Fetching the paper…
Reading the bibliography…
The Rowhammer bug allows unauthorized modification of bits in DRAM cells from unprivileged software, enabling powerful privilege-escalation attacks.
P. Barham, B. Dragovic, K. Fraser, S. Hand, T. Harris, A. Ho, R. Neugebauer, I. Pratt, and A. Warfield, “Xen and the Art of Virtualization,” ACM SIGOPS Operating Systems Review , vol. 37, no. 5, pp. 164–177, 2003
2003
Earlier work this paper cites.
O. D. Kahn and J. R. Wilcox, “Method for dynamically adjusting a memory page closing policy,” Sep. 28 2004, uS Patent 6,799,241
2004
Earlier work this paper cites.
H. G. Rotithor, R. B. Osborne, and N. Aboulenein, “Method and apparatus for out of order memory scheduling,” Oct. 24 2006, uS Patent 7,127,574
2006
Earlier work this paper cites.
I. Habib, “Virtualization with KVM,” Linux J. , vol. 2008, no. 166, Feb. 2008
2008
Earlier work this paper cites.
H. David, C. Fallin, E. Gorbatov, U. R. Hanebutte, and O. Mutlu, “Memory power management via dynamic voltage/frequency scaling,” in ACM International Conference on Autonomic Computing , 2011
2011
Earlier work this paper cites.
D. Kaseridis, J. Stuecheli, and L. K. John, “Minimalist open-page: A DRAM page-mode scheduling policy for the many-core era,” in International Symposium on Microarchitecture (MICRO) , 2011
2011
Earlier work this paper cites.
K. Suzaki, K. Iijima, T. Yagi, and C. Artho, “Memory Deduplication as a Threat to the Guest OS,” in EuroSec , 2011
2011
Earlier work this paper cites.
R.-F. Huang, H.-Y. Yang, M. C.-T. Chao, and S.-C. Lin, “Alternate hammering test for application-specific DRAMs and an industrial case study,” in Annual Design Automation Conference (DAC) , 2012
2012
Earlier work this paper cites.
P. J. Meaney, L. A. Lastras-Montano, V. K. Papazova, E. Stephens, J. S. Johnson, L. C. Alves, J. A. O’Connor, and W. J. Clarke, “IBM zEnterprise redundant array of independent memory subsystem,” IBM Journal of Research and Development , vol. 56, no. 1.2, Jan 2012
2012
Earlier work this paper cites.
R. Lal and P. M. Pappachan, “An architecture methodology for secure video conferencing,” in IEEE International Conference on Technologies for Homeland Security (HST) , 2013
2013
Earlier work this paper cites.
Y. Kim, R. Daly, J. Kim, C. Fallin, J. H. Lee, D. Lee, C. Wilkerson, K. Lai, and O. Mutlu, “Flipping bits in memory without accessing them: An experimental study of DRAM disturbance errors,” in ISCA , 2014
2014
Earlier work this paper cites.
Y. Yarom and K. Falkner, “Flush+Reload: a High Resolution, Low Noise, L3 Cache Side-Channel Attack,” in USENIX Security Symposium , 2014
2014
Earlier work this paper cites.
B. Aichinger, “DDR memory errors caused by Row Hammer,” in HPEC , 2015
2015
Earlier work this paper cites.
——, “Row Hammer Failures in DDR Memory,” in memcon , 2015
2015
Earlier work this paper cites.
I. Anati, F. McKeen, S. Gueron, H. Huang, S. Johnson, R. Leslie-Hurd, H. Patil, C. V. Rozas, and H. Shafi, “Intel Software Guard Extensions (Intel SGX),” 2015, Tutorial Slides presented at ICSA
2015
Earlier work this paper cites.
A. Barresi, K. Razavi, M. Payer, and T. R. Gross, “CAIN: silently breaking ASLR in the cloud,” in Usenix WOOT , 2015
2015
Earlier work this paper cites.
K. Chen, P. Wang, Y. Lee, X. Wang, N. Zhang, H. Huang, W. Zou, and P. Liu, “Finding unknown malice in 10 seconds: Mass vetting for new threats at the Google-Play scale.” in USENIX Security Symposium , 2015
2015
Earlier work this paper cites.
M. Chiappetta, E. Savas, and C. Yilmaz, “Real time detection of cache-based side-channel attacks using hardware performance counters,” Cryptology ePrint Archive, Report 2015/1034, 2015
2015
Earlier work this paper cites.
M. Ghasempour, M. Lujan, and J. Garside, “ARMOR: A Run-time Memory Hot-Row Detector,” 2015. [Online]. Available: http://apt.cs.manchester.ac.uk/projects/ARMOR/RowHammer
2015
Earlier work this paper cites.
D. Gruss, D. Bidner, and S. Mangard, “Practical memory deduplication attacks in sandboxed JavaScript,” in ESORICS , 2015
2015
Earlier work this paper cites.
N. Herath and A. Fogh, “These are Not Your Grand Daddys CPU Performance Counters – CPU Hardware Performance Counters for Security,” in Black Hat Briefings , 2015
2015
Earlier work this paper cites.
N. Karimi, A. K. Kanuparthi, X. Wang, O. Sinanoglu, and R. Karri, “Magic: Malicious aging in circuits/cores,” ACM Transactions on Architecture and Code Optimization (TACO) , vol. 12, no. 1, 2015
2015
Earlier work this paper cites.
D.-H. Kim, P. J. Nair, and M. K. Qureshi, “Architectural support for mitigating row hammering in DRAM memories,” IEEE Computer Architecture Letters , vol. 14, no. 1, pp. 9–12, 2015
2015
Earlier work this paper cites.
Kirill A. Shutemov, “Pagemap: Do Not Leak Physical Addresses to Non-Privileged Userspace,” Mar. 2015, retrieved on November 10, 2015. [Online]. Available: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ab676b7d6fbf4b294bf198fb27ade5b0e865c7ce
2015
Earlier work this paper cites.
M. Salyzyn, “UPSTREAM: pagemap: do not leak physical addresses to non-privileged userspace,” 2015. [Online]. Available: https://android-review.googlesource.com/#/c/kernel/common/+/182766
2015
Earlier work this paper cites.
F. Schuster, M. Costa, C. Fournet, C. Gkantsidis, M. Peinado, G. Mainar-Ruiz, and M. Russinovich, “VC3: trustworthy data analytics in the cloud using SGX,” in S&P , 2015
2015
Cited alongside, same era.
M. Seaborn and T. Dullien, “Exploiting the DRAM rowhammer bug to gain kernel privileges,” in Black Hat Briefings , 2015
2015
Cited alongside, same era.
Y. Xu, W. Cui, and M. Peinado, “Controlled-Channel Attacks: Deterministic Side Channels for Untrusted Operating Systems,” in S&P , May 2015
2015
Cited alongside, same era.
S. Arnautov, B. Trach, F. Gregor, T. Knauth, A. Martin, C. Priebe, J. Lind, D. Muthukumaran, D. O ’ \textquoteright Keeffe, M. L. Stillwell et al. , “SCONE: Secure Linux containers with Intel SGX,” in OSDI , 2016
2016
Cited alongside, same era.
Z. B. Aweke, S. F. Yitbarek, R. Qiao, R. Das, M. Hicks, Y. Oren, and T. Austin, “ANVIL: Software-based protection against next-generation Rowhammer attacks,” ACM SIGPLAN Notices , vol. 51, no. 4, pp. 743–755, 2016
Y. Xiao, X. Zhang, Y. Zhang, and R. Teodorescu, “One bit flips, one cloud flops: Cross-VM Row Hammer attacks and privilege escalation,” in USENIX Security Symposium , 2016
2016
Later among the works it cites.
K. S. Yim, “The rowhammer attack injection methodology,” in IEEE 35th Symposium on Reliable Distributed Systems (SRDS) , 2016
2016
Later among the works it cites.
T. Zhang, Y. Zhang, and R. B. Lee, “Cloudradar: A real-time side-channel attack detection system in clouds,” in RAID , 2016
2016
Later among the works it cites.
M. T. Aga, Z. B. Aweke, and T. Austin, “When good protections go bad: Exploiting anti-DoS measures to accelerate Rowhammer attacks,” in International Symposium on Hardware Oriented Security and Trust , 2017
2017
Closest in time.
F. Brasser, L. Davi, D. Gens, C. Liebchen, and A.-R. Sadeghi, “CAn’t touch this: Software-only mitigation against Rowhammer attacks targeting kernel memory,” in USENIX Security Symposium , 2017
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2016
Cited alongside, same era.
T. Barry, D. Couroussé, and B. Robisson, “Compilation of a countermeasure against instruction-skip fault attacks,” in Workshop on Cryptography and Security in Computing Systems , 2016
2016
Cited alongside, same era.
S. Bhattacharya and D. Mukhopadhyay, “Curious Case of Rowhammer: Flipping Secret Exponent Bits Using Timing Analysis,” in CHES , 2016
2016
Cited alongside, same era.
E. Bosman, K. Razavi, H. Bos, and C. Giuffrida, “Dedup Est Machina: Memory Deduplication as an Advanced Exploitation Vector,” in S&P , 2016
2016
Cited alongside, same era.
H. Brekalo, R. Strackx, and F. Piessens, “Mitigating password database breaches with Intel SGX,” in Workshop on System Software for Trusted Execution , 2016
2016
Cited alongside, same era.
J. Corbet, “Defending against Rowhammer in the kernel,” Oct. 2016. [Online]. Available: https://lwn.net/Articles/704920/
2016
Cited alongside, same era.
V. Costan and S. Devadas, “Intel SGX explained,” Cryptology ePrint Archive, Report 2016/086, 2016
2016
Cited alongside, same era.
D. Gruss, C. Maurice, A. Fogh, M. Lipp, and S. Mangard, “Prefetch Side-Channel Attacks: Bypassing SMAP and Kernel ASLR,” in CCS , 2016
2016
Cited alongside, same era.
2017
Closest in time.
F. Brasser, U. Müller, A. Dmitrienko, K. Kostiainen, S. Capkun, and A.-R. Sadeghi, “Software grand exposure: SGX cache attacks are practical,” in Usenix WOOT , 2017
2017
Closest in time.
Z. Chen, J. Shen, A. Nicolau, A. Veidenbaum, N. F. Ghalaty, and R. Cammarota, “CAMFAS: A compiler approach to mitigate fault attacks via enhanced SIMDization,” in Workshop on Fault Diagnosis and Tolerance in Cryptography (FDTC) , 2017
2017
Closest in time.
——, “kvm-sgx,” 2017. [Online]. Available: https://github.com/01org/kvm-sgx
2017
Closest in time.
——, “qemu-sgx,” 2017. [Online]. Available: https://github.com/01org/qemu-sgx
2017
Closest in time.
——, “xen-sgx,” 2017. [Online]. Available: https://github.com/01org/xen-sgx
2017
Closest in time.
G. Irazoqui, T. Eisenbarth, and B. Sunar, “MASCAT: Stopping microarchitectural attacks before execution,” Cryptology ePrint Archive, Report 2016/1196, 2017
2017
Closest in time.
Y. Jang, J. Lee, S. Lee, and T. Kim, “SGX-Bomb: Locking down the processor via Rowhammer attack,” in SysTEX , 2017
2017
Closest in time.
Jedec Solid State Technology Association, “Low Power Double Data Rate 4,” 2017. [Online]. Available: http://www.jedec.org/standards-documents/docs/jesd209-4b
2017
Closest in time.
F. Kerschbaum and A.-R. Sadeghi, “HardIDX: Practical and secure index with SGX,” in Data and Applications Security and Privacy XXXI: 31st Annual IFIP WG 11.3 Conference, DBSec 2017 , vol. 10359, 2017, p. 386
2017
Closest in time.
A. Kurmus, N. Ioannou, N. Papandreou, and T. Parnell, “From random block corruption to privilege escalation: A filesystem attack vector for rowhammer-like attacks,” in Usenix WOOT , 2017
2017
Closest in time.
S. Lee, M.-W. Shih, P. Gera, T. Kim, H. Kim, and M. Peinado, “Inferring fine-grained control flow inside SGX enclaves with branch shadowing,” in USENIX Security Symposium , 2017
2017
Closest in time.
Microsoft, “Introducing Azure confidential computing,” 2017. [Online]. Available: https://azure.microsoft.com/en-us/blog/introducing-azure-confidential-computing
2017
Closest in time.
——, “Cache and Memory Manager Improvements,” Apr. 2017. [Online]. Available: https://docs.microsoft.com/en-us/windows-server/administration/performance-tuning/subsystem/cache-memory-management/improvements-in-windows-server
2017
Closest in time.
A. Moghimi, G. Irazoqui, and T. Eisenbarth, “CacheZoom: How SGX amplifies the power of cache attacks,” in CHES 2017 , 2017, pp. 69–90
2017
Closest in time.
O. Mutlu, “The RowHammer problem and other issues we may face as memory becomes denser,” in Design, Automation & Test in Europe Conference & Exhibition (DATE) , 2017
2017
Closest in time.
Red Hat, Red Hat Enterprise Linux 7 - Virtualization Tuning and Optimization Guide , 2017
2017
Closest in time.
M. Schwarz, S. Weiser, D. Gruss, C. Maurice, and S. Mangard, “Malware Guard Extension: Using SGX to Conceal Cache Attacks,” in DIMVA , 2017
2017
Closest in time.
W. Wang, G. Chen, X. Pan, Y. Zhang, X. Wang, V. Bindschaedler, H. Tang, and C. A. Gunter, “Leaky cauldron on the dark land: Understanding memory side-channel hazards in SGX,” in CCS , 2017
2017
Closest in time.
Y. Xiao, M. Li, S. Chen, and Y. Zhang, “Stacco: Differentially analyzing side-channel traces for detecting SSL/TLS vulnerabilities in secure enclaves,” in CCS , 2017
2017
Closest in time.
IBM, “IBM Chipkill Memory: Advanced ECC Memory for the IBM Netfinity 7000 M10,” 2019
2019
Closest in time.