RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    Investigating and Improving DRAM-Based Memory System Security by Analyzing and Exploiting DRAM Operations = DRAM 동작 분석 및 활용을 통한 DRAM 기반 메모리 시스템 보안 분석 및 개선

    한글로보기

    https://www.riss.kr/link?id=T17314888

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    국문 초록 (Abstract) kakao i 다국어 번역

    DRAM (Dynamic Random-Access Memory)은 현대 컴퓨터 시스템에서 가장 일반적으로 사용되는 주기억장치이며, 전체적인 시스템의 성능, 신뢰성, 그리고 보안에 직접적으로 영향을 미친다. 그러나 DRAM 내부 구조가 점점 더 복잡해지고, DRAM 장치는 메모리 컨트롤러에 의해 동작이 통제되는 주-종속적 인터페이스를 따르기 때문에, 시스템 차원에서 DRAM의 성능 병목, 신뢰성 문제, 그리고 보안 취약점을 체계적으로 분석하는 데 어려움이 있다. 따라서 DRAM 기반 메모리 시스템의 동작을 정확하게 이해하고 분석하는 것은 고신뢰성, 고성능 시스템 설계를 위해 필수적이다. 본 논문은 DRAM 기반 메모리 시스템의 보안성과 신뢰성 향상을 목표로, DRAM의 내부 동작을 체계적으로 분석하고 이를 활용하는 새로운 방법론을 제안한다. 먼저, DRAM 내부 명령어를 활용한 효율적인 데이터 복사 방식을 통해, DRAM의 대표적인 보안 취약점인 로우해머(RowHammer) 공격에 효과적으로 대응할 수 있는 하드웨어 구조를 제안한다. 또한, DRAM 및 메모리 컨트롤러의 동작 특성을 기반으로 시스템 수준의 메모리 접근 지연시간을 분석하고, 이를 활용하여 DRAM 내부 동작을 추론하는 마이크로벤치마크 기반 분석 기법을 제안한다. 이 분석을 바탕으로, 상용 DRAM과 메모리 컨트롤러의 구조와 동작 특성을 밝히는 역공학 기법을 제안한다. 첫째로, DRAM의 대표적인 취약점인 로우해머 공격에 대해 효율적인 방어를 수행하는 하드웨어 기반 DRAM 내부 로우해머 방지 기법 SHADOW를 제안한다. SHADOW는 로우-셔플링(row-shuffling)을 활용하여, DRAM 서브어레이 내 로우 간 물리적 인접성을 동적으로 무작위함으로써, 기존 로우해머 공격과 새롭게 제안된 비인접 로우해머 공격 및 정교한 로우해머 공격 패턴에 대해서 효율적으로 방어한다. SHADOW는 JEDEC 표준의 RFM 인터페이스를 기반으로 DRAM 내부에서 로우-셔플링이 수행되도록 하며, DRAM 내부 명령어 기반의 로우-복사(row-copy)를 통해 효율적으로 DRAM 내부 로우-셔플링을 구현하여, 데이터 이동에 따른 성능 및 에너지 오버헤드를 최소화한다. 제안하는 구조는 서브어레이당 하나의 추가 DRAM 로우를 사용하여 DRAM 로우의 재배치 정보를 효과적으로 관리하고, DRAM 내부 회로를 재활용하여 접근 시간 지연을 최소화한다. 둘째로, DRAM 기반 메모리 시스템의 내부 구조 및 지연시간 특성 분석을 통해, DRAM 주소 매핑을 구성요소 단위의 매핑 함수로 분해하는 새로운 분석 기법을 제안한다. DRAM 주소 매핑을 채널, 랭크, 뱅크 그룹, 뱅크, 로우, 컬럼의 구성요소별 함수로 분해하는 것은 정확한 메모리 동작 이해 및 로우해머 분석을 위해 필수적이다. 그러나 기존 역공학 기법으로는 물리적 접근 없이 이를 수행하는 데 한계가 있다. 이에 본 논문은 DRAM의 리프레시 간격과 연속적인 메모리 접근 패턴을 활용하여 각 구성요소 별 주소 매핑 함수를 추론할 수 있는 지연시간 기반 분석 기법을 제안한다. 이 방법론을 바탕으로, 채널, 랭크, 뱅크 그룹, 뱅크, 로우, 컬럼 비트까지 정확히 식별할 수 있는 소프트웨어 기반의 주소 매핑 역공학 도구 Sudoku를 구현한다. Sudoku의 유효성을 검증하기 위해 최신 Intel 및 AMD 프로세서를 대상으로 실험을 수행하였으며, 복잡한 DRAM 주소 매핑을 구성요소 단위로 성공적으로 분해할 수 있음을 확인하였다. 본 논문에서 제시한 DRAM 내부 명령어 기반 기법과 시스템 수준에서의 DRAM 지연시간 분석 방법은, 현대 DRAM 기반 메모리 시스템의 성능, 보안성, 그리고 신뢰성 향상에 기여할 수 있다. 특히 SHADOW에서 활용한 DRAM을 활용한 데이터 처리 방식인 DRAM 내부 로우 셔플링 기법은, DRAM의 구조적 특성을 활용하여 데이터 무결성과 보안성을 강화할 수 있음을 보여주는 대표적인 사례이다. 또한 Sudoku의 심층적인 DRAM 및 메모리 컨트롤러의 동작 분석 및 주소 매핑 역공학 기법은, 점차 복잡해지는 DRAM 기반 메모리 시스템에 대해 보다 정밀한 성능 및 보안 분석의 기반을 제공한다. 마지막으로, 본 논문에서 개발한 소프트웨어 도구와 실험 결과는 향후 DRAM 구조 분석, 성능 최적화, 그리고 보안 및 신뢰성 강화 연구에 활용 가능한 실용적인 기반을 제공할 것으로 기대된다.
    번역하기

    DRAM (Dynamic Random-Access Memory)은 현대 컴퓨터 시스템에서 가장 일반적으로 사용되는 주기억장치이며, 전체적인 시스템의 성능, 신뢰성, 그리고 보안에 직접적으로 영향을 미친다. 그러나 DRAM 내...

    DRAM (Dynamic Random-Access Memory)은 현대 컴퓨터 시스템에서 가장 일반적으로 사용되는 주기억장치이며, 전체적인 시스템의 성능, 신뢰성, 그리고 보안에 직접적으로 영향을 미친다. 그러나 DRAM 내부 구조가 점점 더 복잡해지고, DRAM 장치는 메모리 컨트롤러에 의해 동작이 통제되는 주-종속적 인터페이스를 따르기 때문에, 시스템 차원에서 DRAM의 성능 병목, 신뢰성 문제, 그리고 보안 취약점을 체계적으로 분석하는 데 어려움이 있다. 따라서 DRAM 기반 메모리 시스템의 동작을 정확하게 이해하고 분석하는 것은 고신뢰성, 고성능 시스템 설계를 위해 필수적이다. 본 논문은 DRAM 기반 메모리 시스템의 보안성과 신뢰성 향상을 목표로, DRAM의 내부 동작을 체계적으로 분석하고 이를 활용하는 새로운 방법론을 제안한다. 먼저, DRAM 내부 명령어를 활용한 효율적인 데이터 복사 방식을 통해, DRAM의 대표적인 보안 취약점인 로우해머(RowHammer) 공격에 효과적으로 대응할 수 있는 하드웨어 구조를 제안한다. 또한, DRAM 및 메모리 컨트롤러의 동작 특성을 기반으로 시스템 수준의 메모리 접근 지연시간을 분석하고, 이를 활용하여 DRAM 내부 동작을 추론하는 마이크로벤치마크 기반 분석 기법을 제안한다. 이 분석을 바탕으로, 상용 DRAM과 메모리 컨트롤러의 구조와 동작 특성을 밝히는 역공학 기법을 제안한다. 첫째로, DRAM의 대표적인 취약점인 로우해머 공격에 대해 효율적인 방어를 수행하는 하드웨어 기반 DRAM 내부 로우해머 방지 기법 SHADOW를 제안한다. SHADOW는 로우-셔플링(row-shuffling)을 활용하여, DRAM 서브어레이 내 로우 간 물리적 인접성을 동적으로 무작위함으로써, 기존 로우해머 공격과 새롭게 제안된 비인접 로우해머 공격 및 정교한 로우해머 공격 패턴에 대해서 효율적으로 방어한다. SHADOW는 JEDEC 표준의 RFM 인터페이스를 기반으로 DRAM 내부에서 로우-셔플링이 수행되도록 하며, DRAM 내부 명령어 기반의 로우-복사(row-copy)를 통해 효율적으로 DRAM 내부 로우-셔플링을 구현하여, 데이터 이동에 따른 성능 및 에너지 오버헤드를 최소화한다. 제안하는 구조는 서브어레이당 하나의 추가 DRAM 로우를 사용하여 DRAM 로우의 재배치 정보를 효과적으로 관리하고, DRAM 내부 회로를 재활용하여 접근 시간 지연을 최소화한다. 둘째로, DRAM 기반 메모리 시스템의 내부 구조 및 지연시간 특성 분석을 통해, DRAM 주소 매핑을 구성요소 단위의 매핑 함수로 분해하는 새로운 분석 기법을 제안한다. DRAM 주소 매핑을 채널, 랭크, 뱅크 그룹, 뱅크, 로우, 컬럼의 구성요소별 함수로 분해하는 것은 정확한 메모리 동작 이해 및 로우해머 분석을 위해 필수적이다. 그러나 기존 역공학 기법으로는 물리적 접근 없이 이를 수행하는 데 한계가 있다. 이에 본 논문은 DRAM의 리프레시 간격과 연속적인 메모리 접근 패턴을 활용하여 각 구성요소 별 주소 매핑 함수를 추론할 수 있는 지연시간 기반 분석 기법을 제안한다. 이 방법론을 바탕으로, 채널, 랭크, 뱅크 그룹, 뱅크, 로우, 컬럼 비트까지 정확히 식별할 수 있는 소프트웨어 기반의 주소 매핑 역공학 도구 Sudoku를 구현한다. Sudoku의 유효성을 검증하기 위해 최신 Intel 및 AMD 프로세서를 대상으로 실험을 수행하였으며, 복잡한 DRAM 주소 매핑을 구성요소 단위로 성공적으로 분해할 수 있음을 확인하였다. 본 논문에서 제시한 DRAM 내부 명령어 기반 기법과 시스템 수준에서의 DRAM 지연시간 분석 방법은, 현대 DRAM 기반 메모리 시스템의 성능, 보안성, 그리고 신뢰성 향상에 기여할 수 있다. 특히 SHADOW에서 활용한 DRAM을 활용한 데이터 처리 방식인 DRAM 내부 로우 셔플링 기법은, DRAM의 구조적 특성을 활용하여 데이터 무결성과 보안성을 강화할 수 있음을 보여주는 대표적인 사례이다. 또한 Sudoku의 심층적인 DRAM 및 메모리 컨트롤러의 동작 분석 및 주소 매핑 역공학 기법은, 점차 복잡해지는 DRAM 기반 메모리 시스템에 대해 보다 정밀한 성능 및 보안 분석의 기반을 제공한다. 마지막으로, 본 논문에서 개발한 소프트웨어 도구와 실험 결과는 향후 DRAM 구조 분석, 성능 최적화, 그리고 보안 및 신뢰성 강화 연구에 활용 가능한 실용적인 기반을 제공할 것으로 기대된다.

    더보기

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    Dynamic Random-Access Memory (DRAM) is the most commonly used main memory device in modern computer systems, directly determining overall system performance, reliability, and security. However, the increasing complexity of DRAM architectures, coupled with the limited visibility and control provided by the primary-secondary interface, hinders system-level analysis of performance, reliability, and security. Therefore, it is essential to have a precise understanding and analysis of the behavior of DRAM-based main memory systems to design high-performance, highly reliable, and secure computing systems. This dissertation proposes novel techniques to improve the security and reliability of DRAM-based memory systems through a systematic analysis and utilization of DRAM internal operations. First, we propose a new DRAM architecture designed to mitigate the RowHammer vulnerability, a representative reliability and security threat in DRAM.This architecture leverages internal DRAM commands to facilitate efficient in-DRAM data copying. Next, we analyze the system-level memory access latency based on the behaviors of DRAM and memory controllers. We also develop microbenchmarks that infer DRAM internal operations. Building upon this analysis, we introduce a reverse-engineering technique to uncover the structural and operational characteristics of commercial DRAM and memory controllers. First, we propose a new in-DRAM RowHammer protection solution named Shuffling Aggressor DRAM Rows (SHADOW). SHADOW dynamically randomizes DRAM row mapping information, mitigating newly introduced non-adjacent RowHammer attacks and preventing an attacker from targeting a specific victim row that may hold critical data. SHADOW also utilizes the recently introduced JEDEC RFM interface to enable in-DRAM RowHammer mitigation without any DRAM interface changes. To realize the in-DRAM row-shuffle operation with low performance and energy overhead, we introduce novel DRAM microarchitecture optimization techniques. We demonstrate the strong probabilistic protection of SHADOW against RowHammer attacks through adversarial pattern analysis and highlight the compelling performance, area, and energy overheads compared to those of state-of-the-art hardware-based RowHammer prevention solutions. Second, we present a timing-based analysis method based on an in-depth understanding of the memory system's internal structure, behavior, and timing characteristics. Decomposing DRAM address mappings into component-level functions is critical for understanding memory behavior and enabling precise RowHammer attacks, yet existing reverse-engineering methods fall short. We introduce novel timing-based techniques leveraging DRAM refresh intervals and consecutive access latencies to infer component-specific functions. Based on this, we present Sudoku, the first software-based tool to automatically decompose full DRAM address mappings into channel, rank, bank group, and bank functions while identifying row and column bits. We validate Sudoku's effectiveness by successfully decomposing mappings on recent Intel and AMD processors. These proposed approaches, which utilize internal DRAM commands and analyze system-level memory access latency based on DRAM's internal structure and behavior, can enhance the performance, security, and reliability of modern DRAM-based memory systems. The proposed SHADOW demonstrates that processing-using-memory techniques, such as in-DRAM row-copy operations, can be utilized not only to improve system performance but also to enhance security and reliability. Additionally, our detailed analysis of DRAM and memory controller behavior, along with our latency-based reverse-engineering methodology, can provide a foundation for precise evaluations of performance, security, and reliability in increasingly complex DRAM-based memory systems. Moreover, the provided software tool and experimental results provide valuable references for future research and development in DRAM-based memory systems.
    번역하기

    Dynamic Random-Access Memory (DRAM) is the most commonly used main memory device in modern computer systems, directly determining overall system performance, reliability, and security. However, the increasing complexity of DRAM architectures, coupled ...

    Dynamic Random-Access Memory (DRAM) is the most commonly used main memory device in modern computer systems, directly determining overall system performance, reliability, and security. However, the increasing complexity of DRAM architectures, coupled with the limited visibility and control provided by the primary-secondary interface, hinders system-level analysis of performance, reliability, and security. Therefore, it is essential to have a precise understanding and analysis of the behavior of DRAM-based main memory systems to design high-performance, highly reliable, and secure computing systems. This dissertation proposes novel techniques to improve the security and reliability of DRAM-based memory systems through a systematic analysis and utilization of DRAM internal operations. First, we propose a new DRAM architecture designed to mitigate the RowHammer vulnerability, a representative reliability and security threat in DRAM.This architecture leverages internal DRAM commands to facilitate efficient in-DRAM data copying. Next, we analyze the system-level memory access latency based on the behaviors of DRAM and memory controllers. We also develop microbenchmarks that infer DRAM internal operations. Building upon this analysis, we introduce a reverse-engineering technique to uncover the structural and operational characteristics of commercial DRAM and memory controllers. First, we propose a new in-DRAM RowHammer protection solution named Shuffling Aggressor DRAM Rows (SHADOW). SHADOW dynamically randomizes DRAM row mapping information, mitigating newly introduced non-adjacent RowHammer attacks and preventing an attacker from targeting a specific victim row that may hold critical data. SHADOW also utilizes the recently introduced JEDEC RFM interface to enable in-DRAM RowHammer mitigation without any DRAM interface changes. To realize the in-DRAM row-shuffle operation with low performance and energy overhead, we introduce novel DRAM microarchitecture optimization techniques. We demonstrate the strong probabilistic protection of SHADOW against RowHammer attacks through adversarial pattern analysis and highlight the compelling performance, area, and energy overheads compared to those of state-of-the-art hardware-based RowHammer prevention solutions. Second, we present a timing-based analysis method based on an in-depth understanding of the memory system's internal structure, behavior, and timing characteristics. Decomposing DRAM address mappings into component-level functions is critical for understanding memory behavior and enabling precise RowHammer attacks, yet existing reverse-engineering methods fall short. We introduce novel timing-based techniques leveraging DRAM refresh intervals and consecutive access latencies to infer component-specific functions. Based on this, we present Sudoku, the first software-based tool to automatically decompose full DRAM address mappings into channel, rank, bank group, and bank functions while identifying row and column bits. We validate Sudoku's effectiveness by successfully decomposing mappings on recent Intel and AMD processors. These proposed approaches, which utilize internal DRAM commands and analyze system-level memory access latency based on DRAM's internal structure and behavior, can enhance the performance, security, and reliability of modern DRAM-based memory systems. The proposed SHADOW demonstrates that processing-using-memory techniques, such as in-DRAM row-copy operations, can be utilized not only to improve system performance but also to enhance security and reliability. Additionally, our detailed analysis of DRAM and memory controller behavior, along with our latency-based reverse-engineering methodology, can provide a foundation for precise evaluations of performance, security, and reliability in increasingly complex DRAM-based memory systems. Moreover, the provided software tool and experimental results provide valuable references for future research and development in DRAM-based memory systems.

    더보기

    목차 (Table of Contents)

    • Abstract i
    • Contents iv
    • List of Figures vii
    • List of Tables ix
    • Chapter 1. Introduction 1
    • Abstract i
    • Contents iv
    • List of Figures vii
    • List of Tables ix
    • Chapter 1. Introduction 1
    • 1.1 Research Contributions 4
    • 1.2 Outline 5
    • Chapter 2. Background 7
    • 2.1 DRAM-Based Main Memory Systems 7
    • 2.2 DRAM Operations and Timings 9
    • 2.3 DRAM Read-Disturbance Errors 10
    • 2.4 DRAM Address Mappings 13
    • Chapter 3. Preventing RowHammer in DRAM with Intra-Subarray Row Shuffling 16
    • 3.1 Overview 16
    • 3.2 Threat Model 17
    • 3.3 Related Work 18
    • 3.3.1 RowHammer Mitigating Actions and Blast-Attacks 18
    • 3.3.2 Implementation Locations and Counter Structures 21
    • 3.4 SHADOW 22
    • 3.4.1 Overview 22
    • 3.4.2 High-Level Row-Shuffle Operations 23
    • 3.4.3 Incremental Refresh 25
    • 3.4.4 Implications of Row-Shuffle in DRAM 26
    • 3.5 SHADOW Hardware Architecture 26
    • 3.5.1 Remapping-Row 27
    • 3.5.2 Subarray Pairing 28
    • 3.5.3 SHADOW Controller 30
    • 3.6 SHADOW Detailed Operation and Timing 30
    • 3.6.1 Operation and Timing on ACT 31
    • 3.6.2 Operation and Timing on RFM 31
    • 3.7 Evaluation 36
    • 3.7.1 Security Analysis 36
    • 3.7.2 SPICE Circuit Simulation 40
    • 3.7.3 Performance Overhead Analysis 42
    • 3.7.4 Area and Power Analysis 50
    • 3.8 Discussion 53
    • 3.8.1 Hardware RNG Unit in DRAM 53
    • 3.8.2 Soft Post Package Repair (sPPR) 54
    • 3.8.3 Optimizing RFM Interface 55
    • 3.8.4 Per-Row Activation Counting (PRAC) 55
    • Chapter 4. Decomposing DRAM Address Mapping into Component Functions 57
    • 4.1 Overview 57
    • 4.2 Related Work 58
    • 4.2.1 Reverse-Engineering DRAM Address Mappings 58
    • 4.2.2 Limitations of Prior Reverse-Engineering Methods 60
    • 4.3 Understanding How Systems Configure Memory 61
    • 4.4 Timing Channels for Component Function Identification 64
    • 4.4.1 Refresh Intervals 64
    • 4.4.2 Consecutive Memory Accesses 66
    • 4.5 Sudoku 68
    • 4.5.1 Generating Desired Memory Addresses 69
    • 4.5.2 Validating the System of Hash Functions 70
    • 4.5.3 Decomposing DRAM Address Mappings 71
    • 4.6 Results 73
    • 4.6.1 Results: Intel Core Processor 73
    • 4.6.2 Results: AMD Zen 4 Processor 74
    • 4.7 Discussion 74
    • 4.7.1 Exploiting Memory Error Log 74
    • 4.7.2 Extending Sudoku to Other DRAMs and Hash Functions 75
    • 4.7.3 Use Cases of Sudoku 76
    • Chapter 5. Conclusion 79
    • 5.1 Summary 79
    • 5.2 Future Work 81
    • Bibliography 83
    • 국문초록 114
    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼