Ragnar: Exploring Volatile-Channel Vulnerabilities on RDMA NIC
Yunpeng Xu, Yuchen Fan, Teng Ma, Shuwen Deng
Abstract
With the surge in data computation, Remote Direct Memory Access (RDMA) becomes crucial to offering low-latency and highthroughput communication for data centers, but it faces new security threats. This paper presents RAGNAR, a comprehensive suite of hardware-contention-based volatile-channel attacks leveraging the underexplored security vulnerabilities in RDMA hardware. Through comprehensive microbenchmark reverse engineering, we analyze RDMA NICs at multiple granularity levels and then construct covert-channel attacks, achieving 3.2x the bandwidth of state-of-the-art RDMA-targeted attacks on CX-5. We apply side-channel attacks on real-world distributed databases and disaggregated memory, where we successfully fingerprint operations and recover sensitive address data with 95.6% accuracy.
• RDMA-targeted/related SW issues. Software implementation issues by REDMARK [33], and one-sided non-auditability [32].
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 11932d96-1fa9-423c-9b85-3dd26bf352a0Builds on11
- Port Contention for Fun and ProfitAlejandro Cabrera Aldaya, Billy Bob Brumley, Sohaib ul Hassan, Cesar Pereida García et al.S&P 2019 · 240 citations
- Lord of the Ring(s): Side Channel Attacks on the CPU On-Chip Ring Interconnect Are PracticalRiccardo Paccagnella, Licheng Luo, Christopher W. FletcherUSENIX Security 2021 · 121 citations
- Rethinking software runtimes for disaggregated memoryIrina Calciu, M. Talha Imran, Ivan Puddu, Sanidhya Kashyap et al.ASPLOS 2021 · 116 citations
- Sherman: A Write-Optimized Distributed B+Tree Index on Disaggregated MemoryQing Wang, Youyou Lu, Jiwu ShuSIGMOD 2022 · 99 citations
- Collie: Finding Performance Anomalies in RDMA SubsystemsXinhao Kong, Yibo Zhu, Huaping Zhou, Zhuo Jiang et al.NSDI 2022 · 86 citations
Related papers
- ReDMArk: Bypassing RDMA Security MechanismsBenjamin Rothenberger, Konstantin Taranov, Adrian Perrig, Torsten HoeflerUSENIX Security 2021 · 56 citations
- Pythia: Remote Oracles for the MassesShin-Yeh Tsai, Mathias Payer, Yiying ZhangUSENIX Security 2019 · 37 citations
- Bedrock: Programmable Network Support for Secure RDMA SystemsJiarong Xing, Kuo-Feng Hsu, Yiming Qiu, Ziyang Yang et al.USENIX Security 2022
- OneSidedMW: Managing Disaggregated Memory Efficiently, Flexibly, and Securely with RNIC OffloadingZixuan Wang, Jinyu Gu, Xingda Wei, Yubin XiaNSDI 2026
- NeVerMore: Exploiting RDMA Mistakes in NVMe-oF Storage ApplicationsKonstantin Taranov, Benjamin Rothenberger, Daniele De Sensi, Adrian Perrig et al.CCS 2022 · 8 citations
