Lune

USENIX Security2025

McSee: Evaluating Advanced Rowhammer Attacks and Defenses via Automated DRAM Traffic Analysis

Patrick Jattke, Michele Marazzi, Flavien Solt, Max Wipfli, Stefan Gloor, Kaveh Razavi

2025Year

Abstract

Rowhammer attacks and defenses are constantly evolving. Recent attacks rely on hammering multiple banks or keeping rows activated for long durations. On the defense side, the DDR5 standard requires memory controllers to send Refresh Management (RFM) commands when a specific DRAM bank receives too many activations. Are advanced Rowhammer attacks adequately exploiting their target features and do memory controllers send RFM commands adequately? This paper answers these questions by building an automated software platform, called McSee, on top of a highfrequency oscilloscope to study the behavior of DDR4 and DDR5 memory controllers under Rowhammer attacks. Leveraging a series of hardware and software optimizations, McSee is capable of reliably capturing and efficiently decoding singlecycle DDR4 and multi-cycle DDR5 traffic on the DRAM bus. We make a number of key discoveries using McSee. First, we show that hammering too many banks in parallel can actually be detrimental to the performance of Rowhammer attacks. Second, rows remain active far shorter than assumed when considering the recent Rowpress attack. Third, we show that neither Intel nor AMD CPUs send RFM commands even if a DDR5 device requires RFM to properly mitigate Rowhammer. Fourth, we uncover that instead of RFM, the memory controllers of Intel platforms rely on additional mitigative activations, which we characterize for the first time. We conclude by discussing the implications of our findings on the landscape of Rowhammer attacks and defenses. Columns Rows Subchannel A Subchannel B DIMM Bank Group 0 Chip Chip Chip Chip Chip Chip Chip Bank 1 Bank 1 Bank 0 Bank 0 † Subchannel A pins, e.g., CA0 is CA0_A in the UDIMM std. [51].