论文标题
DRAMDIG:一种知识辅助工具,用于发现DRAM地址映射
DRAMDig: A Knowledge-assisted Tool to Uncover DRAM Address Mapping
论文作者
论文摘要
由于最近出现的Rowhammer漏洞需要无证件的DRAM地址映射,我们提出了一种通用知识辅助工具Dramdig,该工具将域知识考虑到有效,确定性地在任何基于Intel的机器上有效,确定性地发现DRAM地址映射。我们在许多机器上测试了Dramdig,这些机器的DRAM芯片和微体系结构不同,从英特尔·桑德桥到咖啡湖。与以前的作品相比,Dramdig在所有测试机上平均只有7.8分钟的所有测试机上的逆向工程DRAM地址映射。根据未透明的映射,我们执行了双面的行锤测试,结果表明,DRAMDIG的位比以前的工作明显高,证明了未发现的DRAM地址映射的正确性。
As recently emerged rowhammer exploits require undocumented DRAM address mapping, we propose a generic knowledge-assisted tool, DRAMDig, which takes domain knowledge into consideration to efficiently and deterministically uncover the DRAM address mappings on any Intel-based machines. We test DRAMDig on a number of machines with different combinations of DRAM chips and microarchitectures ranging from Intel Sandy Bridge to Coffee Lake. Comparing to previous works, DRAMDig deterministically reverse-engineered DRAM address mappings on all the test machines with only 7.8 minutes on average. Based on the uncovered mappings, we perform double-sided rowhammer tests and the results show that DRAMDig induced significantly more bit flips than previous works, justifying the correctness of the uncovered DRAM address mappings.