{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,5,30]],"date-time":"2025-05-30T05:40:10Z","timestamp":1748583610503,"version":"3.41.0"},"publisher-location":"Cham","reference-count":46,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319233178"},{"type":"electronic","value":"9783319233185"}],"license":[{"start":{"date-parts":[[2015,1,1]],"date-time":"2015-01-01T00:00:00Z","timestamp":1420070400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2015]]},"DOI":"10.1007\/978-3-319-23318-5_5","type":"book-chapter","created":{"date-parts":[[2015,8,26]],"date-time":"2015-08-26T17:50:33Z","timestamp":1440611433000},"page":"83-101","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Dynamically Provisioning Isolation in Hierarchical Architectures"],"prefix":"10.1007","author":[{"given":"Kevin","family":"Falzon","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Eric","family":"Bodden","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2015,8,27]]},"reference":[{"key":"5_CR1","unstructured":"CRIU project page, April 2015. http:\/\/criu.org\/Main_Page"},{"key":"5_CR2","unstructured":"KVM project page, April 2015. http:\/\/www.linux-kvm.org\/"},{"key":"5_CR3","unstructured":"Libvirt project page, April 2015. http:\/\/www.libvirt.org\/"},{"key":"5_CR4","doi-asserted-by":"crossref","unstructured":"Acii\u00e7mez, O., Ko\u00e7, c.K., Seifert, J.P.: On the power of simple branch prediction analysis. In: ASIACCS 2007, pp. 312\u2013320. ACM, New York (2007)","DOI":"10.1145\/1229285.1266999"},{"key":"5_CR5","doi-asserted-by":"crossref","unstructured":"Agat, J.: Transforming out timing leaks. In: Proceedings of the 27th ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages, POPL 2000, pp. 40\u201353. ACM, New York (2000)","DOI":"10.1145\/325694.325702"},{"key":"5_CR6","doi-asserted-by":"crossref","unstructured":"Askarov, A., Zhang, D., Myers, A.C.: Predictive black-box mitigation of timing channels. In: CCS 2010, pp. 297\u2013307. ACM, New York (2010)","DOI":"10.1145\/1866307.1866341"},{"key":"5_CR7","doi-asserted-by":"crossref","unstructured":"Azar, Y., Kamara, S., Menache, I., Raykova, M., Shepard, B.: Co-location-resistant clouds. In: CCSW 2014, pp. 9\u201320. ACM, New York (2014)","DOI":"10.1145\/2664168.2664179"},{"key":"5_CR8","doi-asserted-by":"crossref","unstructured":"Bienia, C., Kumar, S., Singh, J.P., Li, K.: The parsec benchmark suite: characterization and architectural implications. In: Proceedings of the 17th International Conference on Parallel Architectures and Compilation Techniques, October 2008","DOI":"10.1145\/1454115.1454128"},{"key":"5_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"355","DOI":"10.1007\/978-3-642-23822-2_20","volume-title":"Computer Security \u2013 ESORICS 2011","author":"BB Brumley","year":"2011","unstructured":"Brumley, B.B., Tuveri, N.: Remote timing attacks are still practical. In: Atluri, V., Diaz, C. (eds.) ESORICS 2011. LNCS, vol. 6879, pp. 355\u2013371. Springer, Heidelberg (2011)"},{"key":"5_CR10","doi-asserted-by":"crossref","unstructured":"Cabuk, S., Brodley, C.E., Shields, C.: IP covert timing channels: design and detection. In: CCS 2004. ACM, New York (2004)","DOI":"10.1145\/1030083.1030108"},{"key":"5_CR11","doi-asserted-by":"crossref","unstructured":"Cardelli, L., Gordon, A.D.: Mobile ambients. In: POPL 1998. ACM Press (1998)","DOI":"10.1007\/BFb0053547"},{"key":"5_CR12","doi-asserted-by":"crossref","unstructured":"Caron, E., Desprez, F., Rouzaud-Cornabas, J.: Smart resource allocation to improve cloud security. In: Nepal, S., Pathan, M. (eds.) Security, Privacy and Trust in Cloud Systems. Springer, Heidelberg (2014)","DOI":"10.1007\/978-3-642-38586-5_4"},{"key":"5_CR13","doi-asserted-by":"crossref","unstructured":"Coppens, B., Verbauwhede, I., Bosschere, K.D., Sutter, B.D.: Practical mitigations for timing-based side-channel attacks on modern x86 processors. In: S&P 2009, pp. 45\u201360. IEEE Computer Society, Washington, DC (2009)","DOI":"10.1109\/SP.2009.19"},{"key":"5_CR14","doi-asserted-by":"crossref","unstructured":"Dolan-Gavitt, B., Leek, T., Hodosh, J., Lee, W.: Tappan zee (north) bridge: mining memory accesses for introspection. In: CCS 2013. ACM, New York (2013)","DOI":"10.1145\/2508859.2516697"},{"key":"5_CR15","unstructured":"Du, J., Sehrawat, N., Zwaenepoel, W.: Performance profiling in a virtualized environment. In: 2nd USENIX Workshop on Hot Topics in Cloud Computing (2010)"},{"key":"5_CR16","unstructured":"Ericsson AB: Erlang reference manual user\u2019s guide, 6.2 edn., September 2014. http:\/\/www.erlang.org\/doc\/reference_manual\/users_guide.html"},{"issue":"1","key":"5_CR17","doi-asserted-by":"publisher","first-page":"64","DOI":"10.1109\/TIFS.2011.2163398","volume":"7","author":"S Gorantla","year":"2012","unstructured":"Gorantla, S., Kadloor, S., Kiyavash, N., Coleman, T., Moskowitz, I., Kang, M.: Characterizing the efficacy of the NRL network pump in mitigating covert timing channels. IEEE Trans. Inf. Forensics Secur. 7(1), 64\u201375 (2012)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"5_CR18","unstructured":"Gueron, S.: Intel advanced encryption standard (AES) new instructions set, May 2010. http:\/\/www.intel.com\/content\/dam\/doc\/white-paper\/advanced-encryption-standard-new-instructions-set-paper.pdf"},{"key":"5_CR19","doi-asserted-by":"crossref","unstructured":"Hu, W.M.: Reducing timing channels with fuzzy time. In: S&P 1991, pp. 8\u201320. IEEE Computer Society, May 1991","DOI":"10.1109\/RISP.1991.130768"},{"key":"5_CR20","doi-asserted-by":"crossref","unstructured":"Hu, W.M.: Lattice scheduling and covert channels. In: S&P 1992, p. 52. IEEE Computer Society, Washington, DC (1992)","DOI":"10.1109\/RISP.1992.213271"},{"key":"5_CR21","unstructured":"Intel: system programming guide, Intel$$\\textregistered $$ 64 & IA-32 architectures software developers manual, vol. 3B. Intel, May 2011"},{"key":"5_CR22","unstructured":"Intel: instruction set reference, intel$$\\textregistered $$ 64 & IA-32 architectures software developers manual, vol. 2. Intel, January 2015"},{"key":"5_CR23","doi-asserted-by":"crossref","unstructured":"Keller, E., Szefer, J., Rexford, J., Lee, R.B.: Nohype: virtualized cloud infrastructure without the virtualization. In: 37th Annual International Symposium on Computer Architecture, ISCA 2010, pp. 350\u2013361. ACM, New York (2010)","DOI":"10.1145\/1815961.1816010"},{"key":"5_CR24","unstructured":"Kim, T., Peinado, M., Mainar-Ruiz, G.: Stealthmem: system-level protection against cache-based side channel attacks in the cloud. In: Security 2012. USENIX Association, Berkeley (2012)"},{"issue":"10","key":"5_CR25","doi-asserted-by":"publisher","first-page":"613","DOI":"10.1145\/362375.362389","volume":"16","author":"BW Lampson","year":"1973","unstructured":"Lampson, B.W.: A note on the confinement problem. CACM 16(10), 613\u2013615 (1973)","journal-title":"CACM"},{"key":"5_CR26","doi-asserted-by":"crossref","unstructured":"Li, P., Gao, D., Reiter, M.: Mitigating access-driven timing channels in clouds using stopwatch. In: 43rd Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN), pp. 1\u201312, June 2013","DOI":"10.1109\/DSN.2013.6575299"},{"key":"5_CR27","unstructured":"Linux: cpuset(7) - Linux manual page, August 2014. http:\/\/www.man7.org\/linux\/man-pages\/man7\/cpuset.7.html"},{"key":"5_CR28","doi-asserted-by":"crossref","unstructured":"Mdhaffar, A., Ben Halima, R., Jmaiel, M., Freisleben, B.: A dynamic complex event processing architecture for cloud monitoring and analysis. In: 2013 IEEE 5th International Conference on Cloud Computing Technology and Science, CloudCom, vol. 2, pp. 270\u2013275, December 2013","DOI":"10.1109\/CloudCom.2013.146"},{"key":"5_CR29","unstructured":"Mucci, P.J., Browne, S., Deane, C., Ho, G.: Papi: a portable interface to hardware performance counters. In: Proceedings of the DoD HPCMP Users Group Conference (1999)"},{"key":"5_CR30","doi-asserted-by":"crossref","unstructured":"Okamura, K., Oyama, Y.: Load-based covert channels between Xen virtual machines. In: 2010 ACM Symposium on Applied Computing, SAC 2010, pp. 173\u2013180. ACM, New York (2010)","DOI":"10.1145\/1774088.1774125"},{"key":"5_CR31","unstructured":"OpenStack foundation: OpenStack documentation, February 2015. http:\/\/www.docs.openstack.org\/"},{"key":"5_CR32","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/11605805_1","volume-title":"Topics in Cryptology \u2013 CT-RSA 2006","author":"DA Osvik","year":"2006","unstructured":"Osvik, D.A., Shamir, A., Tromer, E.: Cache attacks and countermeasures: the case of AES. In: Pointcheval, D. (ed.) CT-RSA 2006. LNCS, vol. 3860, pp. 1\u201320. Springer, Heidelberg (2006)"},{"key":"5_CR33","doi-asserted-by":"crossref","unstructured":"Ristenpart, T., Tromer, E., Shacham, H., Savage, S.: Hey, you, get off of my cloud: exploring information leakage in third-party compute clouds. In: CCS 2009, pp. 199\u2013212. ACM, New York (2009)","DOI":"10.1145\/1653662.1653687"},{"key":"5_CR34","unstructured":"Sailer, R., Jaeger, T., Valdez, E., C\u00e1ceres, R., Perez, R., Berger, S., Linwood, J., Doorn, G.L.: Building a MAC-based security architecture for the Xen opensource hypervisor. In: 21st Annual Competition Section Applications Conference, ACSAC 2005 (2005)"},{"key":"5_CR35","unstructured":"Saltaformaggio, B., Xu, D., Zhang, X.: Busmonitor: a hypervisor-based solution for memory bus covert channels. In: EuroSec 2013. ACM (2013)"},{"key":"5_CR36","first-page":"161","volume-title":"Operating System Concepts, Chap. 5","author":"A Silberschatz","year":"2005","unstructured":"Silberschatz, A., Galvin, P.B., Gagne, G.: Operating System Concepts, Chap. 5, 7th edn, p. 161. Wiley Publishing, New York (2005)","edition":"7"},{"key":"5_CR37","unstructured":"Tycho: live migration of linux containers, October 2014. http:\/\/tycho.ws\/blog\/2014\/09\/container-migration.html"},{"key":"5_CR38","unstructured":"Varadarajan, V., Ristenpart, T., Swift, M.: Scheduler-based defenses against Cross-VM side-channels. In: Security 2014. USENIX Association, San Diego, August 2014"},{"key":"5_CR39","doi-asserted-by":"crossref","unstructured":"Wang, Z., Lee, R.B.: Covert and side channels due to processor architecture. In: 22nd Annual Computer Security Applications Conference, ACSAC 2006, pp. 473\u2013482. IEEE Computer Society, Washington, DC (2006)","DOI":"10.1109\/ACSAC.2006.20"},{"key":"5_CR40","unstructured":"Wu, Z., Xu, Z., Wang, H.: Whispers in the hyper-space: high-speed covert channel attacks in the cloud. In: Security 2012. USENIX Association, Berkeley (2012)"},{"key":"5_CR41","doi-asserted-by":"crossref","unstructured":"Xu, Y., Bailey, M., Jahanian, F., Joshi, K., Hiltunen, M., Schlichting, R.: An exploration of L2 cache covert channels in virtualized environments. In: CCSW 2011, pp. 29\u201340. ACM, New York (2011)","DOI":"10.1145\/2046660.2046670"},{"key":"5_CR42","first-page":"448","volume":"2013","author":"Y Yarom","year":"2013","unstructured":"Yarom, Y., Falkner, K.E.: Flush+reload: a high resolution, low noise, L3 cache side-channel attack. IACR Crypt. ePrint Arch. 2013, 448 (2013)","journal-title":"IACR Crypt. ePrint Arch."},{"key":"5_CR43","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Juels, A., Oprea, A., Reiter, M.K.: Homealone: co-residency detection in the cloud via side-channel analysis. In: S&P 2011, pp. 313\u2013328. IEEE Computer Society, Washington, DC (2011)","DOI":"10.1109\/SP.2011.31"},{"key":"5_CR44","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Juels, A., Reiter, M.K., Ristenpart, T.: Cross-tenant side-channel attacks in paas clouds. In: CCS 2014, pp. 990\u20131003. ACM, New York (2014)","DOI":"10.1145\/2660267.2660356"},{"key":"5_CR45","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Reiter, M.K.: D\u00fcppel: retrofitting commodity operating systems to mitigate cache side channels in the cloud. In: CCS 2013, pp. 827\u2013838. ACM, New York (2013)","DOI":"10.1145\/2508859.2516741"},{"key":"5_CR46","series-title":"IFIP Advances in Information and Communication Technology","doi-asserted-by":"publisher","first-page":"388","DOI":"10.1007\/978-3-642-30436-1_32","volume-title":"Information Security and Privacy Research","author":"M Yu","year":"2012","unstructured":"Yu, M., Zang, W., Zhang, Y., Li, M., Bai, K.: Incentive compatible moving target defense against VM-colocation attacks in clouds. In: Gritzalis, D., Furnell, S., Theoharidou, M. (eds.) SEC 2012. IFIP AICT, vol. 376, pp. 388\u2013399. Springer, Heidelberg (2012)"}],"container-title":["Lecture Notes in Computer Science","Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-23318-5_5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,30]],"date-time":"2025-05-30T04:59:24Z","timestamp":1748581164000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-23318-5_5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015]]},"ISBN":["9783319233178","9783319233185"],"references-count":46,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-23318-5_5","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2015]]},"assertion":[{"value":"27 August 2015","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}