发表机构
Inria Rennes / IRISA Lab, Univ Rennes; CentraleSupélec; Lab-STICC, Univ Bretagne Sud; Univ Rennes, CNRS, Inria IRISA - UMR 6074; Univ. Bretagne-Sud Lab-STICC UMR CNRS 6285(雷恩Inria实验室/IRISA实验室,雷恩大学; 中央苏伊士高等师范学院; Lab-STICC实验室,南布列塔尼大学; 雷恩大学,法国国家科学研究中心,Inria IRISA联合研究单位6074; 南布列塔尼大学Lab-STICC实验室,法国国家科学研究中心联合研究单位6285)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
JENGA攻击可操纵基于硬件计数器的RowHammer对策,将实时任务延迟至其WCET的200%,破坏安全关键实时系统的时间可预测性,本文还推导了计入该延迟的安全分析边界。
AI 中文摘要
安全关键实时系统必须满足多项可靠性要求,尤其是时间可预测性和安全性。在这类系统中,任务必须在有界且已知的执行时间内完成,通常通过最坏情况执行时间(WCET)分析来表征。与此同时,基于DRAM的平台对RowHammer读干扰安全漏洞日益敏感,这促使学术界和工业界开发了众多硬件和软件对策。然而,这些防御措施的影响通常是通过平均情况性能来评估的,而该指标对于安全关键实时系统而言并不充分,这类系统最关注的是最坏情况行为。在本文中,我们研究基于硬件计数器的RowHammer对策对实时系统时序行为的影响。我们以最近DDR5内存标准化的逐行激活计数器(PRAC)对策为案例研究,证明其会引发显著的时序变化。基于该观察结果,我们提出JENGA,即攻击者控制的任务操纵RowHammer对策机制的内部状态,使受害实时任务的执行时间超出其预期WCET的攻击。我们在gem5和Ramulator 2.0仿真环境中实现JENGA,并对TACLeBench工作负载评估其影响。我们表明,此类攻击可将任务延迟至其WCET的200%,使初始时间安全假设不再安全。为解决该问题,我们推导了安全分析边界,用于在受PRAC-N等硬件对策保护的DRAM系统的WCET分析中,计入由缓解措施引发的延迟。
英文摘要
Safety-critical real-time systems must satisfy multiple dependability requirements, notably time predictability and security. In such systems, tasks must complete within bounded and known execution times, typically characterised through Worst-Case Execution Time (WCET) analysis. At the same time, DRAM-based platforms are increasingly sensitive to the RowHammer read-disturbance security vulnerability, which has motivated the development of numerous hardware and software countermeasures in both academia and industry. However, the impact of these defences is generally evaluated in terms of average-case performance, a metric that is insufficient for safetycritical real-time systems, where worst-case behaviour is the primary concern. In this paper, we study the impact of RowHammer countermeasures based on hardware counters on the timing behaviour of real-time systems. We use a Per-Row-Activation-Counter (PRAC) countermeasure as a case study, standardised for recent DDR5 memories, and show that it can introduce significant timing variations. Based on this observation, we introduce JENGA, an attack in which an attacker-controlled task manipulates the internal state of the RowHammer countermeasure mechanism to increase the execution time of a victim real-time task beyond its expected WCET. We implement JENGA in a gem5 and Ramulator 2.0 simulation environment and evaluate its impact on TACLeBench workloads. We show that such an attack can delay tasks up to 200% of their WCET, making the initial timesafety assumptions unsafe. To address this issue, we derive a safe analytical bound that accounts for mitigation-induced delays in WCET analysis for DRAM systems protected by hardware countermeasures, such as PRAC-N.
CommentsTo appear at the 47th IEEE Symposium on Real-Time Systems (RTSS) 2026, 14 pages, 11 figures, 1 table