Science Current Events | Science News | Brightsurf.com
 
Email a Friend Send to a friend
Printer Friendly Print Attack on computer memory reveals vulnerability of widely-used security systems

Attack on computer memory reveals vulnerability of widely-used security systems

February 22, 2008

A team of academic, industry and independent researchers has demonstrated a new class of computer attacks that compromise the contents of "secure" memory systems, particularly in laptops.

The attacks overcome a broad set of security measures called "disk encryption," which are meant to secure information stored in a computer's permanent memory. The researchers cracked several widely used technologies, including Microsoft's BitLocker, Apple's FileVault and Linux's dm-crypt, and described the attacks in a paper and video published on the Web Feb. 21.




The team reports that these attacks are likely to be effective at cracking many other disk encryption systems because these technologies have architectural features in common.

"We've broken disk encryption products in exactly the case when they seem to be most important these days: laptops that contain sensitive corporate data or personal information about business customers," said Alex Halderman, a Ph.D. candidate in Princeton's computer science department. "Unlike many security problems, this isn't a minor flaw; it is a fundamental limitation in the way these systems were designed."

The attack is particularly effective against computers that are turned on but are locked, such as laptops that are in a "sleep" or hibernation mode. One effective countermeasure is to turn a computer off entirely, though in some cases even this does not provide protection.

Halderman's Princeton collaborators included graduate students Nadia Heninger, William Clarkson, Joseph Calandrino, Ariel Feldman and Professor Edward Felten, the director of the Center for Information Technology Policy. The team also included Seth Schoen of the Electronic Frontier Foundation, William Paul of Wind River Systems and independent computer security researcher Jacob Appelbaum.

Felten said the findings demonstrate the risks associated with recent high-profile laptop thefts, including a Veterans Administration computer containing information on 26 million veterans and a University of California, Berkeley laptop that contained information on more than 98,000 graduate students and others. While it is widely believed that disk encryption would protect sensitive information in instances like these, the new research demonstrates that the information could easily be read even when data is encrypted.

"Disk encryption is often recommended as a magic bullet against the loss of private data on laptops," Felten said. "Our results show that disk encryption provides less protection than previously thought. Even encrypted data can be vulnerable if an intruder gets access to the laptop."

The new attacks exploit the fact that information stored in a computer's temporary working memory, or RAM, does not disappear immediately when a computer is shut off or when the memory chip is taken from the machine, as is commonly thought. Under normal circumstances, the data gradually decays over a period of several seconds to a minute. The process can be slowed considerably using simple techniques to cool the chips to low temperatures.

Disk encryption technologies rely on the use of secret keys -- essentially large random numbers -- to encode and protect information. Computers need these keys to access files stored on their own hard disks or other storage systems. Once an authorized user has typed in a password, computers typically store the keys in the temporary RAM so that protected information can be accessed regularly. The keys are meant to disappear as soon as the RAM chips lose power.

The team wrote programs that gained access to essential encryption information automatically after cutting power to machines and rebooting them. The method worked when the attackers had physical access to the computer and when they accessed it remotely over a computer network. The attack even worked when the encryption key had already started to decay, because the researchers were able to reconstruct it from multiple derivative keys that were also stored in memory.

In one extremely powerful version of the attack, they were able to obtain the correct encryption data even when the memory chip was physically removed from one computer and placed in another machine. After obtaining the encryption key, they could then easily access all information on the original machine.

"This method is extremely resistant to countermeasures that defensive programs on the original computer might try to take," Halderman said.

The attacks demonstrate the vulnerability of machines when they are in an active state, including "sleep mode" or the "screen lock" mode that laptops enter when their covers are shut. Even though the machines require a password to unlock the screen, the encryption keys are already located in the RAM, which provides an opportunity for attackers with malicious intent.

None of the attacks required specialized equipment. "I think we're going to see attackers doing things that people have previously though impractical or impossible," Appelbaum said.

The researchers were able to extend the life of the information in RAM by cooling it using readily available "canned air" keyboard dusting products. When turned upside down, these canisters spray very cold liquid. Discharging the cold liquid onto a memory chip, the researchers were able to lower the temperature of the memory to -50 degrees Celsius. This slowed the decay rates enough that an attacker who cut power for 10 minutes would still be able to recover 99.9 percent of the information in the RAM correctly.

"Hints of problems associated with computers retaining their temporary memory have appeared in the scientific literature, but this is the first systematic examination of the security implications," said Schoen.

The researchers posted the paper describing their findings on the website of Princeton's Center for Information Technology Policy. They submitted the paper for publication and it is currently undergoing review.

In the meantime, the researchers have contacted several manufacturers to make them aware of the vulnerability: Microsoft, which includes BitLocker in some versions of Windows Vista; Apple, which created FileVault; and the makers of dm-crypt and TrueCrypt, which are open-source products for Windows and Linux platforms.

"There's not much they can do at this point," Halderman said. "In the short term, they can warn their customers about the vulnerability and tell them to shut their computers down completely when traveling."

In the longer term, Halderman said new technologies may need to be designed that do not require the storing of encryption keys in the RAM, given its inherent vulnerability. The researchers plan to continue investigating this and other defenses against this new security threat.

Princeton University, Engineering School



Related Computer Memory Current Events and Computer Memory News Articles Computer Memory Current Events and Computer Memory News RSS Computer Memory Current Events and Computer Memory News RSS
NC State Develops Material That Could Boost Data Storage, Save Energy
North Carolina State University engineers have created a new material that would allow a fingernail-size computer chip to store the equivalent of 20 high-definition DVDs or 250 million pages of text, far exceeding the storage capacities of today's computer memory systems.

Beating the back-up blues
That sinking feeling when your hard disk starts screeching and you haven't backed up your holiday photos is a step closer to becoming a thing of the past thanks to research into a new kind of computer memory.

Older adults control emotions more easily than young adults
With age comes the ability to better regulate emotions in order to not disrupt performance on a memory-intensive task, according to a study published in the March issue of the journal Psychology and Aging.

Memory in artificial atoms
Three of our nano-physicists have made a discovery that can change the way we store data on our computers. This means that in the future we can store data much faster, and more accurate. Their discovery has been published in the scientific journal Nature Physics.

Swarm approach to photography
A new approach to cleaning up digital photos and other images has been developed by researchers in the UK and Jordan. The research, published recently in Inderscience's International Journal of Innovative Computing and Applications uses a computer algorithm known as a PSO (Particle Swarm Optimization) to intelligently boost contrast and detail in an image without distorting the underlying features.

ASU researchers improve memory devices using nanotech
Arizona State University's Center for Applied Nanoionics (CANi) has a new take on old memory, one that promises to boost the performance, capacity and battery life of consumer electronics from digital cameras to laptops. Best of all, it is cheap, made from common materials and compatible with just about anything currently on the market.

The solution to a 7-decade mystery is crystal-clear to FSU chemist
A Florida State University researcher has helped solve a scientific mystery that stumped chemists for nearly seven decades. In so doing, his team's findings may lead to the development of more-powerful computer memories and lasers.

Landmark Modeling Study at Penn Reveals How Ferroelectric Computer Memory Works
A collaboration of University of Pennsylvania chemists and engineers has performed multi-scale modeling of ferroelectric domain walls and provided a new theory of behavior for domain-wall motion, the "sliding wall" that separates ferroelectric domains and makes high-density ferroelectric RAM (FeRAM) possible.

Carnegie Mellon scientists devise method to increase kidney transplants
Computer scientists at Carnegie Mellon University have developed a new computerized method for matching living kidney donors with kidney disease patients that can increase the number of kidney transplants - and save lives.

A Fresh Spin in Quantum Physics: The 'Spin Triplet' Supercurrent
For the first time, scientists have created a "spin triplet" supercurrent through a ferromagnet over a long distance.
More Computer Memory Current Events and Computer Memory News Articles
PNY OPTIMA 2GB (2x1GB) Dual Channel Kit DDR 400 MHz PC3200 Desktop DIMM Memory Modules MD2048KD1-400

PNY OPTIMA 2GB (2x1GB) Dual Channel Kit DDR 400 MHz PC3200 Desktop DIMM Memory Modules MD2048KD1-400
by PNY

2GB Kit (2x1GB) PC3200 400MHz DDR Desktop DIMMs , notebook computers and processors such as Intel¿s Pentium, Celeron, AMD¿s Athlon, Sempron and others. PNY upgrade modules are compatible with systems from Apple, Compaq, DELL, Gateway, HP, IBM and over 5000 other systems. Boost the performance of your PC to its maximum capability. PNY memory upgrades will prove to be an outstanding value both now and in the future.

Crucial 2GB 667 Mhz CT25664AC667 DDR2 200-Pin SODIMM Laptop Memory

Crucial 2GB 667 Mhz CT25664AC667 DDR2 200-Pin SODIMM Laptop Memory
by CRUCIAL TECHNOLOGY

Go faster and further with a notebook or netbook memory upgrade from Crucial. We've got quality SODIMM memory for mobile systems. And because a memory upgrade is one of the easiest, most affordable ways to improve system performance, it's the ideal solution for on-the-go users. If you count on your netbook or notebook, count on memory from Crucial. Crucial is a key brand in the Lexar Media family of products. So whether you’re focused on your family, friends, work or life outside of work—Crucial DRAM products help make computing more reliable, faster, and more effortless. With upgrades for nearly every PC and Mac system out there, plus flash products and Solid State Drives, you can be sure that if it’s important to you, it’s safe with us.

Kingston Technologies 1GB DDR SDRAM Desktop Memory (KVR400/1GR)

Kingston Technologies 1GB DDR SDRAM Desktop Memory (KVR400/1GR)
by Kingston H. Corporation

Kingston's ValueRAM KVR400/1GR is a 128M x 64-bit (1GB) DDR400 CL3 SDRAM (Synchronous DRAM) memory module. The components on the module include sixteen 64M x 8-bit (16M x 8-bit x 4 Bank) DDR333 SDRAM in TSOP packages. This 184-pin DIMM uses gold contact fingers and requires +2.6V. The product is shipped in retail packaging and includes installation instructions.

PNY OPTIMA 2GB (2x1GB) Dual Channel Kit DDR2 667 MHz PC2-5300 Desktop DIMM Memory Modules MD2048KD2-667

PNY OPTIMA 2GB (2x1GB) Dual Channel Kit DDR2 667 MHz PC2-5300 Desktop DIMM Memory Modules MD2048KD2-667
by PNY

DDR2 is the next generation of DDR memory. DDR2 memory features faster speeds, greater bandwidth, lower power consumption and enhanced thermal performance. Although DDR2 modules are the same physical dimension as DDR modules, the plug-in connector configuration is different and as such DDR2 modules are not compatible with PCs requiring DDR modules, and vice-versa.PNY manufactures DDR2 memory upgrades rated at PC2-3200, PC2-4200, PC2-5300 and higher. They are compatible with desktop and notebook computers and processors including Intel’s Pentium, Celeron, Centrino, AMD’s Athlon and Sempron Socket AM2 processors, and others. PNY upgrade modules are compatible with systems from Apple, Compaq, DELL, Gateway, HP, IBM and over 5000 other systems.Boost the performance of your PC. PNY memory...

Kingston ValueRAM 1 GB 400MHz DDR DIMM Desktop Memory (KVR400X64C3A/1G)

Kingston ValueRAM 1 GB 400MHz DDR DIMM Desktop Memory (KVR400X64C3A/1G)
by Kingston H. Corporation

Kingston is the industry leader in PC memory. Designed with the whitebox user and system integrator in mind, Kingston ValueRAM products are engineered to meet industry standard specifications and rigorously tested to ensure quality. Kingston ValueRAM is ideal for those who purchase memory by spec and are looking for competitvely priced generic memory. Product is backed by a lifetime warranty and free technical support. Included in the package is one 1GB module of 400MHz DDR memory. Specs are standard Non-ECC, 184-pin unbuffered DIMM.

Crucial 2GB Set(2x1GB) 200-Pin PC2 5300 667Mhz SODIMM DDR2 RAM

Crucial 2GB Set(2x1GB) 200-Pin PC2 5300 667Mhz SODIMM DDR2 RAM
by CRUCIAL TECHNOLOGY

Go faster and further with a notebook or netbook memory upgrade from Crucial. We've got quality SODIMM memory for mobile systems. And because a memory upgrade is one of the easiest, most affordable ways to improve system performance, it's the ideal solution for on-the-go users. If you count on your netbook or notebook, count on memory from Crucial. Crucial is a key brand in the Lexar Media family of products. So whether you’re focused on your family, friends, work or life outside of work—Crucial DRAM products help make computing more reliable, faster, and more effortless. With upgrades for nearly every PC and Mac system out there, plus flash products and Solid State Drives, you can be sure that if it’s important to you, it’s safe with us.

Corsair XMS2 4 GB (2 X 2 GB) PC2-6400 800 MHz 240-PIN DDR2 Dual-Channel Memory Kit - TWIN2X4096-6400C5

Corsair XMS2 4 GB (2 X 2 GB) PC2-6400 800 MHz 240-PIN DDR2 Dual-Channel Memory Kit - TWIN2X4096-6400C5
by CORSAIR VALUE SELECT

The Twin2X4096-6400C5 G is a 4096MByte matched pair of DDR2 SDRAM DIMMs. This part delivers outstanding performance in the latest generation of dual-channel DDR2-based motherboards. It has been tested extensively in multiple DDR2 motherboards to ensure compatibility and performance at its rated speed. This memory has been verified to operate at 800MHz at the low latencies of 5-5-5-18.

Crucial / 1GB / 240-pin DIMM / DDR2 PC2-5300 memory module

Crucial / 1GB / 240-pin DIMM / DDR2 PC2-5300 memory module
by CRUCIAL TECHNOLOGY

Every day, you rely on your computer to make your life easier. A Crucial DRAM upgrade can help your system run faster, and it's one of the easiest, most affordable ways to improve system performance. Reap the benefits doing everything from everyday system tasks to mission-critical applications. For over 12 years, Crucial has been recognized as a leader in DRAM upgrades. Our products help people achieve greater system performance through improved productivity, reliability, and speed. As part of one of the world’s largest DRAM manufacturers—Micron Technology—our long tenure of engineering and manufacturing expertise allow us to build high-quality, system-specific memory solutions for customers. We back our products by guaranteeing system compatibility, limited lifetime warranties,...

PNY OPTIMA 1GB  DDR 333 MHz PC2700  Desktop DIMM Memory Module MD1024SD1-333

PNY OPTIMA 1GB DDR 333 MHz PC2700 Desktop DIMM Memory Module MD1024SD1-333
by PNY

DDR (Double Data Rate SDRAM) is a DRAM technology that supports data transfers on both the rising and the falling edges of each clock cycle. This effectively doubles the memory chip’s data throughput and is more efficient than legacy SDR technology. PNY manufactures DDR memory upgrades rated at PC2100, PC2700, and PC3200. They are compatible with desktop and notebook computers and processors such as Intel’s Pentium, Celeron, AMD’s Athlon, Sempron and others. PNY upgrade modules are compatible with systems from Apple, Compaq, DELL, Gateway, HP, IBM and over 5000 other systems. Boost the performance of your PC to its maximum capability. PNY memory upgrades will prove to be an outstanding value both now and in the future.

Crucial Technology CT12864Z335 1GB 184-Pin PC2700 333Mhz DIMM DDR RAM Memory

Crucial Technology CT12864Z335 1GB 184-Pin PC2700 333Mhz DIMM DDR RAM Memory
by CRUCIAL TECHNOLOGY

Every day, you rely on your computer to make your life easier. A Crucial DRAM upgrade can help your system run faster, and it's one of the easiest, most affordable ways to improve system performance. Reap the benefits doing everything from everyday system tasks to mission-critical applications. For over 12 years, Crucial has been recognized as a leader in DRAM upgrades. Our products help people achieve greater system performance through improved productivity, reliability, and speed. As part of one of the world’s largest DRAM manufacturers—Micron Technology—our long tenure of engineering and manufacturing expertise allow us to build high-quality, system-specific memory solutions for customers. We back our products by guaranteeing system compatibility, limited lifetime warranties,...

© 2009 BrightSurf.com