{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,26]],"date-time":"2025-03-26T12:48:19Z","timestamp":1742993299831,"version":"3.40.3"},"publisher-location":"Berlin, Heidelberg","reference-count":37,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783662496343"},{"type":"electronic","value":"9783662496350"}],"license":[{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016]]},"DOI":"10.1007\/978-3-662-49635-0_7","type":"book-chapter","created":{"date-parts":[[2016,3,21]],"date-time":"2016-03-21T08:03:52Z","timestamp":1458547432000},"page":"116-138","source":"Crossref","is-referenced-by-count":1,"title":["Towards a Comprehensive Model of Isolation for Mitigating Illicit Channels"],"prefix":"10.1007","author":[{"given":"Kevin","family":"Falzon","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Eric","family":"Bodden","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"7_CR1","unstructured":"CRIU project page, January 2016. \n                      http:\/\/criu.org\/Main_Page"},{"key":"7_CR2","unstructured":"Libvirt project page, January 2016. \n                      http:\/\/libvirt.org\/"},{"key":"7_CR3","unstructured":"Adams, K., Agesen, O.: A comparison of software and hardware techniques for x86 virtualization. In: Proceedings of the 12th International Conference on Architectural Support for Programming Languages and Operating Systems, pp. 2\u201313. ASPLOS XII. ACM, New York (2006). \n                      http:\/\/doi.acm.org\/10.1145\/1168857.1168860"},{"key":"7_CR4","unstructured":"Afoulki, Z., Rouzaud-Cornabas, J.: A security-aware scheduler for virtual machines on IaaS clouds. Technical report LIFO, ENSI de Bourges (2011)"},{"key":"7_CR5","unstructured":"Amazon: Amazon EC2 instances, April 2015. \n                      https:\/\/aws.amazon.com\/ec2\/instance-types\/"},{"key":"7_CR6","unstructured":"Azar, Y., Kamara, S., Menache, I., Raykova, M., Shepard, B.: Co-location-resistant clouds. In: Proceedings of the 6th Edition of the ACM Workshop on Cloud Computing Security, pp. 9\u201320. CCSW 2014. ACM, New York (2014). \n                      http:\/\/doi.acm.org\/10.1145\/2664168.2664179"},{"key":"7_CR7","doi-asserted-by":"crossref","unstructured":"Backes, M., Kopf, B., Rybalchenko, A.: Automatic discovery and quantification of information leaks. In: Proceedings of the 2009 30th IEEE Symposium on Security and Privacy, SP 2009, pp. 141\u2013153. IEEE Computer Society, Washington, DC (2009). \n                      http:\/\/dx.doi.org\/10.1109\/SP.2009.18","DOI":"10.1109\/SP.2009.18"},{"key":"7_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"205","DOI":"10.1007\/978-3-540-40965-6_14","volume-title":"Advances in Computing Science \u2013 ASIAN 2003. Progamming Languages and Distributed Computation Programming Languages and Distributed Computation","author":"F Barbanera","year":"2003","unstructured":"Barbanera, F., Bugliesi, M., Dezani-Ciancaglini, M., Sassone, V.: A calculus of bounded capacities. In: Saraswat, V.A. (ed.) ASIAN 2003. LNCS, vol. 2896, pp. 205\u2013223. Springer, Heidelberg (2003)"},{"key":"7_CR9","unstructured":"Baumann, A., Peinado, M., Hunt, G.: Shielding applications from an untrusted cloud with haven. In: 11th USENIX Symposium on Operating Systems Design and Implementation (OSDI 2014), pp. 267\u2013283. USENIX Association, Broomfield, October 2014. \n                      https:\/\/www.usenix.org\/conference\/osdi14\/technical-sessions\/presentation\/baumann"},{"key":"7_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"41","DOI":"10.1007\/978-3-319-11698-3_4","volume-title":"Network and System Security","author":"KZ Bijon","year":"2014","unstructured":"Bijon, K.Z., Krishnan, R., Sandhu, R.: A formal model for isolation management in cloud infrastructure-as-a-service. In: Au, M.H., Carminati, B., Kuo, C.-C.J. (eds.) NSS 2014. LNCS, vol. 8792, pp. 41\u201353. Springer, Heidelberg (2014)"},{"key":"7_CR11","unstructured":"Bleikertz, S., Gro\u00df, T., M\u00f6dersheim, S.: Automated verification of virtualized infrastructures. In: Proceedings of the 3rd ACM Workshop on Cloud Computing Security Workshop, CCSW 2011, pp. 47\u201358. ACM, New York (2011). \n                      http:\/\/doi.acm.org\/10.1145\/2046660.2046672"},{"key":"7_CR12","unstructured":"Bleikertz, S., Gro\u00df, T., M\u00f6dersheim, S.: Modeling and analysis of dynamic infrastructure clouds. Technical report, IBM Zurich, December 2013"},{"key":"7_CR13","unstructured":"Bleikertz, S., Vogel, C., Gro\u00df, T.: Cloud radar: near real-time detection of security failures in dynamic virtualized infrastructures. In: Proceedings of the 30th Annual Computer Security Applications Conference, ACSAC 2014, pp. 26\u201335. ACM, New York (2014). \n                      http:\/\/doi.acm.org\/10.1145\/2664243.2664274"},{"key":"7_CR14","unstructured":"Bleikertz, S., Gro, T.: A virtualization assurance language for isolation and deployment. In: POLICY, pp. 33\u201340. IEEE Computer Society (2011). \n                      http:\/\/dblp.uni-trier.de\/db\/conf\/policy\/policy2011.html#BleikertzG11"},{"issue":"1","key":"7_CR15","first-page":"101","volume":"28","author":"C Braghin","year":"2002","unstructured":"Braghin, C., Cortesi, A., Focardi, R.: Security boundaries in mobile ambients. Comput. Lang. Syst. Struct. 28(1), 101\u2013127 (2002). Computer Languages and Security. \n                      http:\/\/www.sciencedirect.com\/science\/article\/pii\/S0096055102000097","journal-title":"Comput. Lang. Syst. Struct."},{"key":"7_CR16","doi-asserted-by":"crossref","unstructured":"Broquedis, F., Clet-Ortega, J., Moreaud, S., Furmento, N., Goglin, B., Mercier,G., Thibault, S., Namyst, R.: hwloc: a generic framework for managing hardware affinities in HPC applications. In: The 18th Euromicro International Conference on Parallel, Distributed and Network-Based Computing, PDP 2010. IEEE, Pisa, February 2010. \n                      https:\/\/hal.inria.fr\/inria-00429889","DOI":"10.1109\/PDP.2010.67"},{"key":"7_CR17","doi-asserted-by":"crossref","unstructured":"Cardelli, L., Gordon, A.D.: Mobile ambients. In: Proceedings of POPL 1998. ACM Press (1998)","DOI":"10.1007\/BFb0053547"},{"key":"7_CR18","doi-asserted-by":"crossref","unstructured":"Caron, E., Rouzaud-Cornabas, J.: Improving users\u2019 isolation in IaaS: virtual machine placement with security constraints. Research report RR-8444, INRIA, January 2014. \n                      https:\/\/hal.inria.fr\/hal-00924296","DOI":"10.1109\/CLOUD.2014.19"},{"key":"7_CR19","unstructured":"Dolan-Gavitt, B., Leek, T., Hodosh, J., Lee, W.: Tappan zee (north) bridge: mining memory accesses for introspection. In: ACM CCS 2013, pp. 839\u2013850. ACM, New York (2013). \n                      http:\/\/doi.acm.org\/10.1145\/2508859.2516697"},{"key":"7_CR20","unstructured":"Doychev, G., Feld, D., K\u00f6pf, B., Mauborgne, L., Reineke, J.: Cacheaudit: A tool for the static analysis of cache side channels. In: Proceedings of the 22nd USENIX Conference on Security, SEC 2013, pp. 431\u2013446. USENIX Association, Berkeley (2013). \n                      http:\/\/dl.acm.org\/citation.cfm?id=2534766.2534804"},{"key":"7_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"83","DOI":"10.1007\/978-3-319-23318-5_5","volume-title":"Information Security","author":"K Falzon","year":"2015","unstructured":"Falzon, K., Bodden, E.: Dynamically provisioning isolation in hierarchical architectures. In: L\u00f3pez, J., Mitchell, C.J. (eds.) ISC 2015. LNCS, vol. 9290, pp. 83\u2013101. Springer, Heidelberg (2015). \n                      http:\/\/dx.doi.org\/10.1007\/978-3-319-23318-5_5"},{"issue":"1","key":"7_CR22","doi-asserted-by":"publisher","first-page":"113","DOI":"10.1007\/s10044-008-0141-y","volume":"13","author":"X Gao","year":"2010","unstructured":"Gao, X., Xiao, B., Tao, D., Li, X.: A survey of graph edit distance. Pattern Anal. Appl. 13(1), 113\u2013129 (2010). \n                      http:\/\/dx.doi.org\/10.1007\/s10044-008-0141-y","journal-title":"Pattern Anal. Appl."},{"key":"7_CR23","unstructured":"Gueron, S.: Intel advanced encryption standard (aes) new instructions set, May 2010. \n                      http:\/\/www.intel.com\/content\/dam\/doc\/white-paper\/advanced-encryption-standard-new-instructions-set-paper.pdf"},{"key":"7_CR24","unstructured":"Hu, W.M.: Reducing timing channels with fuzzy time. In: Proceedings, 1991 IEEE Computer Society Symposium on Research in Security and Privacy, 1991, pp. 8\u201320, May 1991"},{"key":"7_CR25","unstructured":"Jarraya, Y., Eghtesadi, A., Debbabi, M., Zhang, Y., Pourzandi, M.: Cloud calculus: security verification in elastic cloud computing platform. In: Smari, W.W., Fox, G.C. (eds.) CTS, pp. 447\u2013454. IEEE (2012). \n                      http:\/\/dblp.uni-trier.de\/db\/conf\/cts\/cts2012.html#JarrayaEDZP12"},{"key":"7_CR26","unstructured":"Kim, T., Peinado, M., Mainar-Ruiz, G.: Stealthmem: system-level protection against cache-based side channel attacks in the cloud. In: 21st USENIX Conference on Security Symposium. Security 2012. USENIX Association, Berkeley (2012). \n                      http:\/\/dl.acm.org\/citation.cfm?id=2362793.2362804"},{"key":"7_CR27","doi-asserted-by":"crossref","unstructured":"Li, P., Gao, D., Reiter, M.: Mitigating access-driven timing channels in clouds using stopwatch. In: 2013 43rd Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN), pp. 1\u201312, June 2013","DOI":"10.1109\/DSN.2013.6575299"},{"key":"7_CR28","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/11605805_1","volume-title":"Topics in Cryptology \u2013 CT-RSA 2006","author":"DA Osvik","year":"2006","unstructured":"Osvik, D.A., Shamir, A., Tromer, E.: Cache attacks and countermeasures: the case of AES. In: Pointcheval, D. (ed.) CT-RSA 2006. LNCS, vol. 3860, pp. 1\u201320. Springer, Heidelberg (2006). \n                      http:\/\/dx.doi.org\/10.1007\/11605805_1"},{"key":"7_CR29","doi-asserted-by":"crossref","unstructured":"Priebe, C., Muthukumaran, D., O\u2019Keeffe, D., Eyers, D., Shand, B., Kapitza, R., Pietzuch, P.: Cloudsafetynet: detecting data leakage between cloud tenants. In: ACM Cloud Computing Security Workshop (CCSW). ACM, Scottsdale, November 2014","DOI":"10.1145\/2664168.2664174"},{"key":"7_CR30","unstructured":"Raj, H., Nathuji, R., Singh, A., England, P.: Resource management for isolation enhanced cloud services. In: Proceedings of the 2009 ACM Workshop on Cloud Computing Security, CCSW 2009, pp. 77\u201384. ACM, New York (2009). \n                      http:\/\/doi.acm.org\/10.1145\/1655008.1655019"},{"key":"7_CR31","unstructured":"Varadarajan, V., Kooburat, T., Farley, B., Ristenpart, T., Swift, M.M.: Resource-freeing attacks: improve your cloud performance (at your neighbor\u2019s expense). In: Proceedings of the 2012 ACM Conference on Computer and Communications Security, CCS 2012, pp. 281\u2013292. ACM, New York (2012). \n                      http:\/\/doi.acm.org\/10.1145\/2382196.2382228"},{"key":"7_CR32","unstructured":"Varadarajan, V., Ristenpart, T., Swift, M.: Scheduler-based defenses against cross-vm side-channels. In: 23rd USENIX Security Symposium (USENIX Security 2014), pp. 687\u2013702. USENIX Association, San Diego, August 2014. \n                      https:\/\/www.usenix.org\/conference\/usenixsecurity14\/technical-sessions\/presentation\/varadarajan"},{"key":"7_CR33","unstructured":"Wu, Z., Xu, Z., Wang, H.: Whispers in the hyper-space: high-speed covert channel attacks in the cloud. In: 21st USENIX Conference on Security Symposium, Security 2012, pp. 159\u2013173. USENIX Association, Berkeley (2012). \n                      http:\/\/dl.acm.org\/citation.cfm?id=2362793.2362802"},{"key":"7_CR34","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Juels, A., Oprea, A., Reiter, M.K.: Homealone: Co-residency detection in the cloud via side-channel analysis. In: IEEE S&P 2011, pp. 313\u2013328. IEEE Computer Society, Washington, DC (2011). \n                      http:\/\/dx.doi.org\/10.1109\/SP.2011.31","DOI":"10.1109\/SP.2011.31"},{"key":"7_CR35","unstructured":"Zhang, Y., Juels, A., Reiter, M.K., Ristenpart, T.: Cross-vm side channels and their use to extract private keys. In: ACM CCS 2012, pp. 305\u2013316. ACM, New York (2012). \n                      http:\/\/doi.acm.org\/10.1145\/2382196.2382230"},{"key":"7_CR36","unstructured":"Zhang, Y., Juels, A., Reiter, M.K., Ristenpart, T.: Cross-tenant side-channel attacks in paas clouds. In: Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, CCS 2014, pp. 990\u20131003. ACM, New York (2014). \n                      http:\/\/doi.acm.org\/10.1145\/2660267.2660356"},{"key":"7_CR37","unstructured":"Zhang, Y., Reiter, M.K.: D\u00fcppel: retrofitting commodity operating systems to mitigate cache side channels in the cloud. In: ACM CCS 2013, pp. 827\u2013838. ACM, New York (2013). \n                      http:\/\/doi.acm.org\/10.1145\/2508859.2516741"}],"container-title":["Lecture Notes in Computer Science","Principles of Security and Trust"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-662-49635-0_7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,6,1]],"date-time":"2019-06-01T16:16:21Z","timestamp":1559405781000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-662-49635-0_7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016]]},"ISBN":["9783662496343","9783662496350"],"references-count":37,"URL":"https:\/\/doi.org\/10.1007\/978-3-662-49635-0_7","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2016]]}}}