PrIDE: Achieving Secure Rowhammer Mitigation with Low-Cost In-DRAM Trackers
Aamer Jaleel, Gururaj Saileshwar, Stephen W. Keckler, Moinuddin K. Qureshi
摘要
Rowhammer-induced bit-flips are a threat to DRAM security. To mitigate Rowhammer, DDR4 devices employ TRR, an in-DRAM tracker, to identify aggressor rows. In-DRAM trackers tend to be severely resource-constrained (1-30 entries), which means they cannot reliably track all the aggressor rows and are bound to fail for some access patterns. Unfortunately, for existing in-DRAM trackers, it is difficult to a priori determine how often they will fail when subjected to the worst-case pattern. Unsurprisingly, all the current low-cost in-DRAM trackers have been broken with specific access patterns within a few minutes. While provably secure alternatives for in-DRAM tracking exist, they require thousands of tracking entries, making them unappealing for commercial adoption. The goal of our paper is to develop a low-cost in-DRAM tracker that is secure (guarantees a time-to-failure in the range of years) against all access patterns.We contend that the root cause of the vulnerability of current low-cost in-DRAM trackers stems from the use of activation-counters to direct policy decisions (e.g. which rows to insert, which to evict, and which to mitigate). Therefore, an attacker can perform frequent accesses to dummy rows to evade the mitigation of an aggressor row. The key insight of our paper is that to ensure security, the policy decisions of an in-DRAM tracker must not depend on the access pattern. To that end, we propose a secure and low-cost in-DRAM tracker called PrIDE, which consists of a FIFO buffer with probabilistic insertion. As the policy decisions of PrIDE do not depend on the access pattern, we develop a framework to calculate the time-to-failure. Our analysis with DDR5 shows that PrIDE (with 4 entries, 10byte storage) can tolerate Rowhammer thresholds of 1.9 K while guaranteeing per-bank time-to-failure of more than 10,000 years for all access patterns. We also co-design PrIDE with RFM to tolerate thresholds as low as 400 with only slowdown. To the best of our knowledge, PrIDE is the first low-cost in-DRAM tracker to achieve provably secure Rowhammer mitigation.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper16
- MINT: Securely Mitigating Rowhammer with a Minimalist in-DRAM TrackerMoinuddin Qureshi, Salman Qazi, Aamer JaleelMICRO 2024 · 被引用 28 次
- QPRAC: Towards Secure and Practical PRAC-based Rowhammer Mitigation using Priority QueuesJeonghyun Woo, Shaopeng Chris Lin, Prashant J. Nair, Aamer Jaleel 等HPCA 2025 · 被引用 20 次
- Variable Read Disturbance: An Experimental Analysis of Temporal Variation in DRAM Read DisturbanceAtaberk Olgun, F. Nisa Bostanci, Ismail Emir Yüksel, Oguzhan Canpolat 等HPCA 2025 · 被引用 15 次
- AutoRFM: Scaling Low-Cost in-DRAM Trackers to Ultra-Low Rowhammer ThresholdsMoinuddin QureshiHPCA 2025 · 被引用 15 次
- MoPAC: Efficiently Mitigating Rowhammer with Probabilistic Activation CountingSuhas Vittal, Salman Qazi, Poulami Das, Moinuddin QureshiISCA 2025 · 被引用 13 次
它引用的顶会 Paper25
- Drammer: Deterministic Rowhammer Attacks on Mobile PlatformsVictor van der Veen, Yanick Fratantonio, Martina Lindorfer, Daniel Gruss 等CCS 2016 · 被引用 381 次
- Another Flip in the Wall of Rowhammer DefensesDaniel Gruss, Moritz Lipp, Michael Schwarz, Daniel Genkin 等S&P 2018 · 被引用 288 次
- TRRespass: Exploiting the Many Sides of Target Row RefreshPietro Frigo, Emanuele Vannacci, Hasan Hassan, Victor van der Veen 等S&P 2020 · 被引用 274 次
- RAMBleed: Reading Bits in Memory Without Accessing ThemAndrew Kwong, Daniel Genkin, Daniel Gruss, Yuval YaromS&P 2020 · 被引用 239 次
- Exploiting Correcting Codes: On the Effectiveness of ECC Memory Against Rowhammer AttacksLucian Cojocar, Kaveh Razavi, Cristiano Giuffrida, Herbert BosS&P 2019 · 被引用 233 次
相关 Paper
- ProTRR: Principled yet Optimal In-DRAM Target Row RefreshMichele Marazzi, Patrick Jattke, Flavien Solt, Kaveh RazaviS&P 2022 · 被引用 101 次
- Phoenix: Rowhammer Attacks on DDR5 with Self-Correcting SynchronizationDiego Meyer, Patrick Jattke, Michele Marazzi, Salman Qazi 等S&P 2026 · 被引用 25 次
- BLACKSMITH: Scalable Rowhammering in the Frequency DomainPatrick Jattke, Victor van der Veen, Pietro Frigo, Stijn Gunter 等S&P 2022 · 被引用 140 次
- Understanding RowHammer Under Reduced Refresh Latency: Experimental Analysis of Real DRAM Chips and Implications on Future SolutionsYahya Can Tugrul, A. Giray Yaglikçi, Ismail Emir Yüksel, Ataberk Olgun 等HPCA 2025 · 被引用 10 次
- BlockHammer: Preventing RowHammer at Low Cost by Blacklisting Rapidly-Accessed DRAM RowsAbdullah Giray Yaglikçi, Minesh Patel, Jeremie S. Kim, Roknoddin Azizi 等HPCA 2021 · 被引用 124 次
