Williamson; Anne L. Sowell
err分享
err收藏
Polyploidy in Aeginetia indica L. (Orobanchaceae).
err2003-01-01
err0
errOAAI
errGerald M. Schneeweiss; Hanna Weiss
err分享
err收藏
Comparative study between pulsed and continuous wave lasers for Photofrin® photodynamic therapy
err2005-10-19
err0
PREAI
errMasoud Panjehpour; Bergein F. Overholt; Robert C. Denovo; Mark G. Petersen; Rick E. Sneed
err分享
err收藏
学者 查看更多内容