Marionette: A RowHammer Attack via Row Coupling
Seungmin Baek, Minbok Wi, Seonyong Park, Hwayong Nam, Michael Jaemin Kim, Nam Sung Kim, Jung Ho Ahn
摘要
A body of recent work has revealed that two different rows in a DRAM bank, from the perspective of a processor-memory interface, are connected to the same wordline but two separate row buffers (bitline sense amplifiers) in certain DRAM chips. Such a pair of rows is referred to as a ''coupled-row pair.'' Coupled-row pairs pose a substantial security threat as RowHammer bitflips can be caused not only by the conventional, adjacent aggressor rows but also by their coupled rows that are distant in physical address We investigate the impact of a coupled row on both FPGA-based infrastructure and server systems. In RowHammer attacks, coupled rows have hammering strength nearly identical to aggressor rows, with these attacks invisible to conventional, processor-side mitigation solutions. By exploiting these observations, we present Marionette, a new type of RowHammer attack that exploits coupled rows to extend the existing RowHammer attack surface. First, coupled rows enable an attacker to evade two types of existing software-based RowHammer defenses: tracking- and isolation-based defenses. We induce RowHammer bitflips successfully against tracking-based RowHammer defenses by silently hammering coupled rows. We also identify the feasibility of RowHammer bitflips in an isolation-based inter-VM RowHammer defense by breaking DRAM-subarray-level isolation. Second, we successfully conduct an existing RowHammer exploit in a server under the tracking-based RowHammer defense. In a native server system, Marionette enhances the success rate of the RowHammer exploit by up to 1.66x. Lastly, we explore lightweight mitigation schemes for Marionette by exposing the coupled-row relationship to systems.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper7
- Chronus: Understanding and Securing the Cutting-Edge Industry Solutions to DRAM Read DisturbanceOguzhan Canpolat, A. Giray Yaglikçi, Geraldo F. Oliveira, Ataberk Olgun 等HPCA 2025 · 被引用 23 次
- Understanding RowHammer Under Reduced Refresh Latency: Experimental Analysis of Real DRAM Chips and Implications on Future SolutionsYahya Can Tugrul, A. Giray Yaglikçi, Ismail Emir Yüksel, Ataberk Olgun 等HPCA 2025 · 被引用 10 次
- SoK: Systematizing a Decade of Architectural Rowhammer Defenses Through the Lens of Streaming AlgorithmsMichael Jaemin Kim, Seungmin Baek, Jumin Kim, Hwayong Nam 等S&P 2026 · 被引用 6 次
- Memory Band-Aid: A Principled Rowhammer Defense-in-DepthCarina Fiedler, Jonas Juffinger, Sudheendra Raghav Neela, Martin Heckel 等NDSS 2026 · 被引用 5 次
- PVAC: A Rowhammer Mitigation Architecture Exploiting Per-Victim-Row CountingJumin Kim, Seungmin Baek, Hwayong Nam, Minbok Wi 等ISCA 2026 · 被引用 5 次
相关 Paper
- Half-Double: Hammering From the Next Row OverAndreas Kogler, Jonas Juffinger, Salman Qazi, Yoongu Kim 等USENIX Security 2022
- BreakHammer: Enhancing RowHammer Mitigations by Carefully Throttling Suspect ThreadsOguzhan Canpolat, A. Giray Yaglikçi, Ataberk Olgun, Ismail Emir Yuksel 等MICRO 2024 · 被引用 19 次
- One Bit Flips, One Cloud Flops: Cross-VM Row Hammer Attacks and Privilege EscalationYuan Xiao, Xiaokuan Zhang, Yinqian Zhang, Radu TeodorescuUSENIX Security 2016 · 被引用 272 次
- Citadel: Rethinking Memory Allocation to Safeguard Against Inter-Domain Rowhammer ExploitsAnish Saxena, Walter Wang, Alexandros DaglisMICRO 2025 · 被引用 6 次
- SHADOW: Preventing Row Hammer in DRAM with Intra-Subarray Row ShufflingMinbok Wi, Jaehyun Park, Seoyoung Ko, Michael Jaemin Kim 等HPCA 2023 · 被引用 41 次
