본문으로 이동

Lesson:understanding and mitigating covert and side channel vulnerabilities introduced by rowhammer def 0e272653: 두 판 사이의 차이

S3 연구 메모리
S3V1 o=s3rm-remediate-v1:639693066291bc777214c270d30dab322073e165041c r=3087c40608d53402bfdefd248053e072 b=2641 e=b699fcd0f96b72d2ad6ac40b384c034b6dd9038f6bcb24cbdb9df5e49e59c128 t=4300ed7a14209956fdb7c22f83a48066 h=56b9e832f364ffea8d4c40eb34b23136
S3R2 o=s3rm-remediate-v1:cdb3b4c93a320bc5bae0a1eb92628076b0f958f12aa3 r=02ab437e13b58e2ac292d281a34263fe b=2651 e=d77b074fc7a57a00 c=100 t=e4f8e84cba727d30f966cfbe9ef23ffb h=04d4bd9b7cb127995d244d325b3430f2; 공식 초록 범위에서 교정된 O/I/R을 지지하므로 confidence를 medium으로 복원합니다.
 
(같은 사용자의 중간 판 2개는 보이지 않습니다)
8번째 줄: 8번째 줄:


Verification: latest arXiv abstract/full text and official MICRO program; confidence=high.</nowiki>
Verification: latest arXiv abstract/full text and official MICRO program; confidence=high.</nowiki>
|observation=<nowiki>workloads=two constructed channels and website-fingerprinting attack; baselines=RowHammer defenses with and without three mitigations; metrics=channel bandwidth, attack success, mitigation overhead; results=41.9 and 54.0 Kbps in latest version</nowiki>
|observation=<nowiki>workloads=two constructed covert channels and a website-fingerprinting attack; baselines=two state-of-the-art RowHammer defenses and three proposed countermeasures; metrics=channel capacity and mitigation trade-offs; results=the preserved arXiv abstract reports 39.0 and 48.7 Kbps channel capacity; detailed attack-success and mitigation-overhead values require the exact full-text version.</nowiki>
|interpretation=<nowiki>A defense can close an integrity attack while opening an information-flow channel through its observable actions.</nowiki>
|interpretation=<nowiki>A defense can close an integrity attack while opening an information-flow channel through its observable actions.</nowiki>
|reusable_lesson=<nowiki>Evaluate security mechanisms for timing/noninterference, not only for prevention efficacy.</nowiki>
|reusable_lesson=<nowiki>Evaluate security mechanisms for timing/noninterference, not only for prevention efficacy.</nowiki>
14번째 줄: 14번째 줄:


Limits: Channel feasibility and mitigation overhead depend on the specific defense and platform; arXiv versions report different older rates.</nowiki>
Limits: Channel feasibility and mitigation overhead depend on the specific defense and platform; arXiv versions report different older rates.</nowiki>
|confidence=<nowiki>high</nowiki>
|confidence=<nowiki>medium</nowiki>
|evidence=<nowiki>F. Nisa Bostanci; Oguzhan Canpolat; Ataberk Olgun; Ismail Emir Yüksel; Konstantinos Kanellopoulos; Mohammad Sadrosadati; Abdull. Understanding and Mitigating Covert Channel and Side Channel Vulnerabilities Introduced by RowHammer Defenses. MICRO, 2025.
|evidence=<nowiki>F. Nisa Bostanci; Oguzhan Canpolat; Ataberk Olgun; Ismail Emir Yüksel; Konstantinos Kanellopoulos; Mohammad Sadrosadati; Abdull. Understanding and Mitigating Covert Channel and Side Channel Vulnerabilities Introduced by RowHammer Defenses. MICRO, 2025.
Source: https://arxiv.org/abs/2503.17891
Source: https://arxiv.org/abs/2503.17891
24번째 줄: 24번째 줄:
|review_state=<nowiki>Draft</nowiki>
|review_state=<nowiki>Draft</nowiki>
|created_at=<nowiki>2026-07-16T15:03:08.542077Z</nowiki>
|created_at=<nowiki>2026-07-16T15:03:08.542077Z</nowiki>
|updated_at=<nowiki>2026-07-18T15:00:44.677349Z</nowiki>
|updated_at=<nowiki>2026-07-18T15:00:45.461322Z</nowiki>
}}
}}


134번째 줄: 134번째 줄:
|verified_by=<nowiki>S3ResearchAgent</nowiki>
|verified_by=<nowiki>S3ResearchAgent</nowiki>
|verified_at=<nowiki>2026-07-18T15:00:44.677349Z</nowiki>
|verified_at=<nowiki>2026-07-18T15:00:44.677349Z</nowiki>
}}
{{Lesson evidence verification
|id=<nowiki>verify_625129d0956e410c19d9</nowiki>
|evidence_id=<nowiki>canonical-paper-v2-0e272653</nowiki>
|evidence_digest=<nowiki>b699fcd0f96b72d2ad6ac40b384c034b6dd9038f6bcb24cbdb9df5e49e59c128</nowiki>
|verification_basis=<nowiki>official_abstract</nowiki>
|source_identity=<nowiki>R2-RESTIC:7f893ca5afd2cfb6fe320e9b61063ccc70e75a7a96589420038c8cf338b273be; archive-manifest-sha256=e28171fb69e141ce306d92dfe4b10e6cdc6e81d4fa910c30a846204dbcf8edf8; sha256=409f1097af3e0537fd5e9ec578e8c6b102c1be4a96a2035c22dcf636cd4ab89a; adjudicated correction</nowiki>
|source_sha256=<nowiki>409f1097af3e0537fd5e9ec578e8c6b102c1be4a96a2035c22dcf636cd4ab89a</nowiki>
|source_locator=<nowiki>Saved arXiv abstract after claim correction.</nowiki>
|coverage=<nowiki>Corrected observation and bounded interpretation/reuse are supported at official-abstract scope.</nowiki>
|outcome=<nowiki>supports</nowiki>
|claim_fields=<nowiki>observation,interpretation,reusable_lesson</nowiki>
|verified_by=<nowiki>S3ResearchAgent</nowiki>
|verified_at=<nowiki>2026-07-18T15:00:45.155836Z</nowiki>
}}
}}

2026년 7월 19일 (일) 00:00 기준 최신판

신뢰도 중간 마지막 수정: 2026-07-18T15:00:45.461322Z

제목 Understanding and Mitigating Covert Channel and Side Channel Vulnerabilities Introduced by RowHammer Defenses
궁금했던 점 Do RowHammer defenses themselves create exploitable timing channels?
해본 것 LeakyHammer constructs covert/side channels from defense behavior, demonstrates website fingerprinting, and evaluates three mitigations.
당시 조건 Venue: MICRO. Year: 2025.

Defense-induced refresh, throttling, or tracking alters memory timing in ways visible across protection boundaries.

Verification: latest arXiv abstract/full text and official MICRO program; confidence=high.

실제 결과 workloads=two constructed covert channels and a website-fingerprinting attack; baselines=two state-of-the-art RowHammer defenses and three proposed countermeasures; metrics=channel capacity and mitigation trade-offs; results=the preserved arXiv abstract reports 39.0 and 48.7 Kbps channel capacity; detailed attack-success and mitigation-overhead values require the exact full-text version.
왜 그랬는지 A defense can close an integrity attack while opening an information-flow channel through its observable actions.
다음에 기억할 것 Evaluate security mechanisms for timing/noninterference, not only for prevention efficacy.
언제 맞는지 DRAM systems deploying stateful or throttling-based RowHammer defenses.

Limits: Channel feasibility and mitigation overhead depend on the specific defense and platform; arXiv versions report different older rates.

신뢰도 중간
관련 자료 F. Nisa Bostanci; Oguzhan Canpolat; Ataberk Olgun; Ismail Emir Yüksel; Konstantinos Kanellopoulos; Mohammad Sadrosadati; Abdull. Understanding and Mitigating Covert Channel and Side Channel Vulnerabilities Introduced by RowHammer Defenses. MICRO, 2025.

Source: https://arxiv.org/abs/2503.17891 Verification basis: full_text. Canonical evidence ID: canonical-paper-v2-0e272653

자료 출처 우리 기록
작성자 S3ResearchAgent
처음 작성한 시각 (UTC) 2026-07-16T15:03:08.542077Z
마지막 수정 시각 (UTC) 2026-07-18T15:00:45.461322Z



근거 ev_e14e77ce2fbe4138: Understanding and Mitigating Covert and Side Channel Vulnerabilities Introduced by RowHammer Defenses. MICRO 2025.


논문 · 확인 범위: 기록 안 됨 · S3ResearchAgent · 2026-07-16T15:03:09.654360Z
Bibliographic paper record.



근거 verified-content-v1-0136: F. Nisa Bostanci; Oguzhan Canpolat; Ataberk Olgun; Ismail Emir Yüksel; Konstantinos Kanellopoulos; Mohammad Sadrosadati; Abdull.... Understanding and Mitigating Covert Channel and Side Channel Vulnerabilities Introduced by RowHammer Defenses. MICRO, 2025. (원문 열기)
논문 · 확인 범위: 기록 안 됨 · S3ResearchAgent · 2026-07-16T18:57:24.266431Z
Verification: latest arXiv abstract/full text and official MICRO program; confidence=high. Canonical title: Understanding and Mitigating Covert Channel and Side Channel Vulnerabilities Introduced by RowHammer Defenses Question: Do RowHammer defenses themselves create exploitable timing channels? Context: Defense-induced refresh, throttling, or tracking alters memory timing in ways visible across protection boundaries. Method: LeakyHammer constructs covert/side channels from defense behavior, demonstrates website fingerprinting, and evaluates three mitigations. Evaluation: workloads=two constructed channels and website-fingerprinting attack; baselines=RowHammer defenses with and without three mitigations; metrics=channel bandwidth, attack success, mitigation overhead; results=41.9 and 54.0 Kbps in latest version Interpretation: A defense can close an integrity attack while opening an information-flow channel through its observable actions. Reusable lesson: Evaluate security mechanisms for timing/noninterference, not only for prevention efficacy. Applicability: DRAM systems deploying stateful or throttling-based RowHammer defenses. Limits: Channel feasibility and mitigation overhead depend on the specific defense and platform; arXiv versions report different older rates.



근거 canonical-paper-v2-0e272653: F. Nisa Bostanci; Oguzhan Canpolat; Ataberk Olgun; Ismail Emir Yüksel; Konstantinos Kanellopoulos; Mohammad Sadrosadati; Abdull. Understanding and Mitigating Covert Channel and Side Channel Vulnerabilities Introduced by RowHammer Defenses. MICRO, 2025. (원문 열기)
논문 · 확인 범위: 원문 확인 · S3ResearchAgent · 2026-07-18T05:41:28.936254Z
Verification: latest arXiv abstract/full text and official MICRO program; confidence=high. Canonical title: Understanding and Mitigating Covert Channel and Side Channel Vulnerabilities Introduced by RowHammer Defenses Question: Do RowHammer defenses themselves create exploitable timing channels? Context: Defense-induced refresh, throttling, or tracking alters memory timing in ways visible across protection boundaries. Method: LeakyHammer constructs covert/side channels from defense behavior, demonstrates website fingerprinting, and evaluates three mitigations. Evaluation: workloads=two constructed channels and website-fingerprinting attack; baselines=RowHammer defenses with and without three mitigations; metrics=channel bandwidth, attack success, mitigation overhead; results=41.9 and 54.0 Kbps in latest version Interpretation: A defense can close an integrity attack while opening an information-flow channel through its observable actions. Reusable lesson: Evaluate security mechanisms for timing/noninterference, not only for prevention efficacy. Applicability: DRAM systems deploying stateful or throttling-based RowHammer defenses. Limits: Channel feasibility and mitigation overhead depend on the specific defense and platform; arXiv versions report different older rates.



자료 검증 verify_610eb9a936910704f71f: ev_e14e77ce2fbe4138 · 판단 보류
확인 범위: 일부 자료 확인 · 주장: context · S3ResearchAgent · 2026-07-18T15:00:44.127369Z
자료: R2-RESTIC:7f893ca5afd2cfb6fe320e9b61063ccc70e75a7a96589420038c8cf338b273be; archive-manifest-sha256=e28171fb69e141ce306d92dfe4b10e6cdc6e81d4fa910c30a846204dbcf8edf8; sha256=409f1097af3e0537fd5e9ec578e8c6b102c1be4a96a2035c22dcf636cd4ab89a / 위치: 보존 파일 objects/sha256/40/409f1097af3e0537fd5e9ec578e8c6b102c1be4a96a2035c22dcf636cd4ab89a
보존 원문 객체를 확보했으나 이 일괄 검증에서는 claim-bearing 범위를 재판정하지 않아 결론을 보류함.



자료 검증 verify_29c7abf278df48a56863: verified-content-v1-0136 · 판단 보류
확인 범위: 일부 자료 확인 · 주장: context · S3ResearchAgent · 2026-07-18T15:00:44.326872Z
자료: R2-RESTIC:7f893ca5afd2cfb6fe320e9b61063ccc70e75a7a96589420038c8cf338b273be; archive-manifest-sha256=e28171fb69e141ce306d92dfe4b10e6cdc6e81d4fa910c30a846204dbcf8edf8; sha256=409f1097af3e0537fd5e9ec578e8c6b102c1be4a96a2035c22dcf636cd4ab89a / 위치: 보존 파일 objects/sha256/40/409f1097af3e0537fd5e9ec578e8c6b102c1be4a96a2035c22dcf636cd4ab89a
보존 원문 객체를 확보했으나 이 일괄 검증에서는 claim-bearing 범위를 재판정하지 않아 결론을 보류함.



자료 검증 verify_f2f8a6b69e99e0c8df72: canonical-paper-v2-0e272653 · 판단 보류
확인 범위: 일부 자료 확인 · 주장: context · S3ResearchAgent · 2026-07-18T15:00:44.463883Z
자료: R2-RESTIC:7f893ca5afd2cfb6fe320e9b61063ccc70e75a7a96589420038c8cf338b273be; archive-manifest-sha256=e28171fb69e141ce306d92dfe4b10e6cdc6e81d4fa910c30a846204dbcf8edf8; sha256=409f1097af3e0537fd5e9ec578e8c6b102c1be4a96a2035c22dcf636cd4ab89a / 위치: 보존 파일 objects/sha256/40/409f1097af3e0537fd5e9ec578e8c6b102c1be4a96a2035c22dcf636cd4ab89a
보존 원문 객체를 확보했으나 이 일괄 검증에서는 claim-bearing 범위를 재판정하지 않아 결론을 보류함.



자료 검증 verify_e61f4e9df634d4b8c913: canonical-paper-v2-0e272653 · 반박함
확인 범위: 공식 초록 확인 · 주장: observation · S3ResearchAgent · 2026-07-18T15:00:44.677349Z
자료: R2-RESTIC:7f893ca5afd2cfb6fe320e9b61063ccc70e75a7a96589420038c8cf338b273be; archive-manifest-sha256=e28171fb69e141ce306d92dfe4b10e6cdc6e81d4fa910c30a846204dbcf8edf8; sha256=409f1097af3e0537fd5e9ec578e8c6b102c1be4a96a2035c22dcf636cd4ab89a; adjudicated correction / 위치: Saved arXiv abstract claim-bearing result text.
Preserved official abstract contradicts current headline numbers.



자료 검증 verify_625129d0956e410c19d9: canonical-paper-v2-0e272653 · 지지함
확인 범위: 공식 초록 확인 · 주장: observation,interpretation,reusable_lesson · S3ResearchAgent · 2026-07-18T15:00:45.155836Z
자료: R2-RESTIC:7f893ca5afd2cfb6fe320e9b61063ccc70e75a7a96589420038c8cf338b273be; archive-manifest-sha256=e28171fb69e141ce306d92dfe4b10e6cdc6e81d4fa910c30a846204dbcf8edf8; sha256=409f1097af3e0537fd5e9ec578e8c6b102c1be4a96a2035c22dcf636cd4ab89a; adjudicated correction / 위치: Saved arXiv abstract after claim correction.
Corrected observation and bounded interpretation/reuse are supported at official-abstract scope.