B
今週中
研究チームが、DDR5 RDIMMメモリを採用した機密コンピューティングサーバを標的とするハードウェア攻撃手法「DDRop」
📌 一言でいうと
研究チームが、DDR5 RDIMMメモリを採用した機密コンピューティングサーバを標的とするハードウェア攻撃手法「DDRop」を公開しました。この攻撃は、メモリ書き込みメカニズムの「新鮮度(freshness)」検証の欠如を突き、物理的なインターポザーを用いてIntel TDXやAMD SEV-SNPなどのメモリ保護を突破します。攻撃には物理的なアクセスが必要ですが、成功するとメモリ内容の読み取りや偽造レポートの作成が可能です。
🔍該当判定
- Intel TDX、Intel SGX、AMD SEV-SNPなどの「機密コンピューティング(Confidential Computing)」機能を有効にしたサーバーを運用している
- サーバーにDDR5 RDIMM(登録済みメモリ)を搭載している
- 不特定多数が物理的に接触できる場所(共用スペースや外部委託先など)にサーバーを設置している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
サーバへの物理的なアクセス制限を厳格化し、ハードウェアサプライチェーンの監視を強化すること。また、将来的なハードウェア設計においてメモリの整合性と新鮮度検証機能の導入を検討すること。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】DDR5メモリを標的としたハードウェア攻撃「DDRop」について
お疲れさまです。機密コンピューティング環境における新たな物理攻撃手法に関する情報共有です。
■ 概要
DDR5 RDIMMメモリの書き込みメカニズムにおける「新鮮度(freshness)」検証の不備を突いた攻撃手法「DDRop」が報告されました。物理的なインターポザーを介してメモリバスに介入することで、Intel TDXやAMD SEV-SNPなどのメモリ暗号化保護をバイパスし、データの読み取りや改ざんが可能です。
■ 影響範囲
- DDR5 RDIMMメモリを採用し、Intel TDX、Scalable SGX、AMD SEV-SNP等を利用しているサーバ
■ 対応手順
1. サーバラックおよび物理ハードウェアへのアクセス権限を再確認し、物理的な接触を制限する。
2. ハードウェアのサプライチェーン管理を強化し、不正なデバイス(インターポザー等)の混入を防止する。
3. ベンダー(Intel/AMD)からのハードウェアレベルの修正や対策アップデートを注視する。
■ 参考情報
- DDRop 公式サイト: https://ddropattack.eu/
対応優先度: 中(物理アクセスが必要なため)
対応期限: 継続的な監視
お疲れさまです。機密コンピューティング環境における新たな物理攻撃手法に関する情報共有です。
■ 概要
DDR5 RDIMMメモリの書き込みメカニズムにおける「新鮮度(freshness)」検証の不備を突いた攻撃手法「DDRop」が報告されました。物理的なインターポザーを介してメモリバスに介入することで、Intel TDXやAMD SEV-SNPなどのメモリ暗号化保護をバイパスし、データの読み取りや改ざんが可能です。
■ 影響範囲
- DDR5 RDIMMメモリを採用し、Intel TDX、Scalable SGX、AMD SEV-SNP等を利用しているサーバ
■ 対応手順
1. サーバラックおよび物理ハードウェアへのアクセス権限を再確認し、物理的な接触を制限する。
2. ハードウェアのサプライチェーン管理を強化し、不正なデバイス(インターポザー等)の混入を防止する。
3. ベンダー(Intel/AMD)からのハードウェアレベルの修正や対策アップデートを注視する。
■ 参考情報
- DDRop 公式サイト: https://ddropattack.eu/
対応優先度: 中(物理アクセスが必要なため)
対応期限: 継続的な監視
Subject: [Info] Hardware Attack 'DDRop' Targeting DDR5 Memory
Dear team,
We are sharing information regarding a new physical attack method targeting confidential computing environments.
■ Overview
Researchers have disclosed 'DDRop', an attack that exploits the lack of 'freshness' verification in DDR5 RDIMM memory encryption. By using a physical interposer to intercept the memory bus, attackers can bypass protections such as Intel TDX and AMD SEV-SNP to read or manipulate encrypted memory data.
■ Scope
- Servers using DDR5 RDIMM memory and implementing Intel TDX, Scalable SGX, or AMD SEV-SNP.
■ Recommended Actions
1. Strictly limit and monitor physical access to server hardware and racks.
2. Enhance hardware supply chain security to prevent the installation of unauthorized interposers.
3. Monitor updates from Intel and AMD regarding hardware-level mitigations.
■ Reference
- DDRop Official Site: https://ddropattack.eu/
Priority: Medium (Requires physical access)
Deadline: Ongoing monitoring
Dear team,
We are sharing information regarding a new physical attack method targeting confidential computing environments.
■ Overview
Researchers have disclosed 'DDRop', an attack that exploits the lack of 'freshness' verification in DDR5 RDIMM memory encryption. By using a physical interposer to intercept the memory bus, attackers can bypass protections such as Intel TDX and AMD SEV-SNP to read or manipulate encrypted memory data.
■ Scope
- Servers using DDR5 RDIMM memory and implementing Intel TDX, Scalable SGX, or AMD SEV-SNP.
■ Recommended Actions
1. Strictly limit and monitor physical access to server hardware and racks.
2. Enhance hardware supply chain security to prevent the installation of unauthorized interposers.
3. Monitor updates from Intel and AMD regarding hardware-level mitigations.
■ Reference
- DDRop Official Site: https://ddropattack.eu/
Priority: Medium (Requires physical access)
Deadline: Ongoing monitoring