PT-Guard: Integrity-Protected Page Tables to Defend Against Breakthrough Rowhammer Attacks

Anish Saxena*, Gururaj Saileshwar, Jonas Juffinger, Andreas Kogler, Daniel Gruss, Moinuddin Qureshi

*Korrespondierende/r Autor/-in für diese Arbeit

Publikation: Beitrag in Buch/Bericht/KonferenzbandBeitrag in einem KonferenzbandBegutachtung

Abstract

Page tables enforce process isolation in systems. Rowhammer attacks break process isolation by flipping bits in DRAM to tamper page tables and achieving privilege escalation. Moreover, new Rowhammer attacks break existing mitigations. We seek to protect systems against such breakthrough attacks. We present PT-Guard, an integrity protection mechanism for page tables. PT-Guard uses unused bits in Page Table Entries (PTE) to embed a Message Authentication Code (MAC) for the PTE cacheline without any storage overhead. These unused bits arise from PTEs supporting petabytes of physical memory while systems targeted by Rowhammer use at-most terabytes of mem-ory. By storing and verifying MACs for PTEs, PT-Guard detects arbitrary bit-flips in PTEs. Moreover, PT-Guard also provides best-effort correction of faulty-PTEs leveraging value locality. PT-Guard protects page tables from breakthrough Rowhammer attacks with negligible hardware changes, no DRAM storage, <72 bytes of SRAM, 1.3% slowdown, and no software changes.

Originalspracheenglisch
TitelProceedings - 2023 53rd Annual IEEE/IFIP International Conference on Dependable Systems and Networks, DSN 2023
Seiten95-108
Seitenumfang14
ISBN (elektronisch)9798350347937
DOIs
PublikationsstatusVeröffentlicht - 9 Aug. 2023
Veranstaltung53rd Annual IEEE/IFIP International Conference on Dependable Systems and Networks: DSN 2023 - Porto, Portugal
Dauer: 27 Juni 202330 Juni 2023

Konferenz

Konferenz53rd Annual IEEE/IFIP International Conference on Dependable Systems and Networks
KurztitelDSN
Land/GebietPortugal
OrtPorto
Zeitraum27/06/2330/06/23

ASJC Scopus subject areas

  • Software
  • Artificial intelligence
  • Sicherheit, Risiko, Zuverlässigkeit und Qualität
  • Computernetzwerke und -kommunikation

Fingerprint

Untersuchen Sie die Forschungsthemen von „PT-Guard: Integrity-Protected Page Tables to Defend Against Breakthrough Rowhammer Attacks“. Zusammen bilden sie einen einzigartigen Fingerprint.

Dieses zitieren