The weakness occurs because of ‘BadRAM’ – rogue memory modules that deliberately provide false information to the computer’s processor during startup.
Processors are present in every computer and are necessary to perform every calculation. The computer’s memory (DRAM) is essential for storing code and data. When a computer boots up, the processor will communicate with DRAM modules to learn size, speed and configuration.
This information is stored on the so-called SPD chip. But by tampering with this chip, the researchers found that attackers were able to bypass the AMD’s security mechanisms put in place to protect sensitive data – particularly data stored in shared cloud environments with pervasive data breaches and insider threats.
In this case, the researchers targeted a security technology called Secure Encrypted Virtualisation (SEV), designed by global computing company AMD. This cutting-edge technology protects privacy and trust in cloud computing by encrypting a virtual machine’s memory and isolating it from advanced attackers.
We found that using cheap, off-the-shelf equipment, we were able to trick the computer’s processor into allowing access to protected memory.
Professor David Oswald, School of Computer Science
The BadRAM logo.
The research was carried out by a consortium of experts from KU Leuven, Belgium; the University of Luebeck, Germany; and the University of Birmingham, UK.
It has led to AMD issuing firmware updates to securely validate memory configurations as processors boot up.
Professor David Oswald, at the University of Birmingham, said: “We found that using cheap, off-the-shelf equipment, we were able to trick the computer’s processor into allowing access to protected memory.”
The researchers have published a website to explain the weakness and the potential threat posed. They explain that BadRAM makes the computer’s memory module intentionally lie about its size, tricking the CPU into addressing ‘ghost’ memory regions that don’t exist.
This leads to two CPU addresses mapping to the same DRAM location. And through these aliases, attackers can bypass CPU memory protections, exposing sensitive data or causing disruptions.
Professor Oswald added: “We worked with AMD to ensure they were able to adopt appropriate countermeasures so that BadRAM is detected at the point the computer boots up. While it’s good practice to keep your system up-to-date, most cloud providers will have updated their firmware to include AMD’s countermeasures – so there is no need to worry that your data is not secure!”
Flaw in computer memory leads to global security fixes
The weakness occurs because of ‘BadRAM’ – rogue memory modules that deliberately provide false information to the computer’s processor during startup. Processors are present in every computer and are...
2024-12-14
No Comment
RELATED BY
-
Landscape improvements for Perry Park complet ...
As part of the Legacy Project for the Alexander...Posted 4 weeks ago -
Madrasah Ameer Hamzah opens in Birmingham
On Saturday 21st June was the opening of a...Posted 4 weeks ago -
UK Youth Pioneer Zaf Bags the British Muslim ...
Oceanic Awards has proudly announced the winners for the...Posted 2 months ago -
30 girls win opportunity to become Ambassador ...
On Tuesday 27 May, the British, Canadian and Jordanian...Posted 2 months ago
-
Council visits around 2,000 tenants in an int ...
Visiting housing tenants and asking them how they are...Posted 2 weeks ago -
Woman prosecuted for illegally subletting Bir ...
A former Birmingham City Council tenant has been fined...Posted 2 weeks ago -
Birmingham Targets Dangerous E-Bikes in Major ...
Birmingham City Council and partners have carried out a...Posted 3 weeks ago -
Birmingham Urges Residents to Support Nationa ...
Birmingham City Council is backing a national campaign to...Posted 3 weeks ago
-
Birmingham City Council tenants make big savi ...
Birmingham City Council tenants make big savings thanks to...Posted 5 days ago -
Birmingham becomes UK’s first Nature Ci ...
Birmingham has been declared the UK’s first official Nature...Posted 6 days ago -
Cook with love, with truth — Cook for life ...
Chef Danilo Mariano Paula (Instagram A/c: chefdanilobrasil ) is an executive...Posted 1 week ago -
Retrofit project that has made council homes ...
Birmingham City Council tenants in more than 2,000 households...Posted 2 weeks ago
LATEST REVIEWS
-
2025-05-26
-
2025-04-14
-
2025-04-10
-
2025-03-16