ZebRAM: comprehensive and compatible software protection against rowhammer attacks
At a glance
- Citations
- 55
- References
- 25
- Comments
- 0
Abstract
The Rowhammer vulnerability common to many modern<br/>DRAM chips allows attackers to trigger bit flips in a row<br/>of memory cells by accessing the adjacent rows at high<br/>frequencies. As a result, they are able to corrupt sensitive<br/>data structures (such as page tables, cryptographic keys,<br/>object pointers, or even instructions in a program), and<br/>circumvent all existing defenses.<br/>This paper introduces ZebRAM, a novel and compre-<br/>hensive software-level protection against Rowhammer.<br/>ZebRAM isolates every DRAM row that contains data<br/>with guard rows that absorb any Rowhammer-induced bit<br/>flips; the only known method to protect against all forms<br/>of Rowhammer. Rather than leaving guard rows unused,<br/>ZebRAM improves performance by using the guard rows<br/>as efficient, integrity-checked and optionally compressed<br/>swap space. ZebRAM requires no hardware modifications<br/>and builds on virtualization extensions in commodity pro-<br/>cessors to transparently control data placement in DRAM.<br/>Our evaluation shows that ZebRAM provides strong se-<br/>curity guarantees while utilizing all available memory.
Publication details
- DOI
- 10.5555/3291168.3291220
- OpenAlex
- W2899469948
- Document type
- conference-paper
- Language
- EN
- Source
- VU Research Portal
- Last metadata update
Comments
Log in to join the discussion.