[ad_1]
In 2015, researchers One disturbing discovery by Google is that the data theft technique “Rowhammer”, which was previously considered to be a theoretical problem, Can be used Under real-world conditions. Now, a group of different Google computer scientists show that the problem will only get worse, partly because of improvements in chip design.
Rowhammer is a physical hacking technique that can manipulate the electrical charge in a computer’s memory chip (called DRAM) to destroy or leak data. In an attack, the hacker repeatedly runs the same program on a “row” of DRAM transistors to “hammer” that row until the row leaks electricity into an adjacent row. If operated in a targeted manner, this leakage will physically flip the bit in the next row of the transistor from 1 to 0, and vice versa. By strategically flipping enough bits, the attacker can begin to manipulate the target system and gain a digital foothold.
from original In a 2014 Rowhammer study, chip manufacturers added mitigation measures to monitor adjacent rows for suspicious behavior. But as the chip size gets smaller and smaller, the ripple effect produced by hammering a given row may flip the bit by two or more rows. Think of Gallagher smashing a watermelon. You can protect the sight of the audience by giving them all the plastic poncho. However, if he swings hard enough and the crowd is crowded tight enough, the peel and pulp may come in contact with the face two to three rows deep.
Researchers Call their attack “Half-Double”, please note that this technology is not applicable to earlier generation DRAMs where the transistor rows are far apart.The rest is Moore’s Law However, with the dense packaging of transistors, the risk of overflow in the Rowhammer attack is increasing.
Google researchers told Wired in a written response to the question: “This is the result of miniaturization.” “In our experiments with older DDR4 chips, this technology was not successful. We are today This study is released to improve understanding of this threat. We hope it will further discuss durable and effective mitigation measures.”
Google disclosed its findings to the semiconductor engineering trade organization JEDEC, which has release two Expedient. Researchers have also been coordinating with other industry partners to raise awareness of the issue. But it will take some time for chip manufacturers to fully understand the meaning.
“Imagine your house is big,” said Daniel Moghimi, a postdoctoral researcher at the University of California, San Diego Researched Rowhammer And microarchitecture attacks. “If your neighbor also has a huge house and it plays loudly, you may be able to hear it from the house, but you may not be able to hear it from under three doors. When the distance between the units is very close, the concert disturbs many neighbors in the apartment. The density of DRAM units and their closeness to each other are the same idea.”
Comprehensive repair also needs to reconsider the way the chip is designed and apply it to future DRAMs. Looking back at Mighimi’s analogy, it is much easier to build a new apartment with thicker walls and higher insulation than it is to renovate an existing building.
Moghimi said that researchers have theoretically understood this potential risk, but Google’s discovery once again proved a possible, real attack. He said: “It shows that it is more practical than many people think.”
This wasn’t the first time the Rowhammer attack seemed to be resolved, and then shouted again.Researchers at Vrije Universiteit Amsterdam repeatedly display In the past 18 months, current chip defenses against more traditional Rowhammer attacks may be defeated. But Google’s findings further warn that the increase in the size and efficiency of memory chips may bring new risks brought by Rowhammer.
These hacking techniques require skill and even luck to carry out actual targeted attacks. However, given that the potential Rowhammer risk basically exists in every computing device in it, it is worth taking its progress seriously.
More exciting wired stories
[ad_2]
Source link






