McSee: Evaluating Advanced Rowhammer Attacks and Defenses via Automated DRAM Traffic Analysis

Patrick Jattke

34th USENIX Security Symposium (USENIX Security '25) · Day 3 · Hardware Security 3: Side-Channel and Fault Injection Attacks

Overview

Patrick Jattke's presentation at USENIX Security unveils McSee, a novel platform designed for the automated analysis of DRAM (Dynamic Random-Access Memory) traffic. The talk delves into the escalating "arms race" between advanced Rowhammer attacks and modern hardware defenses, particularly those introduced with the DDR5 standard. McSee provides an unprecedented level of visibility into the low-level interactions between the memory controller and DRAM devices, allowing researchers to precisely evaluate the efficacy of sophisticated Rowhammer attack techniques like sledgehammer and row press, as well as the implementation and behavior of new DDR5 mitigation features such as Refresh Management (RFM) and Probabilistic Row Refresh (PTR).

Watch on YouTube · Slides

Visual summary for McSee: Evaluating Advanced Rowhammer Attacks and Defenses via Automated DRAM Traffic Analysis by Patrick Jattke
Visual summary for McSee: Evaluating Advanced Rowhammer Attacks and Defenses via Automated DRAM Traffic Analysis by Patrick Jattke

Key moments

  1. 0:00 Introduction to DRAM, Rowhammer, and DDR5 features
  2. 2:00 McSee platform goals, design, and capabilities
  3. 3:15 Optimizing McSee's data processing and DDR5 decoding
  4. 4:10 McSee's findings on Sledgehammer multibang attacks
  5. 5:10 Analyzing Rowpress attacks and potential for improvement
  6. 6:00 Evaluating DDR5 Refresh Management (RFM) mitigation
  7. 7:25 Quantifying time to bypass PTR mitigation
  8. 8:20 Conclusion and future research directions with McSee

McSee: Evaluating Advanced Rowhammer Attacks and Defenses via Automated DRAM Traffic Analysis

Speakers: Patrick Jattke

Conference: USENIX Security

YouTube: https://www.youtube.com/watch?v=YFsV_Xpg5-E

Overview

Patrick Jattke's presentation at USENIX Security unveils McSee, a novel platform designed for the automated analysis of DRAM (Dynamic Random-Access Memory) traffic. The talk delves into the escalating "arms race" between advanced Rowhammer attacks and modern hardware defenses, particularly those introduced with the DDR5 standard. McSee provides an unprecedented level of visibility into the low-level interactions between the memory controller and DRAM devices, allowing researchers to precisely evaluate the efficacy of sophisticated Rowhammer attack techniques like sledgehammer and row press, as well as the implementation and behavior of new DDR5 mitigation features such as Refresh Management (RFM) and Probabilistic Row Refresh (PTR).

The core motivation behind McSee is to address the opaque nature of Rowhammer exploitation and mitigation. Attackers are constantly devising more complex hammering patterns, while memory manufacturers introduce new defenses, often without clear public documentation on their operational specifics or real-world effectiveness. McSee bridges this knowledge gap by offering a flexible, high-speed, and accessible platform for capturing and decoding DDR5 bus traffic at a command level. This enables empirical validation of attack hypotheses and the discovery of unexpected mitigation behaviors in commercial off-the-shelf (COTS) hardware, providing crucial insights for both offensive and defensive security research.

This work is critical because Rowhammer remains a persistent and potent threat, capable of inducing bit flips in memory that can lead to privilege escalation or data corruption. By systematically analyzing DRAM traffic, McSee provides concrete data on how different hammering patterns manifest on the memory bus and how various mitigation strategies respond. The findings presented challenge existing assumptions about certain attack vectors and expose the current state of DDR5 defense adoption, offering actionable intelligence for memory controller designers, system architects, and security practitioners to build more resilient systems against this fundamental hardware vulnerability.

Background

▶ Watch: Introduction to DRAM, Rowhammer, and DDR5 features (0:00)

To understand the significance of McSee, it's essential to first grasp the fundamentals of DRAM and the Rowhammer vulnerability. Modern computer systems rely heavily on DRAM for main memory, where data is stored in millions of tiny capacitors arranged in a grid of rows and columns within DRAM banks. Each capacitor holds an electrical charge representing a bit (0 or 1). To prevent charge leakage and data loss, these capacitors must be periodically refreshed.

Rowhammer is a memory disturbance error that arises when a DRAM row (the "aggressor row") is repeatedly accessed in quick succession. This rapid, localized electrical activity can cause charge leakage in physically adjacent rows (the "victim rows"), leading to bit flips – a 0 changing to a 1, or vice versa. The classic attack pattern involves "double-sided hammering," where two aggressor rows, separated by a single victim row, are repeatedly accessed to maximize the disturbance on the victim. These bit flips, while seemingly random, can be strategically exploited by attackers to alter critical system data, bypass security mechanisms, or gain unauthorized privileges.

The problem has evolved into an "arms race." On the offensive side, researchers have developed increasingly sophisticated attacks:

  • Sledgehammer: A technique that hammers multiple banks in parallel to trigger more bit flips and facilitate exploitation, aiming to overcome per-bank mitigation strategies.
  • Row press: An attack that aims to keep DRAM rows open for longer durations, potentially increasing the disturbance effect and the likelihood of bit flips.

On the defensive side, memory manufacturers and CPU vendors have introduced various mitigations:

  • TR-based mitigations: Early defenses focused on increasing refresh rates or employing Target Row Refresh (TRR), which attempts to identify and refresh potentially vulnerable rows.
  • DDR5 Standard Changes: The DDR5 standard, introduced in November 2020, brought several architectural changes relevant to Rowhammer:
  • Split DIMs: DIMMs are now split into two sub-channels, potentially affecting how hammering patterns propagate.
  • Fine Granularity Refresh Mode: Allows refreshes to be sent to single banks only, but twice as often, theoretically offering more precise protection.
  • Refresh Management (RFM): A new optional feature where the DRAM device itself uses per-bank activation counters. When a certain activation threshold (RAA IMT - Rolling Accumulated Activation Initial Management Threshold) is reached for a row, the memory controller sends RFM commands to the DIM to decrease the counter and potentially trigger internal refreshes. This offloads some mitigation logic to the DRAM device.
  • Probabilistic Row Refresh (PTR) / Adaptive Row Refresh (ARR): Memory controller-based mitigations that probabilistically refresh rows adjacent to frequently accessed aggressor rows.

Despite these advancements, the effectiveness and real-world deployment of these DDR5 features, especially the optional ones, have remained largely unknown. The lack of transparency into DRAM internal mechanisms and memory controller behavior makes it challenging for researchers to precisely evaluate attack efficacy or validate defense implementations. This opacity perpetuates the "arms race in the dark," hindering the development of robust, verifiable security solutions. McSee directly addresses this challenge by providing the necessary visibility into the DRAM command bus.

Key Findings

▶ Watch: Optimizing McSee's data processing and DDR5 decoding (3:15)

The McSee platform enabled several critical discoveries regarding both advanced Rowhammer attacks and the state of DDR5 defenses on COTS hardware:

1. Sledgehammer Attack Optimization and Hypothesis Invalidation:

  • Optimal Bank Hammering: Through detailed analysis of DRAM traffic on an Intel Coffee Lake machine, McSee demonstrated that hammering up to six banks in parallel is beneficial for maximizing total activations. Beyond six banks, the activation rate per bank drastically drops, which could make bypassing TRR mitigations more difficult. This provides concrete guidance for attackers on optimizing sledgehammer patterns for specific hardware.
  • Activation Reordering: The research invalidated a previous hypothesis suggesting that hammering more banks would lead to less activation reordering (the memory controller rearranging commands). McSee found the opposite: increasing the number of hammered banks from one to seven resulted in up to 6.7 times more activation reordering. This finding is significant because increased reordering can make Rowhammer attacks less predictable and harder to execute effectively, challenging a key assumption in prior work.

2. Row Press Effectiveness on Real Systems:

  • Limited Impact: While previous work on row press suggested a potential for significantly extending row open times (up to 17.6x), McSee's analysis on a real Intel Coffee Lake system with the same DIM revealed a much smaller impact. The average row open time only decreased by 2x when using the most effective row press pattern.
  • Potential for Improvement: This discrepancy highlights that while row press might be theoretically potent, its practical implementation on real systems is currently limited. The findings suggest that there is "still a lot of potential to improve row press attacks on real systems," implying that current CPU memory controllers or DRAM devices might inherently limit the duration a row can be kept open, or that attack patterns need further refinement to bypass these implicit controls.

3. DDR5 Refresh Management (RFM) Adoption:

  • Low Adoption by DIMs: McSee's custom DDR5 SPD decoder revealed that while most DDR5 devices report valid RFM values (RAA IMT and RAA MMT), only one out of 30 DIMs in the test pool actually required RFM. This indicates a very low adoption rate of this optional, hardware-level mitigation by DRAM manufacturers in the tested samples.
  • Lack of Memory Controller Support: Even for the DIM that required RFM, the analysis across Intel Alder Lake, Raptor Lake, and AMD Zen 4 systems showed no RFM commands being issued by the memory controllers. This suggests that current CPU memory controllers from these major vendors do not actively utilize or support the RFM feature, rendering it ineffective even if a DIM technically supports it.

4. Discovery of Probabilistic Row Refresh (PTR) in Intel CPUs:

  • Implicit Mitigation: While RFM was not observed, McSee unexpectedly discovered that Intel Alder Lake and Raptor Lake CPUs employ an implicit memory controller-based mitigation resembling Probabilistic Row Refresh (PTR). Aggressor-adjacent rows were sometimes activated even when the test code never explicitly accessed them, indicating an automatic refresh mechanism.
  • Quantifying PTR Efficacy: Through repeated experiments hammering two aggressor rows, McSee quantified the probability of an aggressor-adjacent row being refreshed by PTR at 0.091% per block of 8K activations. This is a small but measurable probability that impacts Rowhammer attack success.
  • PTR Bypass Times: Based on this probability, McSee calculated the time required to "naively" bypass PTR and achieve a 50% attack success probability:
  • 1 week for devices with a Rowhammer threshold of 18.8K activations.
  • 1 day for devices with a threshold of 16.7K activations.
  • 1 hour for devices with a threshold of 13.2K activations.

This demonstrates that while PTR increases the time to succeed, it does not completely stop Rowhammer attacks; it merely acts as a deterrent that can be overcome with sufficient time and persistent hammering.

Overall, McSee's key findings provide empirical, bus-level evidence that clarifies the effectiveness of advanced Rowhammer attacks and exposes the current, often limited, state of DDR5 mitigation deployment in real-world systems.

Technical Deep Dive

▶ Watch: Analyzing Rowpress attacks and potential for improvement (5:10)

The core of this research is the McSee platform, a sophisticated hardware-software co-design built for automated DRAM traffic analysis at the command level. The platform was designed with three primary goals:

  1. Suitability for DDR5: Capable of handling the high speeds, multiple channels, and complex protocols of DDR5.
  2. Flexibility: Adaptable to different DRAM form factors and standards.
  3. Accessibility: Relying on hardware potentially available in academic settings.

McSee Platform Architecture:

The platform consists of several key hardware components:

  • High-Speed Oscilloscope: The central component for capturing high-frequency electrical signals from the DRAM bus. It supports up to 80 digital signals, necessary for comprehensive DDR5 bus monitoring.
  • Digitizer: Converts the analog signals captured by the oscilloscope into digital data.
  • Analog Probe: Used to synchronize the workload execution with the triggering of the oscilloscope, ensuring that the captured bus traffic corresponds precisely to the intended software-driven actions.
  • Soldering Leads: These are meticulously soldered to a custom DDR5 UDI (User Debug Interface) interposer. This interposer sits between the CPU memory controller and the DDR5 DIMM, providing access points to tap into the high-speed DDR5 command/address bus signals without disrupting normal operation.

Data Processing Pipeline Optimization:

Capturing raw DDR5 bus traffic generates an immense volume of data. To make McSee practically usable, significant optimizations were required for the data processing pipeline:

  1. Custom Data Output Format: Instead of the default, slow CSV format, a different data output format named XMLIC was utilized. This format is more efficient for high-speed data transfer.
  2. Custom Converter: The vendor's base studio converter for XMLIC was found to be too slow, so a custom converter was developed, significantly improving conversion speed.
  3. Network Card Upgrade: The network card connecting the capture hardware to the processing server was upgraded to facilitate faster file transfers of the large captured traces.
  4. Parallelization: The conversion and decoding processes were parallelized, distributing the computational load and further accelerating the analysis.

These optimizations collectively achieved a 16x speed-up in the data processing pipeline, transforming McSee from a theoretically capable system into a practically usable research tool.

DDR5 Bus Decoding:

A major technical challenge was accurately decoding the complex DDR5 bus protocol. DDR5 introduces particularities such as multicycle commands, where a single logical command can span multiple clock cycles or bus transfers. The research team developed a custom DDR5 decoder that is platform agnostic and open source. This decoder interprets the raw digital signals captured from the bus, reconstructing the actual DRAM commands (e.g., ACTIVATE, READ, WRITE, REFRESH) and their associated addresses and timing. The decoder's availability in the project artifacts enhances reproducibility and accessibility for other researchers.

Applying McSee to Attack Analysis:

  • Sledgehammer: McSee was used to capture traces while an Intel Coffee Lake machine hammered one to 16 banks. By analyzing the decoded commands, the researchers could precisely count total activations, activations per bank, and crucially, measure the distance between consecutive activations to the same aggressor pairs. This allowed for the quantification of activation reordering and the identification of optimal hammering bank counts.
  • Row Press: For row press analysis, McSee measured the "average row open time" (takon) by observing the duration between an ACTIVATE command and the subsequent PRECHARGE command for a given row. This was compared against the AC min (minimum active-to-precharge time) degrees reported in prior work, revealing the actual reduction in row open time on a real system.

Applying McSee to Defense Analysis:

  • RFM Analysis: The team first developed a custom DDR5 SPD (Serial Presence Detect) decoder to read out the RFM parameters from DIMMs. These parameters include whether RFM is required by the DIM, the RAA IMT (Rolling Accumulated Activation Initial Management Threshold), and the RAA MMT (Maximum Management Threshold). Subsequently, McSee was used to monitor the bus traffic on Intel Alder Lake, Raptor Lake, and AMD Zen 4 systems during Rowhammer experiments. The absence of specific RFM commands on the bus directly indicated whether the memory controller was engaging this mitigation.
  • PTR Analysis: The unexpected observation of aggressor-adjacent rows being activated without explicit software commands led to the investigation of PTR. McSee captured numerous traces of specific hammering patterns (e.g., 8K activations with CL flush and NOPs between hammers) and then analyzed the decoded commands for unexpected ACTIVATE commands to rows adjacent to the aggressors. By repeating this experiment 512 times, the researchers collected enough data to fit the observed PTR events to a binomial distribution, thereby quantifying the probability of a PTR-induced refresh. This probabilistic understanding allowed for the calculation of how long it would take to achieve a 50% attack success probability, providing a concrete measure of PTR's effectiveness as a delay mechanism.

This detailed technical approach, combining specialized hardware capture with optimized software decoding and analysis, is what makes McSee a powerful tool for demystifying the complex interactions at the DRAM interface.

Demo / Proof of Concept

▶ Watch: Evaluating DDR5 Refresh Management (RFM) mitigation (6:00)

While the talk did not feature a live, interactive demo in the traditional sense, the entire presentation is a demonstration of McSee's capabilities through the extensive experimental results and validations performed. The research effectively serves as a proof of concept for using automated DRAM traffic analysis to evaluate advanced Rowhammer attacks and defenses on real hardware.

The "demo" can be understood through the following experimental validations:

  1. Sledgehammer Optimization and Reordering:
  • Setup: An Intel Coffee Lake machine was used, running specific Rowhammer code designed to hammer a variable number of banks (from 1 to 16).
  • Methodology: McSee captured the DDR5 command/address bus traffic during these experiments. The custom decoder parsed the raw bus signals into logical DRAM commands.
  • Proof: The analysis clearly showed how "total activation throughput" increased up to six banks, and then activations per bank dropped. More significantly, by analyzing the timestamps and addresses of consecutive ACTIVATE commands, McSee precisely measured the distance between them, revealing up to 6.7 times more activation reordering when increasing the number of hammered banks. This directly demonstrated McSee's ability to quantify subtle memory controller behaviors in response to attack patterns.
  1. Row Press Effect on Real Systems:
  • Setup: The same Intel Coffee Lake machine and specific DIM used in the original row press research were employed.
  • Methodology: After reproducing the original row press bit flips as a sanity check, McSee was used to measure the average row open time (takon). This involved observing the duration between ACTIVATE and PRECHARGE commands for the targeted rows after a fixed number of cache block reads.
  • Proof: The results showed that the AC min (active-to-precharge time) only decreased by 2x, a stark contrast to the 17.6x reported in prior work for the most effective row press pattern. This empirical measurement directly validated the limited practical impact of row press on the tested real system, showcasing McSee's capability to provide ground truth data on attack efficacy.
  1. RFM and PTR Mitigation Analysis:
  • Setup: A pool of 30 DDR5 DIMMs and three different CPU systems (Intel Alder Lake, Raptor Lake, and AMD Zen 4) were used.
  • Methodology:
  • For RFM, McSee first used its custom SPD decoder to read RFM parameters from the DIMMs. Then, Rowhammer experiments were run on the CPU systems while McSee monitored for RFM commands on the bus.
  • For PTR, specific double-sided Rowhammer patterns (hammering two aggressor rows for 8K activations, repeated 512 times, with CL flush and NOPs) were executed. McSee captured the full bus traffic.
  • Proof: The absence of RFM commands on any system, even with a DIM requiring RFM, demonstrated the lack of memory controller support. For PTR, the analysis of the 512 repeated experiments allowed for the statistical quantification of the probability of an aggressor-adjacent row being refreshed (0.091%). This data then enabled the calculation of time-to-bypass, serving as a concrete demonstration of how McSee can discover and quantify implicit hardware mitigations.

These experiments, meticulously documented and quantified through McSee's analysis, collectively serve as a robust proof of concept for the platform's ability to shed light on the complex, often hidden, dynamics of Rowhammer attacks and defenses.

Defensive Implications

▶ Watch: Conclusion and future research directions with McSee (8:20)

The findings from McSee have several critical implications for defenders, memory controller designers, and system architects:

  1. Re-evaluate Rowhammer Mitigation Strategies: The discovery that Refresh Management (RFM) is largely unimplemented by both DIM manufacturers (low "required RFM" flag) and major CPU memory controllers (no RFM commands observed) is a significant concern. RFM was designed to provide a hardware-level, per-bank mitigation. Its absence means systems are not benefiting from this intended layer of defense, forcing reliance on other, potentially less effective, mechanisms. Defenders should advocate for the full implementation and activation of optional DDR5 mitigation features.
  1. Understand PTR as a Delay Tactic, Not a Complete Stop: The identification and quantification of Probabilistic Row Refresh (PTR) in Intel Alder Lake and Raptor Lake CPUs is a crucial insight. While PTR does increase the time required for a Rowhammer attack to succeed (from hours to days or even weeks for certain thresholds), it does not fully prevent the attack. Defenders must understand that PTR is a probabilistic deterrent, not a complete safeguard. This implies that systems with high-value data or stringent security requirements may still be vulnerable over longer attack durations, or to more sophisticated attacks that can bypass PTR more efficiently.
  1. Prioritize Memory Controller-Based Defenses: Given the low adoption of DIM-level RFM, memory controller-based mitigations like PTR become even more critical. System designers and CPU manufacturers should focus on strengthening and improving these controller-side defenses. Research into deterministic, rather than probabilistic, Rowhammer mitigations at the memory controller level is highly warranted.
  1. Awareness of Attack Optimization: The finding that hammering up to six banks is optimal for maximizing activations on an Intel Coffee Lake system provides attackers with a clear optimization strategy. Defenders need to be aware that attackers will likely target these optimal patterns. Mitigation strategies that are effective against single-bank or fewer-bank hammering might be less effective against these multi-bank optimized attacks.
  1. Reconsider Row Press Effectiveness: The finding that row press has a limited effect on real systems (only 2x reduction in AC min compared to 17.6x) offers a temporary reprieve for defenders. While this doesn't mean row press should be ignored, it suggests that its immediate threat level on current COTS hardware might be lower than previously theorized. However, the researchers also noted "potential for improvement" in row press attacks, meaning future iterations could become more potent. Defenders should monitor research in this area and not become complacent.
  1. Demand Greater Transparency: The entire McSee project underscores the need for greater transparency from hardware vendors regarding the implementation and operational specifics of Rowhammer mitigations. Without tools like McSee, defenders are operating in the dark. Standardized mechanisms for querying mitigation status, thresholds, and activation logs from DRAM devices and memory controllers would greatly aid in building verifiable secure systems.
  1. Future-Proofing Against Evolving Attacks: The "arms race" nature of Rowhammer means new attack techniques will continue to emerge. Platforms like McSee are essential for continuous evaluation. Defenders should support research into automated analysis tools to stay ahead of the curve and validate the effectiveness of new mitigation features (e.g., DRFM or PRA) as they become available.

In summary, defenders should not solely rely on the presence of "DDR5" as a guarantee of Rowhammer immunity. A nuanced understanding of which mitigations are truly active, their specific behaviors, and their limitations, as revealed by McSee, is crucial for building robust and resilient systems.

Key Takeaways

  • McSee is a powerful, open-source platform for automated, command-level DDR5 DRAM traffic analysis, enabling empirical evaluation of Rowhammer attacks and defenses.
  • Sledgehammer attacks are most effective when hammering around six banks in parallel on tested Intel Coffee Lake systems, and contrary to prior hypotheses, more banks lead to significantly more activation reordering (up to 6.7x).
  • Row press attacks have limited practical impact on current real systems, achieving only a 2x reduction in row open time compared to a theoretical 17.6x, indicating potential for attack improvement.
  • DDR5's Refresh Management (RFM) mitigation is largely inactive: Most DIMs do not require it, and Intel Alder Lake, Raptor Lake, and AMD Zen 4 memory controllers do not issue RFM commands.
  • Intel Alder Lake and Raptor Lake CPUs employ a Probabilistic Row Refresh (PTR) mitigation, refreshing aggressor-adjacent rows with a probability of 0.091% per 8K activations.
  • PTR delays, but does not prevent, Rowhammer attacks: It can be bypassed within hours to weeks, depending on the Rowhammer threshold, meaning it increases time-to-exploit rather than fully stopping the attack.

About the Speaker(s)

The talk was presented by Patrick Jattke. Based on the technical depth and research presented at USENIX Security, Patrick Jattke is a researcher likely affiliated with an academic institution or a research-focused organization specializing in computer architecture, memory security, and hardware vulnerabilities. His work on McSee demonstrates expertise in low-level hardware analysis, reverse engineering of memory protocols, and the development of sophisticated tools for security evaluation.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Jattke brings a hardware measurement platform that actually closes the empirical gap in Rowhammer research — no more arguing from simulation or vendor spec sheets, you're reading the real bus. The RFM non-adoption finding alone (zero RFM commands across Intel Alder Lake, Raptor Lake, and AMD Zen 4 despite DDR5 ostensibly supporting it) is the kind of uncomfortable ground truth that should embarrass multiple teams at Intel and AMD simultaneously.

Heather Calloway (CISO) — WEAK

Technically rigorous work that produces real findings — RFM is largely unimplemented, PTR is probabilistic and bypassable, row press is weaker in practice than theory. But this is a research platform paper aimed at other hardware security researchers, and it never makes the jump to institutional relevance. The defensive implications section is bolted on, not integrated.

→ Top-rated talks at 34th USENIX Security Symposium (USENIX Security '25)

All talks from 34th USENIX Security Symposium (USENIX Security '25)