When Mitigations Backfire: Timing Channel Attacks and Defense for PRAC-Based RowHammer Mitigations
Jeonghyun Woo, Joyce Qu, Gururaj Saileshwar, Prashant Jayaprakash Nair
摘要
Per Row Activation Counting (PRAC) has emerged as a robust framework for mitigating RowHammer (RH) vulnerabilities in modern DRAM systems.However, we uncover a critical vulnerability: a timing channel introduced by the Alert Back-Off (ABO) protocol and Refresh Management (RFM) commands.We present PRACLeak, a novel attack that exploits these timing differences to leak sensitive information, such as secret keys from vulnerable AES implementations, by monitoring memory access latencies.To counter this, we propose Timing-Safe PRAC (TPRAC), a defense that eliminates PRAC-induced timing channels without compromising RH mitigation efficacy.TPRAC uses Timing-Based RFMs, issued periodically and independent of memory activity.It requires only a single-entry in-DRAM mitigation queue per DRAM bank and is compatible with existing DRAM standards.Our evaluations demonstrate that TPRAC closes timing channels while incurring only 3.4% performance overhead at the RH threshold of 1024. CCS Concepts• Security and privacy → Security in hardware.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- Understanding and Mitigating Covert Channel and Side Channel Vulnerabilities Introduced by RowHammer DefensesF. Nisa Bostanci, Oguzhan Canpolat, Ataberk Olgun, Ismail Emir Yüksel 等MICRO 2025 · 被引用 8 次
- PVAC: A Rowhammer Mitigation Architecture Exploiting Per-Victim-Row CountingJumin Kim, Seungmin Baek, Hwayong Nam, Minbok Wi 等ISCA 2026 · 被引用 5 次
- Early Silicon of Raptor: The First 3D-DRAM Accelerator for Generative InferencePrashant J. Nair, Ramyad Hadidi, Subramani Ganesh, Sangamesh Kodge 等ISCA 2026 · 被引用 4 次
- PuDghost: Experimental Analysis of Computation Result Corruption in Processing-Using-Dram Operations on Real Dram Chips and Implications for Future SystemsDaichi Tokuda, Ismail Emir Yüksel, Tatsuya Kubo, Ataberk Olgun 等ISCA 2026 · 被引用 4 次
- PRowhammer: Propagating Bit-Flips from CPU to GPUMrityunjay Shukla, Shubham Roy, Sayandeep Saha, Biswabandan PandaISCA 2026 · 被引用 1 次
它引用的顶会 Paper57
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- DRAMA: Exploiting DRAM Addressing for Cross-CPU AttacksPeter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz 等USENIX Security 2016 · 被引用 500 次
- Drammer: Deterministic Rowhammer Attacks on Mobile PlatformsVictor van der Veen, Yanick Fratantonio, Martina Lindorfer, Daniel Gruss 等CCS 2016 · 被引用 381 次
- Flip Feng Shui: Hammering a Needle in the Software StackKaveh Razavi, Ben Gras, Erik Bosman, Bart Preneel 等USENIX Security 2016 · 被引用 306 次
相关 Paper
- QPRAC: Towards Secure and Practical PRAC-based Rowhammer Mitigation using Priority QueuesJeonghyun Woo, Shaopeng Chris Lin, Prashant J. Nair, Aamer Jaleel 等HPCA 2025 · 被引用 20 次
- MoPAC: Efficiently Mitigating Rowhammer with Probabilistic Activation CountingSuhas Vittal, Salman Qazi, Poulami Das, Moinuddin QureshiISCA 2025 · 被引用 13 次
- Chronus: Understanding and Securing the Cutting-Edge Industry Solutions to DRAM Read DisturbanceOguzhan Canpolat, A. Giray Yaglikçi, Geraldo F. Oliveira, Ataberk Olgun 等HPCA 2025 · 被引用 23 次
- Loaded Dice: Solving the Non-Selection Problem for Scalable Probabilistic RowHammer DefenseJeonghyun Woo, Junsu Kim, Aamer Jaleel, Prashant J. NairISCA 2026 · 被引用 1 次
- MIRZA: Efficiently Mitigating Rowhammer with Randomization and ALERTHritvik Taneja, Ali Hajiabadi, Michele Marazzi, Kaveh Razavi 等HPCA 2026 · 被引用 6 次
