{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T15:49:22Z","timestamp":1783007362491,"version":"3.54.5"},"reference-count":45,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2014,11,17]],"date-time":"2014-11-17T00:00:00Z","timestamp":1416182400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["0910483, 1330599"],"award-info":[{"award-number":["0910483, 1330599"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100007703","name":"North Carolina State University","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100007703","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100016682","name":"VMWare","doi-asserted-by":"crossref","id":[{"id":"10.13039\/100016682","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/100004316","name":"International Business Machines Corporation","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100004316","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Inf. Syst. Secur."],"published-print":{"date-parts":[[2014,11,17]]},"abstract":"<jats:p>This article presents StopWatch, a system that defends against timing-based side-channel attacks that arise from coresidency of victims and attackers in infrastructure-as-a-service clouds. StopWatch triplicates each cloud-resident guest virtual machine (VM) and places replicas so that the three replicas of a guest VM are coresident with nonoverlapping sets of (replicas of) other VMs. StopWatch uses the timing of I\/O events at a VM\u2019s replicas collectively to determine the timings observed by each one or by an external observer, so that observable timing behaviors are similarly likely in the absence of any other individual, coresident VMs. We detail the design and implementation of StopWatch in Xen, evaluate the factors that influence its performance, demonstrate its advantages relative to alternative defenses against timing side channels with commodity hardware, and address the problem of placing VM replicas in a cloud under the constraints of StopWatch so as to still enable adequate cloud utilization.<\/jats:p>","DOI":"10.1145\/2670940","type":"journal-article","created":{"date-parts":[[2014,11,24]],"date-time":"2014-11-24T15:29:41Z","timestamp":1416842981000},"page":"1-28","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":26,"title":["StopWatch"],"prefix":"10.1145","volume":"17","author":[{"given":"Peng","family":"Li","sequence":"first","affiliation":[{"name":"University of North Carolina at Chapel Hill"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Debin","family":"Gao","sequence":"additional","affiliation":[{"name":"Singapore Management University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michael K.","family":"Reiter","sequence":"additional","affiliation":[{"name":"University of North Carolina at Chapel Hill"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2014,11,17]]},"reference":[{"key":"e_1_2_2_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/325694.325702"},{"key":"e_1_2_2_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866341"},{"key":"e_1_2_2_3_1","volume-title":"Proceedings of the 9th USENIX Symposium on Operating Systems Design and Implementation.","author":"Aviram A.","unstructured":"A. Aviram , S.-C. Weng , S. Hu , and B. Ford . 2010. Efficient system-enforced deterministic parallelism . In Proceedings of the 9th USENIX Symposium on Operating Systems Design and Implementation. A. Aviram, S.-C. Weng, S. Hu, and B. Ford. 2010. Efficient system-enforced deterministic parallelism. In Proceedings of the 9th USENIX Symposium on Operating Systems Design and Implementation."},{"key":"e_1_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPDS.2006.56"},{"key":"e_1_2_2_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/2381913.2381915"},{"key":"e_1_2_2_6_1","volume-title":"Proceedings of the USENIX Annual Technical Conference, FREENIX Track. 41--46","author":"Bellard F.","year":"2005","unstructured":"F. Bellard . 2005 . QEMU, a fast and protable dynamic translator . In Proceedings of the USENIX Annual Technical Conference, FREENIX Track. 41--46 . F. Bellard. 2005. QEMU, a fast and protable dynamic translator. In Proceedings of the USENIX Annual Technical Conference, FREENIX Track. 41--46."},{"key":"e_1_2_2_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/58564.58565"},{"key":"e_1_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/225535.225538"},{"key":"e_1_2_2_10_1","volume-title":"Proceedings of the 12th USENIX Security Symposium. 1--14","author":"Brumley D.","unstructured":"D. Brumley and D. Boneh . 2003. Remote timing attacks are practical . In Proceedings of the 12th USENIX Security Symposium. 1--14 . D. Brumley and D. Boneh. 2003. Remote timing attacks are practical. In Proceedings of the 12th USENIX Security Symposium. 1--14."},{"key":"e_1_2_2_11_1","volume-title":"Proceedings of the 15th USENIX Security Symposium.","author":"Cox B.","unstructured":"B. Cox , D. Evans , A. Filipi , J. Rowanhill , W. Hu , J. Davidson , J. Knight , A. Nguyen-Tuong , and J. Hiser . 2006. N-variant systems: A secretless framework for security through diversity . In Proceedings of the 15th USENIX Security Symposium. B. Cox, D. Evans, A. Filipi, J. Rowanhill, W. Hu, J. Davidson, J. Knight, A. Nguyen-Tuong, and J. Hiser. 2006. N-variant systems: A secretless framework for security through diversity. In Proceedings of the 15th USENIX Security Symposium."},{"key":"e_1_2_2_12_1","volume-title":"Proceedings of the 5th USENIX Symposium on Networked Systems Design and Implementation. 161--174","author":"Cully B.","year":"2008","unstructured":"B. Cully , G. Lefebvre , D. Meyer , M. Feeley , N. Hutchinson , and Andrew Warfield . 2008 . Remus: High availability via asynchronous virtual machine replication . In Proceedings of the 5th USENIX Symposium on Networked Systems Design and Implementation. 161--174 . B. Cully, G. Lefebvre, D. Meyer, M. Feeley, N. Hutchinson, and Andrew Warfield. 2008. Remus: High availability via asynchronous virtual machine replication. In Proceedings of the 5th USENIX Symposium on Networked Systems Design and Implementation. 161--174."},{"key":"e_1_2_2_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/MM.2010.14"},{"key":"e_1_2_2_14_1","unstructured":"E. Deza and M. Deza. 2006. Dictionary of Distances. Elsevier.  E. Deza and M. Deza. 2006. Dictionary of Distances . Elsevier."},{"key":"e_1_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/1346256.1346273"},{"key":"e_1_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1007\/11663812_4"},{"key":"e_1_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2008.39"},{"key":"e_1_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.2002.801405"},{"key":"e_1_2_2_19_1","first-page":"795","article-title":"Distributions of order statistics","volume":"3","author":"G\u00fcng\u00f6r M.","year":"2009","unstructured":"M. G\u00fcng\u00f6r , Y. Bulut , and S. \u00c7al\u0131k . 2009 . Distributions of order statistics . Appl. Math. Sci. 3 , 16, 795 -- 802 . M. G\u00fcng\u00f6r, Y. Bulut, and S. \u00c7al\u0131k. 2009. Distributions of order statistics. Appl. Math. Sci. 3, 16, 795--802.","journal-title":"Appl. Math. Sci."},{"key":"e_1_2_2_20_1","volume-title":"Proceedings of the 20th USENIX Security Symposium.","author":"Haeberlen A.","unstructured":"A. Haeberlen , B. C. Pierce , and A. Narayan . 2011. Differential privacy under fire . In Proceedings of the 20th USENIX Security Symposium. A. Haeberlen, B. C. Pierce, and A. Narayan. 2011. Differential privacy under fire. In Proceedings of the 20th USENIX Security Symposium."},{"key":"e_1_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/2517488.2517491"},{"key":"e_1_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.1002\/jgt.20536"},{"key":"e_1_2_2_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/RISP.1991.130768"},{"key":"e_1_2_2_24_1","volume-title":"Intel 64 and IA-32 Architectures Software Developer\u2019s Manual","unstructured":"Intel. 2011. Intel 64 and IA-32 Architectures Software Developer\u2019s Manual . Intel Corporation . Intel. 2011. Intel 64 and IA-32 Architectures Software Developer\u2019s Manual. Intel Corporation."},{"key":"e_1_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/168588.168604"},{"key":"e_1_2_2_26_1","volume-title":"Proceedings of the INFOCOM. 1558--1569","author":"Karagiannis T.","unstructured":"T. Karagiannis , M. Molle , M. Faloutsos , and A. Broido . 2004. A nonstationary Poisson view of Internet traffic . In Proceedings of the INFOCOM. 1558--1569 . T. Karagiannis, M. Molle, M. Faloutsos, and A. Broido. 2004. A nonstationary Poisson view of Internet traffic. In Proceedings of the INFOCOM. 1558--1569."},{"key":"e_1_2_2_27_1","volume-title":"Proceedings of the 21st USENIX Security Symposium.","author":"Kim T.","unstructured":"T. Kim , M. Peinado , and G. Mainar-Ruiz . 2012. StealthMem: System-level protection against cache-based side channel attacks in the cloud . In Proceedings of the 21st USENIX Security Symposium. T. Kim, M. Peinado, and G. Mainar-Ruiz. 2012. StealthMem: System-level protection against cache-based side channel attacks in the cloud. In Proceedings of the 21st USENIX Security Symposium."},{"key":"e_1_2_2_28_1","unstructured":"C. C. Lindner and C. A. Rodger. 2008. Design Theory. CRC Press Chapter 1.   C. C. Lindner and C. A. Rodger. 2008. Design Theory . CRC Press Chapter 1."},{"key":"e_1_2_2_29_1","volume-title":"Proceedings of the IEEE Symposium on Reliable Distributed Systems. 263--273","author":"Narasimhan P.","unstructured":"P. Narasimhan , L. E. Moser , and P. M. Melliar-Smith . 1999. Enforcing determinism for the consistent replication of multithreaded CORBA applications . In Proceedings of the IEEE Symposium on Reliable Distributed Systems. 263--273 . P. Narasimhan, L. E. Moser, and P. M. Melliar-Smith. 1999. Enforcing determinism for the consistent replication of multithreaded CORBA applications. In Proceedings of the IEEE Symposium on Reliable Distributed Systems. 263--273."},{"key":"e_1_2_2_30_1","volume-title":"Proceeding of the 38th IEEE\/IFPF International Conference on Dependable Systems and Networks.","author":"Nguyen-Tuong A.","unstructured":"A. Nguyen-Tuong , D. Evans , J. C. Knight , B. Cox , and J. W. Davidson . 2008. Security through redundant data diversity . In Proceeding of the 38th IEEE\/IFPF International Conference on Dependable Systems and Networks. A. Nguyen-Tuong, D. Evans, J. C. Knight, B. Cox, and J. W. Davidson. 2008. Security through redundant data diversity. In Proceeding of the 38th IEEE\/IFPF International Conference on Dependable Systems and Networks."},{"key":"e_1_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/1500175.1500204"},{"key":"e_1_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/1655008.1655019"},{"key":"e_1_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653687"},{"key":"e_1_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/98163.98167"},{"key":"e_1_2_2_36_1","doi-asserted-by":"crossref","unstructured":"T. Speakman J. Crowcroft J. Gemmell D. Farinacci S. Lin D. Leshchiner M. Luby T. Montgomery L. Rizzo A. Tweedly N. Bhaskar R. Edmonstone R. Sumanasekara and L. Vicisano. 2001. PGM reliable transport protocol specification. Request for Comments 3208 Internet Engineering Task Force.   T. Speakman J. Crowcroft J. Gemmell D. Farinacci S. Lin D. Leshchiner M. Luby T. Montgomery L. Rizzo A. Tweedly N. Bhaskar R. Edmonstone R. Sumanasekara and L. Vicisano. 2001. PGM reliable transport protocol specification. Request for Comments 3208 Internet Engineering Task Force.","DOI":"10.17487\/rfc3208"},{"key":"e_1_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-009-9049-y"},{"key":"e_1_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2005.163"},{"key":"e_1_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046660.2046671"},{"key":"e_1_2_2_40_1","volume-title":"Timekeeping in VMware Virtual Machines","unstructured":"VMWare. 2010. Timekeeping in VMware Virtual Machines . VMWare Inc . VMWare. 2010. Timekeeping in VMware Virtual Machines. VMWare Inc."},{"key":"e_1_2_2_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/RISP.1991.130767"},{"key":"e_1_2_2_42_1","volume-title":"Proceedings of the 3rd Workshop on Modeling, Benchmarking and Simulation.","author":"Xu M.","unstructured":"M. Xu , V. Malyugin , J. Sheldon , G. Venkitachalam , and B. Weissman . 2007. ReTrace: Collecting execution trace with virtual machine deterministic replay . In Proceedings of the 3rd Workshop on Modeling, Benchmarking and Simulation. M. Xu, V. Malyugin, J. Sheldon, G. Venkitachalam, and B. Weissman. 2007. ReTrace: Collecting execution trace with virtual machine deterministic replay. In Proceedings of the 3rd Workshop on Modeling, Benchmarking and Simulation."},{"key":"e_1_2_2_43_1","volume-title":"Proceedings of the International Workshop on Future Directions in Distributed Computing.","author":"Yin J.","unstructured":"J. Yin , A. Venkataramani , J.-P. Martin , L. Alvisi , and M. Dahlin . 2002. Byzantine fault-tolerant confidentiality . In Proceedings of the International Workshop on Future Directions in Distributed Computing. J. Yin, A. Venkataramani, J.-P. Martin, L. Alvisi, and M. Dahlin. 2002. Byzantine fault-tolerant confidentiality. In Proceedings of the International Workshop on Future Directions in Distributed Computing."},{"key":"e_1_2_2_44_1","volume-title":"Proceedings of the 16th IEEE Computer Security Foundations Workshop. 29--43","author":"Zdancewic S.","unstructured":"S. Zdancewic and A. C. Myers . 2003. Observational determinism for concurrent program security . In Proceedings of the 16th IEEE Computer Security Foundations Workshop. 29--43 . S. Zdancewic and A. C. Myers. 2003. Observational determinism for concurrent program security. In Proceedings of the 16th IEEE Computer Security Foundations Workshop. 29--43."},{"key":"e_1_2_2_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046772"},{"key":"e_1_2_2_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/2254064.2254078"},{"key":"e_1_2_2_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382230"}],"container-title":["ACM Transactions on Information and System Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2670940","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2670940","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T06:12:18Z","timestamp":1750227138000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2670940"}},"subtitle":["A Cloud Architecture for Timing Channel Mitigation"],"short-title":[],"issued":{"date-parts":[[2014,11,17]]},"references-count":45,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2014,11,17]]}},"alternative-id":["10.1145\/2670940"],"URL":"https:\/\/doi.org\/10.1145\/2670940","relation":{},"ISSN":["1094-9224","1557-7406"],"issn-type":[{"value":"1094-9224","type":"print"},{"value":"1557-7406","type":"electronic"}],"subject":[],"published":{"date-parts":[[2014,11,17]]},"assertion":[{"value":"2014-01-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2014-09-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2014-11-17","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}