arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

从车队到实验室:重新审视工业级Rowhammer缓解方案的安全性与复杂性

From Fleet to Lab: Revisiting the Security and Complexity of Industrial Rowhammer Mitigation

Hritvik Taneja, Moinuddin Qureshi

arXiv 2608.26072首次发表:更新:

AI 中文总结

本文分析工业级Rowhammer缓解方案Sigries的安全漏洞与复杂性问题,提出FiRM系列方案,通过协同设计跟踪与采样模式,实现低开销、安全的Rowhammer防御,性能优于Sigries与PARA。

AI 中文摘要

本文研究了存储控制器(MC)处高效且安全的Rowhammer缓解方案。Rowhammer缓解在跟踪存储与缓解率之间存在根本权衡:精确跟踪器(如Misra-Gries)可避免不必要的缓解,但需要大型CAM结构;而基于采样的方案(如PARA)无需存储,但即使未受攻击也会频繁触发缓解。微软最近在其Azure Cobalt 200 SoC中部署了Sigries,这是一种MC侧的Rowhammer防御方案,结合了配置不足的Misra-Gries跟踪器与行采样 fallback机制。Sigries发现,跟踪器到采样的转换可能存在安全问题,并声称反向转换始终安全。我们的分析表明,该转换也存在漏洞,跨子库的Round-Robin攻击可将Sigries的平均无故障时间(MTTF)降至约1秒,比PARA的13年低8个数量级。Sigries还存在CAM复杂性高、存储开销大的问题。我们提出的方案FiRM(Filtered Rowhammer Mitigation)基于以下见解:对于安全设计,跟踪模式与采样模式不应独立配置,而应协同设计,以确保系统不仅在两种模式下安全,在转换过程中也保持安全。FiRM对良性工作负载无性能损失,因为它们未超过过滤阈值,且用简单的SRAM过滤器替代了复杂的基于CAM的跟踪器。为应对压力模式,我们提出了FiRM-P(概率型)与FiRM-D(确定型)两种方案。FiRM-P在转换及稳态阶段使用可变概率,以兼顾安全性与低性能开销;FiRM-D通过调节缓解速率提供有保证的确定型安全性。FiRM-P与FiRM-D的存储开销均低于Sigries。本文表明,采用原则性方法可同时避免Sigries的安全性问题与复杂性问题。

英文摘要

This paper studies efficient and secure Rowhammer mitigation at the Memory-Controller (MC). Rowhammer mitigation faces a fundamental tradeoff between tracking storage and mitigation rate: precise trackers (such as Misra-Gries) avoid unnecessary mitigations but require large CAM structures, whereas sampling-based schemes (such as PARA) require no storage but incur frequent mitigations even when not under attack. Microsoft recently deployed Sigries, an MC-side Rowhammer defense that combines an under-provisioned Misra-Gries tracker with a row-sampling fallback, in its Azure Cobalt 200 SoC. Sigries observed that the tracker-to-sampling transition can be insecure, and claimed the reverse transition is always safe. Our analysis shows that this transition is also vulnerable, and a Round-Robin Attack across sub-banks reduces the MTTF of Sigries to about 1 second, 8 orders of magnitude below the 13 years with PARA. Sigries also suffers from CAM complexity and high storage overheads. Our proposal, FiRM (Filtered Rowhammer Mitigation), is based on the insight that, for a secure design, the tracking-mode and sampling-mode should not be configured independently but co-designed to ensure the system remains secure not only in both modes but also during transitions. FiRM incurs zero slowdown for benign workloads, since they do not exceed the filtering threshold, and also replaces the complex CAM-based tracker with simple SRAM filters. To handle stressful patterns, we propose FiRM-P (probabilistic) and FiRM-D (deterministic). FiRM-P uses varying probabilities during transitions and steady state to ensure both security and low performance overhead. FiRM-D provides guaranteed deterministic security by modulating the rate of mitigation. Both FiRM-P and FiRM-D have less storage overhead than Sigries. Our paper shows that a principled approach can avoid both the insecurity and the complexity of Sigries.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑