According to new research, modern RAM cards are still vulnerable to Rowhammer attacks, despite the measures developers to mitigate the risk. These measures, referred to as Target Row Refresh (TRR), are a combination of software and hardware that were added to the design of modern RAM cards after 2014, after the discovery of the first Rowhammer attack. It is worth mentioning further details about Rowhammer attacks at this point.
In modern RAM, whenever a computer accesses data , the data is stored in memory cells. While engineers have developed the ability to cram as many memory cells as possible onto a RAM stick , they have also developed the ability to electrically interfere with each other. This is essentially what makes a Rowhammer attack possible. Specifically, in 2014, academics realized that by performing very fast read or write operations on a row of memory, they could cause electrical interference, even to the point of destroying or modifying the data stored in a RAM.
Although Rowhammer attacks were only described on a theoretical level, in reality they could be used to modify computer data or steal information from cloud servers.
Since 2014, the hardware industry has been trying to come up with a solution for Rowhammer. Initially, academics showed how a Rowhammer attack could modify data stored on DDR3 and DDR4 memory cards . They then showed how a Rowhammer attack could be carried out via JavaScript , via the web , and not necessarily with access to a computer, either physically or through local malware. They also discovered a Rowhammer attack that “hit” Windows computers through the Microsoft Edge browser , as well as a Rowhammer attack that targeted Linux- based virtual machines installed in a cloud environment. The academics used a Rowhammer attack to gain root privileges on Android smartphones, while bypassing the protections put in place after the first attacks were discovered. They also showed how a hacker could improve the effectiveness of a Rowhammer attack by relying on local GPU cards . They then developed a technique for launching such attacks via network packets, and they also developed a Rowhammer attack targeting an Android memory subsystem called ION, which “broke” the isolation between the operating system and local applications, allowing hackers to steal data and take full control of devices. In addition, they discovered an attack called ECCploit, which also works against modern RAM cards that use error-correcting code (ECC). Later, they discovered RAMBleed, a variant of the Rowhammer attack that can not only modify data on targeted systems, but also remove it from them.
Target Row Refresh (TRR) is an attempt to mitigate all variants of Rowhammer, aiming to combine software patches and hardware fixes, redesigning RAM memory cards to prevent interference caused by Rowhammer. A hardware redesign of RAM was exactly what the creators of Rowhammer wanted. DDR4 memory cards were the first to receive TRR protection, and for a few years, vendors believed they had found a solution to this attack.
In a new research paper titled “TRRespass: Harnessing the Many Facets of Target Row Refresh,” a team of academics from universities in the Netherlands and Switzerland have developed a tool called TRRespass that can be used to upgrade TRR. They point out that after studying all the different ways in which TRR has been implemented by different vendors, they created TRRespass, a tool that can detect new row patterns. TRRespass shows that even the latest generation DDR4 systems with in-DRAM TRR, which have not been damaged by such attacks, are often vulnerable to new RowHammer variants.
In total, the research team said it tested 43 DIMMs (Dual In-line Module Memory, another name for laptop/PC/server RAM) and found that 13 DIMMs from the three major DRAM vendors (Samsung, Hynix, and Micron) are vulnerable to the new Rowhammer variants produced by the TRRespass tool. In addition to DDR4, the team is also testing LPDDR4 (X) chips that appear to be equally vulnerable to RowHammer bit flips. LPDDR4, also known as Low-Power DDR, is the type of memory used in smartphones and smart devices.
According to the research team's tests, TRRespass successfully detected new Rowhammer attacks targeting LPDDR4 memory cards used in smartphones from Google, LG, OnePlus, and Samsung, and in November 2019, it published a list of affected vendors.
Currently, the new TRR-bypass Rowhammer attack is identified as CVE-2020-10255. RAM products that receive software or hardware fixes for this vulnerability will likely take a few years to achieve the desired results.
