Overview
Syllabus
Intro
Landscape of Rowhammer
Rowhammer Primer
Two Key Requirements for Rowhammer Testing
Challenges in Generating Highest Rate of ACTS
Typical Rowhammer Instruction Sequence
Rate of ACTs from Previous Instruction Sequences
Our Near-Optimal Instruction Sequence on Skylake
Determining Physically Adjacent Rows
Previous Reverse-Engineering Methodology Relies on Rowhammer
Mount a Devastating Rowhammer by Masking Refreshes (REF)
Fault Injector that Masks Refresh Commands
Our Complete Hardware Stack
Row Adjacency Map
Key Takeaways
An end-to-end methodology to test if any cloud server is susceptible to Rowhammer
Taught by
IEEE Symposium on Security and Privacy