{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,25]],"date-time":"2025-03-25T14:27:19Z","timestamp":1742912839121,"version":"3.40.3"},"publisher-location":"Cham","reference-count":37,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783031020667"},{"type":"electronic","value":"9783031020674"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-031-02067-4_3","type":"book-chapter","created":{"date-parts":[[2022,4,8]],"date-time":"2022-04-08T05:10:25Z","timestamp":1649394625000},"page":"38-54","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["A TSX-Based KASLR Break: Bypassing UMIP and\u00a0Descriptor-Table Exiting"],"prefix":"10.1007","author":[{"given":"Mohammad Sina","family":"Karvandi","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Saleh","family":"Khalaj Monfared","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mohammad Sina","family":"Kiarostami","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dara","family":"Rahmati","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Saeid","family":"Gorgin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,4,9]]},"reference":[{"key":"3_CR1","unstructured":"Devices, A.M.: AMD64 architecture programmer\u2019s manual volume 2: system programming (2006)"},{"issue":"1","key":"3_CR2","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s13389-016-0141-6","volume":"8","author":"Q Ge","year":"2018","unstructured":"Ge, Q., Yarom, Y., Cock, D., Heiser, G.: A survey of microarchitectural timing attacks and countermeasures on contemporary hardware. J. Cryptogr. Eng. 8(1), 1\u201327 (2018)","journal-title":"J. Cryptogr. Eng."},{"key":"3_CR3","unstructured":"Gras, B., Razavi, K., Bos, H., Giuffrida, C.: Translation leak-aside buffer: defeating cache side-channel protections with TLB attacks. In: 27th USENIX Security Symposium (USENIX Security 18), pp. 955\u2013972 (2018)"},{"key":"3_CR4","unstructured":"Gruss, D., Hansen, D., Gregg, B.: Kernel isolation: from an academic idea to an efficient patch for every computer. login: USENIX Mag. 43(4), 10\u201314 (2018)"},{"key":"3_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"161","DOI":"10.1007\/978-3-319-62105-0_11","volume-title":"Engineering Secure Software and Systems","author":"D Gruss","year":"2017","unstructured":"Gruss, D., Lipp, M., Schwarz, M., Fellner, R., Maurice, C., Mangard, S.: KASLR is dead: long live KASLR. In: Bodden, E., Payer, M., Athanasopoulos, E. (eds.) ESSoS 2017. LNCS, vol. 10379, pp. 161\u2013176. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-62105-0_11"},{"key":"3_CR6","unstructured":"Guide, P.: Intel\u00ae 64 and IA-32 architectures software developer\u2019s manual. Volume 3C: Chapter 24, Virtual Machine Control Structures (Table 24\u20136. Definitions of Primary Processor-Based VM-Execution Controls) 3C (2019)"},{"key":"3_CR7","unstructured":"Guide, P.: Intel\u00ae 64 and IA-32 architectures software developer\u2019s manual. Volume 4: Chapter 2, Model-Specific Registers (MSRS) (Table 2\u20132. IA-32 Architectural MSRs) 4 (2019)"},{"key":"3_CR8","unstructured":"Guide, P.: Intel\u00ae 64 and IA-32 architectures software developer\u2019s manual. Volume 3A: Chapter 1, System Architecture Overview, Time Stamp Disable, 3A (2019)"},{"issue":"10","key":"3_CR9","doi-asserted-by":"publisher","first-page":"2211","DOI":"10.1109\/TPDS.2019.2911278","volume":"30","author":"O Hajihassani","year":"2019","unstructured":"Hajihassani, O., Monfared, S.K., Khasteh, S.H., Gorgin, S.: Fast AES implementation: a high-throughput bitsliced approach. IEEE Trans. Parallel Distrib. Syst. 30(10), 2211\u20132222 (2019)","journal-title":"IEEE Trans. Parallel Distrib. Syst."},{"key":"3_CR10","unstructured":"Intel: Intel virtualization technology flexmigration application note (2012). https:\/\/www.intel.com\/content\/dam\/www\/public\/us\/en\/documents\/application-notes\/virtualization-technology-flexmigration-application-note.pdf"},{"key":"3_CR11","unstructured":"Ionescu, A.: Blog post (2018). http:\/\/www.alex-ionescu.com\/?p=340"},{"key":"3_CR12","unstructured":"Jurczyk, M., Coldwind, G.: GDT and LDT in windows kernel vulnerability exploitation (2010)"},{"key":"3_CR13","unstructured":"Karvandi, S.: Call gates\u2019 ring transitioning in IA-32 mode (2019). https:\/\/rayanfam.com\/topics\/call-gates-ring-transitioning-in-ia-32-mode\/"},{"key":"3_CR14","unstructured":"Karvandi, S.: Hypervisor from scratch - part 6: virtualizing an already running system (2019). https:\/\/rayanfam.com\/topics\/hypervisor-from-scratch-part-6\/"},{"key":"3_CR15","doi-asserted-by":"crossref","unstructured":"Kiarostami, M.S., Reza Daneshvaramoli, M., Monfared, S.K., Rahmati, D., Gorgin, S.: Multi-agent non-overlapping pathfinding with Monte-Carlo Tree search. In: 2019 IEEE Conference on Games (CoG), pp. 1\u20134 (2019)","DOI":"10.1109\/CIG.2019.8848043"},{"issue":"17","key":"3_CR16","doi-asserted-by":"publisher","first-page":"2174","DOI":"10.3390\/electronics10172174","volume":"10","author":"T Kim","year":"2021","unstructured":"Kim, T., Kim, T., Shin, Y.: Breaking KASLR using memory deduplication in virtualized environments. Electronics 10(17), 2174 (2021)","journal-title":"Electronics"},{"key":"3_CR17","doi-asserted-by":"crossref","unstructured":"Kim, Y., et al.: Flipping bits in memory without accessing them: an experimental study of dram disturbance errors. In: ACM SIGARCH Computer Architecture News, vol. 42, pp. 361\u2013372. IEEE Press (2014)","DOI":"10.1145\/2678373.2665726"},{"key":"3_CR18","doi-asserted-by":"crossref","unstructured":"Kocher, P., et al.: Spectre attacks: exploiting speculative execution. arXiv preprint arXiv:1801.01203 (2018)","DOI":"10.1109\/SP.2019.00002"},{"key":"3_CR19","doi-asserted-by":"crossref","unstructured":"Koschel, J., Giuffrida, C., Bos, H., Razavi, K.: TagBleed: breaking Kaslr on the isolated kernel address space using tagged TLBs. In: 2020 IEEE European Symposium on Security and Privacy (EuroS&P), pp. 309\u2013321. IEEE (2020)","DOI":"10.1109\/EuroSP48549.2020.00027"},{"key":"3_CR20","doi-asserted-by":"crossref","unstructured":"Kurth, M., Gras, B., Andriesse, D., Giuffrida, C., Bos, H., Razavi, K.: NetCAT: practical cache attacks from the network. In: S&P, May 2020. https:\/\/www.vusec.net\/download\/?t=papers\/netcat_sp20.pdf. Intel Bounty Reward","DOI":"10.1109\/SP40000.2020.00082"},{"key":"3_CR21","unstructured":"Lewis, P.: Using a call gate to prevent secure sandbox leakage, uS Patent 8,528,083, 3 September 2013"},{"key":"3_CR22","unstructured":"Lipp, M., et al.: Meltdown: reading kernel memory from user space. In: 27th USENIX Security Symposium (USENIX Security 18), pp. 973\u2013990 (2018)"},{"key":"3_CR23","unstructured":"Microsoft Security Response Center: Kva shadow: mitigating meltdown on windows (2018). https:\/\/msrc-blog.microsoft.com\/2018\/03\/23\/kva-shadow-mitigating-meltdown-on-windows\/"},{"key":"3_CR24","unstructured":"Minkin, M., et al.: Fallout: reading Kernel writes from user space. arXiv preprint arXiv:1905.12701 (2019)"},{"key":"3_CR25","unstructured":"MITRE: Cwe-123: Write-what-where condition (2019). https:\/\/cwe.mitre.org\/data\/definitions\/123.html"},{"key":"3_CR26","doi-asserted-by":"crossref","unstructured":"Monfared, S.K., Hajihassani, O., Kiarostami, M.S., Zanjani, S.M., Rahmati, D., Gorgin, S.: BSRNG: a high throughput parallel bitsliced approach for random number generators. In: 49th International Conference on Parallel Processing-ICPP: Workshops, pp. 1\u201310 (2020)","DOI":"10.1145\/3409390.3409402"},{"key":"3_CR27","doi-asserted-by":"crossref","unstructured":"Oliverio, M., Razavi, K., Bos, H., Giuffrida, C.: Secure page fusion with VUsion. In: Proceedings of the 26th Symposium on Operating Systems Principles, pp. 531-545 (2017). https:\/\/www.vusec.net\/projects\/vusion","DOI":"10.1145\/3132747.3132781"},{"key":"3_CR28","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/11605805_1","volume-title":"Topics in Cryptology \u2013 CT-RSA 2006","author":"DA Osvik","year":"2006","unstructured":"Osvik, D.A., Shamir, A., Tromer, E.: Cache attacks and countermeasures: the case of AES. In: Pointcheval, D. (ed.) CT-RSA 2006. LNCS, vol. 3860, pp. 1\u201320. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11605805_1"},{"key":"3_CR29","doi-asserted-by":"crossref","unstructured":"Schwarz, M., et al.: ZombieLoad: cross-privilege-boundary data sampling. arXiv preprint arXiv:1905.05726 (2019)","DOI":"10.1145\/3319535.3354252"},{"key":"3_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"247","DOI":"10.1007\/978-3-319-70972-7_13","volume-title":"Financial Cryptography and Data Security","author":"M Schwarz","year":"2017","unstructured":"Schwarz, M., Maurice, C., Gruss, D., Mangard, S.: Fantastic timers and where to find them: high-resolution microarchitectural attacks in JavaScript. In: Kiayias, A. (ed.) FC 2017. LNCS, vol. 10322, pp. 247\u2013267. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-70972-7_13"},{"key":"3_CR31","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-319-60876-1_1","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"M Schwarz","year":"2017","unstructured":"Schwarz, M., Weiser, S., Gruss, D., Maurice, C., Mangard, S.: Malware guard extension: using SGX to conceal cache attacks. In: Polychronakis, M., Meier, M. (eds.) DIMVA 2017. LNCS, vol. 10327, pp. 3\u201324. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-60876-1_1"},{"key":"3_CR32","unstructured":"Seaborn, M., Dullien, T.: Exploiting the DRAM rowhammer bug to gain kernel privileges. Black Hat 15 (2015)"},{"key":"3_CR33","unstructured":"Stecklina, J., Prescher, T.: LazyFP: leaking FPU register state using microarchitectural side-channels. arXiv preprint arXiv:1806.07480 (2018)"},{"key":"3_CR34","unstructured":"Van Schaik, S., Giuffrida, C., Bos, H., Razavi, K.: Malicious management unit: Why stopping cache attacks in software is harder than you think. In: 27th USENIX Security Symposium (USENIX Security 18), pp. 937\u2013954 (2018)"},{"key":"3_CR35","unstructured":"Weisse, O., et al.: Foreshadow-NG: breaking the virtual memory abstraction with transient out-of-order execution (2018)"},{"key":"3_CR36","unstructured":"Wiki, O.D.: Sysenter (2017). https:\/\/wiki.osdev.org\/SYSENTER"},{"key":"3_CR37","unstructured":"Yarom, Y., Falkner, K.: Flush + reload: a high resolution, low noise, L3 cache side-channel attack. In: 23rd USENIX Security Symposium (USENIX Security 14), pp. 719\u2013732 (2014)"}],"container-title":["Lecture Notes in Computer Science","Risks and Security of Internet and Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-02067-4_3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,4,8]],"date-time":"2022-04-08T05:13:58Z","timestamp":1649394838000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-02067-4_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783031020667","9783031020674"],"references-count":37,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-02067-4_3","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"9 April 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CRiSIS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Risks and Security of Internet and Systems","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Ames, IA","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"12 November 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"13 November 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"crisis2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.crisis-2021.com\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Easychaire","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"23","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"9","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"39% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.5","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}