{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T15:54:52Z","timestamp":1783007692714,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":98,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,10,5]],"date-time":"2020-10-05T00:00:00Z","timestamp":1601856000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100007601","name":"Horizon 2020","doi-asserted-by":"publisher","award":["681402"],"award-info":[{"award-number":["681402"]}],"id":[{"id":"10.13039\/501100007601","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100002418","name":"Intel Corporation","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100002418","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Cloudflare"},{"name":"\u00d6sterreichische Forschungsf\u00f6rderungsgesellschaft","award":["ESPRESSO"],"award-info":[{"award-number":["ESPRESSO"]}]},{"name":"ARM"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,10,5]]},"DOI":"10.1145\/3320269.3384747","type":"proceedings-article","created":{"date-parts":[[2020,10,5]],"date-time":"2020-10-05T16:33:22Z","timestamp":1601915602000},"page":"481-493","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":40,"title":["KASLR: Break It, Fix It, Repeat"],"prefix":"10.1145","author":[{"given":"Claudio","family":"Canella","sequence":"first","affiliation":[{"name":"Graz University of Technology, Graz, Austria"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michael","family":"Schwarz","sequence":"additional","affiliation":[{"name":"Graz University of Technology, Graz, Austria"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Martin","family":"Haubenwallner","sequence":"additional","affiliation":[{"name":"Graz University of Technology, Graz, Austria"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Martin","family":"Schwarzl","sequence":"additional","affiliation":[{"name":"Graz University of Technology, Graz, Austria"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Daniel","family":"Gruss","sequence":"additional","affiliation":[{"name":"Graz University of Technology, Graz, Austria"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2020,10,5]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Tiago Alves. 2004. TrustZone: Integrated Hardware and Software Security.  Tiago Alves. 2004. TrustZone: Integrated Hardware and Software Security."},{"key":"e_1_3_2_1_2_1","unstructured":"Apple Inc. 2012. OS X Mountain Lion Core Technologies Overview. http:\/\/movies.apple.com\/media\/us\/osx\/2012\/docs\/OSX_MountainLion_Core_Technologies_Overview.pdf  Apple Inc. 2012. OS X Mountain Lion Core Technologies Overview. http:\/\/movies.apple.com\/media\/us\/osx\/2012\/docs\/OSX_MountainLion_Core_Technologies_Overview.pdf"},{"key":"e_1_3_2_1_3_1","unstructured":"ARM Limited. 2018. Vulnerability of Speculative Processors to Cache Timing Side-Channel Mechanism.  ARM Limited. 2018. Vulnerability of Speculative Processors to Cache Timing Side-Channel Mechanism."},{"key":"e_1_3_2_1_4_1","volume-title":"Nigel P Smart, and Yuval Yarom","author":"Benger Naomi","year":"2014"},{"key":"e_1_3_2_1_5_1","unstructured":"Daniel J. Bernstein. 200"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"crossref","unstructured":"Erik Bosman and Herbert Bos. 2014. Framing Signals - A Return to Portable Shellcode. In S&P.  Erik Bosman and Herbert Bos. 2014. Framing Signals - A Return to Portable Shellcode. In S&P.","DOI":"10.1109\/SP.2014.23"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"crossref","unstructured":"Erik Bosman Kaveh Razavi Herbert Bos and Cristiano Giuffrida. 2016. Dedup Est Machina: Memory Deduplication as an Advanced Exploitation Vector. In S&P.  Erik Bosman Kaveh Razavi Herbert Bos and Cristiano Giuffrida. 2016. Dedup Est Machina: Memory Deduplication as an Advanced Exploitation Vector. In S&P.","DOI":"10.1109\/SP.2016.63"},{"key":"e_1_3_2_1_8_1","unstructured":"Ferdinand Brasser Urs M\u00fcller Alexandra Dmitrienko Kari Kostiainen Srdjan Capkun and Ahmad-Reza Sadeghi. 2017. Software Grand Exposure: SGX Cache Attacks Are Practical. In WOOT.  Ferdinand Brasser Urs M\u00fcller Alexandra Dmitrienko Kari Kostiainen Srdjan Capkun and Ahmad-Reza Sadeghi. 2017. Software Grand Exposure: SGX Cache Attacks Are Practical. In WOOT."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"crossref","unstructured":"Claudio Canella Daniel Genkin Lukas Giner Daniel Gruss Moritz Lipp Marina Minkin Daniel Moghimi Frank Piessens Michael Schwarz Berk Sunar Jo Van Bulck and Yuval Yarom. 2019 a. Fallout: Leaking Data on Meltdown-resistant CPUs. In CCS.  Claudio Canella Daniel Genkin Lukas Giner Daniel Gruss Moritz Lipp Marina Minkin Daniel Moghimi Frank Piessens Michael Schwarz Berk Sunar Jo Van Bulck and Yuval Yarom. 2019 a. Fallout: Leaking Data on Meltdown-resistant CPUs. In CCS.","DOI":"10.1145\/3319535.3363219"},{"key":"e_1_3_2_1_10_1","volume-title":"USENIX Security Symposium.","author":"Canella Claudio","year":"2019"},{"key":"e_1_3_2_1_11_1","volume-title":"USENIX Security Symposium.","author":"Carlini Nicholas","year":"2015"},{"key":"e_1_3_2_1_12_1","volume-title":"Wagner","author":"Carlini Nicholas","year":"2014"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"crossref","unstructured":"Stephen Checkoway Lucas Davi Alexandra Dmitrienko Ahmad-Reza Sadeghi Hovav Shacham and Marcel Winandy. 2010. Return-oriented programming without returns. In CCS.  Stephen Checkoway Lucas Davi Alexandra Dmitrienko Ahmad-Reza Sadeghi Hovav Shacham and Marcel Winandy. 2010. Return-oriented programming without returns. In CCS.","DOI":"10.1145\/1866307.1866370"},{"key":"e_1_3_2_1_14_1","unstructured":"Liang Chen and Qidan He. 2016. Shooting the OS X El Capitan Kernel Like a Sniper.  Liang Chen and Qidan He. 2016. Shooting the OS X El Capitan Kernel Like a Sniper."},{"key":"e_1_3_2_1_15_1","unstructured":"Jonathan Corbet. 2018. Preventing kernel-stack leaks. https:\/\/lwn.net\/Articles\/748642\/  Jonathan Corbet. 2018. Preventing kernel-stack leaks. https:\/\/lwn.net\/Articles\/748642\/"},{"key":"e_1_3_2_1_16_1","volume-title":"SPEC CPU 2017","author":"Standard Performance Evaluation Corporation","year":"2017"},{"key":"e_1_3_2_1_17_1","unstructured":"Ian Cutress. 2018. Spectre and Meltdown in Hardware: Intel Clarifies Whiskey Lake and Amber Lake. https:\/\/www.anandtech.com\/show\/13301\/spectre-and-meltdown-in-hardware-intel-clarifies-whiskey-lake-and-amber-lake  Ian Cutress. 2018. Spectre and Meltdown in Hardware: Intel Clarifies Whiskey Lake and Amber Lake. https:\/\/www.anandtech.com\/show\/13301\/spectre-and-meltdown-in-hardware-intel-clarifies-whiskey-lake-and-amber-lake"},{"key":"e_1_3_2_1_18_1","unstructured":"Lizzie Dixon. 2017. Breaking KASLR with perf. https:\/\/blog.lizzie.io\/kaslr-and-perf.html  Lizzie Dixon. 2017. Breaking KASLR with perf. https:\/\/blog.lizzie.io\/kaslr-and-perf.html"},{"key":"e_1_3_2_1_19_1","unstructured":"ecma international. 2018. ECMAScript 2018 Language Specification. https:\/\/www.ecma-international.org\/ecma-262\/9.0\/index.html  ecma international. 2018. ECMAScript 2018 Language Specification. https:\/\/www.ecma-international.org\/ecma-262\/9.0\/index.html"},{"key":"e_1_3_2_1_20_1","unstructured":"Jake Edge. 2013. Kernel address space layout randomization. https:\/\/lwn.net\/Articles\/569635\/  Jake Edge. 2013. Kernel address space layout randomization. https:\/\/lwn.net\/Articles\/569635\/"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"crossref","unstructured":"Dmitry Evtyushkin Dmitry Ponomarev and Nael Abu-Ghazaleh. 2016. Jump over ASLR: Attacking branch predictors to bypass ASLR. In MICRO.  Dmitry Evtyushkin Dmitry Ponomarev and Nael Abu-Ghazaleh. 2016. Jump over ASLR: Attacking branch predictors to bypass ASLR. In MICRO.","DOI":"10.1109\/MICRO.2016.7783743"},{"key":"e_1_3_2_1_22_1","unstructured":"Agner Fog. 2016. The microarchitecture of Intel AMD and VIA CPUs: An optimization guide for assembly programmers and compiler makers.  Agner Fog. 2016. The microarchitecture of Intel AMD and VIA CPUs: An optimization guide for assembly programmers and compiler makers."},{"key":"e_1_3_2_1_23_1","unstructured":"Ulf Frisk. 2016. Windows 10 KASLR Recovery with TSX. http:\/\/blog.frizk.net\/2016\/11\/windows-10-kaslr-recovery-with-tsx.html  Ulf Frisk. 2016. Windows 10 KASLR Recovery with TSX. http:\/\/blog.frizk.net\/2016\/11\/windows-10-kaslr-recovery-with-tsx.html"},{"key":"e_1_3_2_1_24_1","unstructured":"Thomas Garnier. 2016. Kernel memory randomization and trampoline page tables. https:\/\/medium.com\/@mxatone\/kernel-memory-randomization-and-trampoline-page-tables-9f73827270ab  Thomas Garnier. 2016. Kernel memory randomization and trampoline page tables. https:\/\/medium.com\/@mxatone\/kernel-memory-randomization-and-trampoline-page-tables-9f73827270ab"},{"key":"e_1_3_2_1_25_1","volume-title":"A Survey of Microarchitectural Timing Attacks and Countermeasures on Contemporary Hardware. Journal of Cryptographic Engineering","author":"Ge Qian","year":"2016"},{"key":"e_1_3_2_1_26_1","volume-title":"LAZARUS: Practical Side-Channel Resilient Kernel-Space Randomization. In RAID.","author":"Gens David","year":"2017"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"crossref","unstructured":"Jason Gionta William Enck and Per Larsen. 2016. Preventing kernel code-reuse attacks through disclosure resistant code diversification. In Communications and Network Security (CNS).  Jason Gionta William Enck and Per Larsen. 2016. Preventing kernel code-reuse attacks through disclosure resistant code diversification. In Communications and Network Security (CNS).","DOI":"10.1109\/CNS.2016.7860485"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"crossref","unstructured":"Enes G\u00f6 ktas Elias Athanasopoulos Herbert Bos and Georgios Portokalidis. 2014. Out of Control: Overcoming Control-Flow Integrity. In S&P.  Enes G\u00f6 ktas Elias Athanasopoulos Herbert Bos and Georgios Portokalidis. 2014. Out of Control: Overcoming Control-Flow Integrity. In S&P.","DOI":"10.1109\/SP.2014.43"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"crossref","unstructured":"Ben Gras Kaveh Razavi Erik Bosman Herbert Bos and Cristiano Giuffrida. 2017. ASLR on the Line: Practical Cache Attacks on the MMU. In NDSS.  Ben Gras Kaveh Razavi Erik Bosman Herbert Bos and Cristiano Giuffrida. 2017. ASLR on the Line: Practical Cache Attacks on the MMU. In NDSS.","DOI":"10.14722\/ndss.2017.23271"},{"key":"e_1_3_2_1_30_1","volume-title":"Kernel Isolation: From an Academic Idea to an Efficient Patch for Every Computer. USENIX ;login","author":"Gruss Daniel","year":"2018"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"crossref","unstructured":"Daniel Gruss Moritz Lipp Michael Schwarz Richard Fellner Cl\u00e9mentine Maurice and Stefan Mangard. 2017. KASLR is Dead: Long Live KASLR. In ESSoS.  Daniel Gruss Moritz Lipp Michael Schwarz Richard Fellner Cl\u00e9mentine Maurice and Stefan Mangard. 2017. KASLR is Dead: Long Live KASLR. In ESSoS.","DOI":"10.1007\/978-3-319-62105-0_11"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"crossref","unstructured":"Daniel Gruss Cl\u00e9mentine Maurice Anders Fogh Moritz Lipp and Stefan Mangard. 2016a. Prefetch Side-Channel Attacks: Bypassing SMAP and Kernel ASLR. In CCS.  Daniel Gruss Cl\u00e9mentine Maurice Anders Fogh Moritz Lipp and Stefan Mangard. 2016a. Prefetch Side-Channel Attacks: Bypassing SMAP and Kernel ASLR. In CCS.","DOI":"10.1145\/2976749.2978356"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"crossref","unstructured":"Daniel Gruss Cl\u00e9mentine Maurice Klaus Wagner and Stefan Mangard. 2016b. Flush+Flush: A Fast and Stealthy Cache Attack. In DIMVA.  Daniel Gruss Cl\u00e9mentine Maurice Klaus Wagner and Stefan Mangard. 2016b. Flush+Flush: A Fast and Stealthy Cache Attack. In DIMVA.","DOI":"10.1007\/978-3-319-40667-1_14"},{"key":"e_1_3_2_1_34_1","volume-title":"Cache Template Attacks: Automating Attacks on Inclusive Last-Level Caches. In USENIX Security Symposium.","author":"Gruss Daniel","year":"2015"},{"key":"e_1_3_2_1_35_1","unstructured":"Noam Hadad and Jonathan Afek. 2018. Overcoming (some) Spectre browser mitigations. https:\/\/alephsecurity.com\/2018\/06\/26\/spectre-browser-query-cache\/  Noam Hadad and Jonathan Afek. 2018. Overcoming (some) Spectre browser mitigations. https:\/\/alephsecurity.com\/2018\/06\/26\/spectre-browser-query-cache\/"},{"key":"e_1_3_2_1_36_1","unstructured":"Jann Horn. 2018. speculative execution variant 4: speculative store bypass.  Jann Horn. 2018. speculative execution variant 4: speculative store bypass."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"crossref","unstructured":"Ralf Hund Carsten Willems and Thorsten Holz. 2013. Practical Timing Side Channel Attacks against Kernel Space ASLR. In S&P.  Ralf Hund Carsten Willems and Thorsten Holz. 2013. Practical Timing Side Channel Attacks against Kernel Space ASLR. In S&P.","DOI":"10.1109\/SP.2013.23"},{"key":"e_1_3_2_1_38_1","unstructured":"Intel. [n.d.]. Intel 64 and IA-32 Architectures Optimization Reference Manual. https:\/\/www.intel.com\/content\/www\/us\/en\/architecture-and-technology\/64-ia-32-architectures-optimization-manual.html  Intel. [n.d.]. Intel 64 and IA-32 Architectures Optimization Reference Manual. https:\/\/www.intel.com\/content\/www\/us\/en\/architecture-and-technology\/64-ia-32-architectures-optimization-manual.html"},{"key":"e_1_3_2_1_39_1","unstructured":"Intel. 2018a. Intel Analysis of Speculative Execution Side Channels. https:\/\/software.intel.com\/security-software-guidance\/api-app\/sites\/default\/files\/336983-Intel-Analysis-of-Speculative-Execution-Side-Channels-White-Paper.pdf  Intel. 2018a. Intel Analysis of Speculative Execution Side Channels. https:\/\/software.intel.com\/security-software-guidance\/api-app\/sites\/default\/files\/336983-Intel-Analysis-of-Speculative-Execution-Side-Channels-White-Paper.pdf"},{"key":"e_1_3_2_1_40_1","unstructured":"Intel. 2018b. Speculative Execution Side Channel Mitigations. Revision 3.0.  Intel. 2018b. Speculative Execution Side Channel Mitigations. Revision 3.0."},{"key":"e_1_3_2_1_41_1","unstructured":"Intel. 2019 a. Deep Dive: Intel Analysis of Microarchitectural Data Sampling. https:\/\/software.intel.com\/security-software-guidance\/insights\/deep-dive-intel-analysis-microarchitectural-data-sampling  Intel. 2019 a. Deep Dive: Intel Analysis of Microarchitectural Data Sampling. https:\/\/software.intel.com\/security-software-guidance\/insights\/deep-dive-intel-analysis-microarchitectural-data-sampling"},{"key":"e_1_3_2_1_42_1","volume-title":"2019 b. Intel 64 and IA-32 Architectures Software Developer's Manual"},{"key":"e_1_3_2_1_43_1","unstructured":"Intel. 2019 c. Performance Monitoring Impact of Intel Transactional Synchronization Extension Memory. https:\/\/cdrdv2.intel.com\/v1\/dl\/getContent\/604224  Intel. 2019 c. Performance Monitoring Impact of Intel Transactional Synchronization Extension Memory. https:\/\/cdrdv2.intel.com\/v1\/dl\/getContent\/604224"},{"key":"e_1_3_2_1_44_1","volume-title":"Twitter: Windows KASLR. https:\/\/twitter.com\/aionescu\/status\/725399988306644992","author":"Ionescu Alex","year":"2016"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"crossref","unstructured":"Gorka Irazoqui Thomas Eisenbarth and Berk Sunar. 2015. S$A: A Shared Cache Attack that Works Across Cores and Defies VM Sandboxing -- and its Application to AES. In S&P.  Gorka Irazoqui Thomas Eisenbarth and Berk Sunar. 2015. S$A: A Shared Cache Attack that Works Across Cores and Defies VM Sandboxing -- and its Application to AES. In S&P.","DOI":"10.1109\/SP.2015.42"},{"key":"e_1_3_2_1_46_1","volume-title":"Thomas Eisenbarth, and Berk Sunar.","author":"Irazoqui Gorka","year":"2014"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"crossref","unstructured":"Kyriakos K. Ispoglou Bader AlBassam Trent Jaeger and Mathias Payer. 2018. Block Oriented Programming: Automating Data-Only Attacks. In CCS.  Kyriakos K. Ispoglou Bader AlBassam Trent Jaeger and Mathias Payer. 2018. Block Oriented Programming: Automating Data-Only Attacks. In CCS.","DOI":"10.1145\/3243734.3243739"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"crossref","unstructured":"Yeongjin Jang Jaehyuk Lee Sangho Lee and Taesoo Kim. 2017. SGX-Bomb: Locking Down the Processor via Rowhammer Attack. In SysTEX.  Yeongjin Jang Jaehyuk Lee Sangho Lee and Taesoo Kim. 2017. SGX-Bomb: Locking Down the Processor via Rowhammer Attack. In SysTEX.","DOI":"10.1145\/3152701.3152709"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"crossref","unstructured":"Yeongjin Jang Sangho Lee and Taesoo Kim. 2016. Breaking Kernel Address Space Layout Randomization with Intel TSX. In CCS.  Yeongjin Jang Sangho Lee and Taesoo Kim. 2016. Breaking Kernel Address Space Layout Randomization with Intel TSX. In CCS.","DOI":"10.1145\/2976749.2978321"},{"key":"e_1_3_2_1_50_1","unstructured":"David Kaplan Jeremy Powell and Tom Woller. 2016. AMD Memory Encryption.  David Kaplan Jeremy Powell and Tom Woller. 2016. AMD Memory Encryption."},{"key":"e_1_3_2_1_51_1","volume-title":"Speculative Buffer Overflows: Attacks and Defenses. arXiv:1807.03757","author":"Kiriansky Vladimir","year":"2018"},{"key":"e_1_3_2_1_52_1","unstructured":"Amit Klein and Benny Pinkas. 2019. From IP ID to Device ID and KASLR Bypass. In USENIX Security.  Amit Klein and Benny Pinkas. 2019. From IP ID to Device ID and KASLR Bypass. In USENIX Security."},{"key":"e_1_3_2_1_53_1","volume-title":"Spectre Attacks: Exploiting Speculative Execution. In S&P.","author":"Kocher Paul","year":"2019"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"crossref","unstructured":"Paul C. Kocher. 1996. Timing Attacks on Implementations of Diffe-Hellman RSA DSS and Other Systems. In CRYPTO.  Paul C. Kocher. 1996. Timing Attacks on Implementations of Diffe-Hellman RSA DSS and Other Systems. In CRYPTO.","DOI":"10.1007\/3-540-68697-5_9"},{"key":"e_1_3_2_1_55_1","unstructured":"Esmaeil Mohammadian Koruyeh Khaled Khasawneh Chengyu Song and Nael Abu-Ghazaleh. 2018. Spectre Returns! Speculation Attacks using the Return Stack Buffer. In WOOT.  Esmaeil Mohammadian Koruyeh Khaled Khasawneh Chengyu Song and Nael Abu-Ghazaleh. 2018. Spectre Returns! Speculation Attacks using the Return Stack Buffer. In WOOT."},{"key":"e_1_3_2_1_56_1","volume-title":"USENIX Security Symposium.","author":"Lee Jaehyuk","year":"2017"},{"key":"e_1_3_2_1_57_1","unstructured":"Linux. 2019. Complete virtual memory map with 4-level page tables. https:\/\/www.kernel.org\/doc\/Documentation\/x86\/x86_64\/mm.txt  Linux. 2019. Complete virtual memory map with 4-level page tables. https:\/\/www.kernel.org\/doc\/Documentation\/x86\/x86_64\/mm.txt"},{"key":"e_1_3_2_1_58_1","volume-title":"ARMageddon: Cache Attacks on Mobile Devices. In USENIX Security Symposium.","author":"Lipp Moritz","year":"2016"},{"key":"e_1_3_2_1_59_1","volume-title":"USENIX Security Symposium.","author":"Lipp Moritz","year":"2018"},{"key":"e_1_3_2_1_60_1","volume-title":"Lee","author":"Liu Fangfei","year":"2015"},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"crossref","unstructured":"G. Maisuradze and C. Rossow. 2018. ret2spec: Speculative Execution Using Return Stack Buffers. In CCS.  G. Maisuradze and C. Rossow. 2018. ret2spec: Speculative Execution Using Return Stack Buffers. In CCS.","DOI":"10.1145\/3243734.3243761"},{"key":"e_1_3_2_1_62_1","volume-title":"Stefan Mangard, and Kay R\u00f6mer.","author":"Maurice Cl\u00e9mentine","year":"2017"},{"key":"e_1_3_2_1_63_1","volume-title":"Spectre is here to stay: An analysis of side-channels and speculative execution. arXiv:1902.05178","author":"Mcilroy Ross","year":"2019"},{"key":"e_1_3_2_1_64_1","volume-title":"Lmbench: Portable Tools for Performance Analysis. In USENIX ATC.","author":"McVoy Larry","year":"1996"},{"key":"e_1_3_2_1_65_1","volume-title":"Pascal Felber, and Emanuel Onica.","author":"Mogage Andrei","year":"2019"},{"key":"e_1_3_2_1_66_1","unstructured":"Mozilla. 2019 a. Index Masking in Firefox. https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=1430051  Mozilla. 2019 a. Index Masking in Firefox. https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=1430051"},{"key":"e_1_3_2_1_67_1","unstructured":"Mozilla. 2019 b. performance.now resolution. https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/API\/Performance\/now  Mozilla. 2019 b. performance.now resolution. https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/API\/Performance\/now"},{"key":"e_1_3_2_1_68_1","unstructured":"Net Applications.com. 2019. Desktop Operating System Market Share. http:\/\/www.netmarketshare.com\/operating-system-market-share.aspx  Net Applications.com. 2019. Desktop Operating System Market Share. http:\/\/www.netmarketshare.com\/operating-system-market-share.aspx"},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"crossref","unstructured":"Dag Arne Osvik Adi Shamir and Eran Tromer. 2006. Cache Attacks and Countermeasures: the Case of AES. In CT-RSA.  Dag Arne Osvik Adi Shamir and Eran Tromer. 2006. Cache Attacks and Countermeasures: the Case of AES. In CT-RSA.","DOI":"10.1007\/11605805_1"},{"key":"e_1_3_2_1_70_1","unstructured":"Matthew Panzarino. 2012. Apple releases OS X 10.8 Mountain Lion Developer Preview 2 lists known issues. https:\/\/thenextweb.com\/apple\/2012\/03\/16\/apple-releases-os-x-10--8-mountain-lion-developer-preview-2-to-mac-developers\/  Matthew Panzarino. 2012. Apple releases OS X 10.8 Mountain Lion Developer Preview 2 lists known issues. https:\/\/thenextweb.com\/apple\/2012\/03\/16\/apple-releases-os-x-10--8-mountain-lion-developer-preview-2-to-mac-developers\/"},{"key":"e_1_3_2_1_71_1","unstructured":"Colin Percival. 2005. Cache missing for fun and profit. In BSDCan.  Colin Percival. 2005. Cache missing for fun and profit. In BSDCan."},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"crossref","unstructured":"Marios Pomonis Theofilos Petsios Angelos D Keromytis Michalis Polychronakis and Vasileios P Kemerlis. 2017. kR^ X: Comprehensive Kernel Protection against Just-In-Time Code Reuse. In EuroSys.  Marios Pomonis Theofilos Petsios Angelos D Keromytis Michalis Polychronakis and Vasileios P Kemerlis. 2017. kR^ X: Comprehensive Kernel Protection against Just-In-Time Code Reuse. In EuroSys.","DOI":"10.1145\/3064176.3064216"},{"key":"e_1_3_2_1_73_1","unstructured":"Dan Rosenberg. 2010. kptr_restrict for hiding kernel pointers. https:\/\/lwn.net\/Articles\/420403\/  Dan Rosenberg. 2010. kptr_restrict for hiding kernel pointers. https:\/\/lwn.net\/Articles\/420403\/"},{"key":"e_1_3_2_1_74_1","unstructured":"Morten Schenk. 2019. Development of a new Windows 10 KASLR Bypass (in One WinDBG Command). https:\/\/www.offensive-security.com\/vulndev\/development-of-a-new-windows-10-kaslr-bypass-in-one-windbg-command\/  Morten Schenk. 2019. Development of a new Windows 10 KASLR Bypass (in One WinDBG Command). https:\/\/www.offensive-security.com\/vulndev\/development-of-a-new-windows-10-kaslr-bypass-in-one-windbg-command\/"},{"key":"e_1_3_2_1_75_1","doi-asserted-by":"crossref","unstructured":"Felix Schuster Thomas Tendyck Christopher Liebchen Lucas Davi Ahmad-Reza Sadeghi and Thorsten Holz. 2015. Counterfeit Object-oriented Programming: On the Difficulty of Preventing Code Reuse Attacks in C+Applications. In S&P.  Felix Schuster Thomas Tendyck Christopher Liebchen Lucas Davi Ahmad-Reza Sadeghi and Thorsten Holz. 2015. Counterfeit Object-oriented Programming: On the Difficulty of Preventing Code Reuse Attacks in C+Applications. In S&P.","DOI":"10.1109\/SP.2015.51"},{"key":"e_1_3_2_1_76_1","volume-title":"2019 a. Store-to-Leak Forwarding: Leaking Data on Meltdown-resistant CPUs. arXiv:1905.05725","author":"Schwarz Michael","year":"2019"},{"key":"e_1_3_2_1_77_1","doi-asserted-by":"crossref","unstructured":"Michael Schwarz Daniel Gruss Moritz Lipp Cl\u00e9mentine Maurice Thomas Schuster Anders Fogh and Stefan Mangard. 2018a. Automated Detection Exploitation and Elimination of Double-Fetch Bugs using Modern CPU Features. In AsiaCCS.  Michael Schwarz Daniel Gruss Moritz Lipp Cl\u00e9mentine Maurice Thomas Schuster Anders Fogh and Stefan Mangard. 2018a. Automated Detection Exploitation and Elimination of Double-Fetch Bugs using Modern CPU Features. In AsiaCCS.","DOI":"10.1145\/3196494.3196508"},{"key":"e_1_3_2_1_78_1","doi-asserted-by":"crossref","unstructured":"Michael Schwarz Moritz Lipp Daniel Gruss Samuel Weiser Cl\u00e9mentine Maurice Raphael Spreitzer and Stefan Mangard. 2018b. KeyDrown: Eliminating Software-Based Keystroke Timing Side-Channel Attacks. In NDSS.  Michael Schwarz Moritz Lipp Daniel Gruss Samuel Weiser Cl\u00e9mentine Maurice Raphael Spreitzer and Stefan Mangard. 2018b. KeyDrown: Eliminating Software-Based Keystroke Timing Side-Channel Attacks. In NDSS.","DOI":"10.14722\/ndss.2018.23027"},{"key":"e_1_3_2_1_79_1","unstructured":"Michael Schwarz Moritz Lipp Daniel Moghimi Jo Van Bulck Julian Stecklina Thomas Prescher and Daniel Gruss. 2019 b. ZombieLoad: Cross-Privilege-Boundary Data Sampling. In CCS.  Michael Schwarz Moritz Lipp Daniel Moghimi Jo Van Bulck Julian Stecklina Thomas Prescher and Daniel Gruss. 2019 b. ZombieLoad: Cross-Privilege-Boundary Data Sampling. In CCS."},{"key":"e_1_3_2_1_80_1","doi-asserted-by":"crossref","unstructured":"Michael Schwarz Cl\u00e9mentine Maurice Daniel Gruss and Stefan Mangard. 2017a. Fantastic Timers and Where to Find Them: High-Resolution Microarchitectural Attacks in JavaScript. In FC.  Michael Schwarz Cl\u00e9mentine Maurice Daniel Gruss and Stefan Mangard. 2017a. Fantastic Timers and Where to Find Them: High-Resolution Microarchitectural Attacks in JavaScript. In FC.","DOI":"10.1007\/978-3-319-70972-7_13"},{"key":"e_1_3_2_1_81_1","doi-asserted-by":"crossref","unstructured":"Michael Schwarz Samuel Weiser and Daniel Gruss. 2019 c. Practical Enclave Malware with Intel SGX. In DIMVA.  Michael Schwarz Samuel Weiser and Daniel Gruss. 2019 c. Practical Enclave Malware with Intel SGX. In DIMVA.","DOI":"10.1007\/978-3-030-22038-9_9"},{"key":"e_1_3_2_1_82_1","doi-asserted-by":"crossref","unstructured":"Michael Schwarz Samuel Weiser Daniel Gruss Cl\u00e9mentine Maurice and Stefan Mangard. 2017b. Malware Guard Extension: Using SGX to Conceal Cache Attacks. In DIMVA.  Michael Schwarz Samuel Weiser Daniel Gruss Cl\u00e9mentine Maurice and Stefan Mangard. 2017b. Malware Guard Extension: Using SGX to Conceal Cache Attacks. In DIMVA.","DOI":"10.1007\/978-3-319-60876-1_1"},{"key":"e_1_3_2_1_83_1","doi-asserted-by":"crossref","unstructured":"Hovav Shacham. 2007. The geometry of innocent flesh on the bone: Return-into-libc without function calls (on the x86). In CCS.  Hovav Shacham. 2007. The geometry of innocent flesh on the bone: Return-into-libc without function calls (on the x86). In CCS.","DOI":"10.1145\/1315245.1315313"},{"key":"e_1_3_2_1_84_1","volume-title":"KASLR: An Exercise in Cargo Cult Security. https:\/\/grsecurity.net\/kaslr_an_exercise_in_cargo_cult_security.php","author":"Spengler Brad","year":"2013"},{"key":"e_1_3_2_1_85_1","volume-title":"LazyFP: Leaking FPU Register State using Microarchitectural Side-Channels. arXiv:1806.07480","author":"Stecklina Julian","year":"2018"},{"key":"e_1_3_2_1_86_1","doi-asserted-by":"crossref","unstructured":"Laszlo Szekeres Mathias Payer Tao Wei and Dawn Song. 2013. SoK: Eternal War in Memory. In S&P.  Laszlo Szekeres Mathias Payer Tao Wei and Dawn Song. 2013. SoK: Eternal War in Memory. In S&P.","DOI":"10.1109\/SP.2013.13"},{"key":"e_1_3_2_1_87_1","volume-title":"USENIX Security Symposium.","author":"Bulck Jo Van","year":"2018"},{"key":"e_1_3_2_1_88_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00089"},{"key":"e_1_3_2_1_89_1","volume-title":"RIDL: Rogue In-flight Data Load. In S&P.","author":"van Schaik Stephan","year":"2019"},{"key":"e_1_3_2_1_90_1","doi-asserted-by":"crossref","unstructured":"Pepe Vila Boris K\u00f6pf and Jose Morales. 2019. Theory and Practice of Finding Eviction Sets. In S&P.  Pepe Vila Boris K\u00f6pf and Jose Morales. 2019. Theory and Practice of Finding Eviction Sets. In S&P.","DOI":"10.1109\/SP.2019.00042"},{"key":"e_1_3_2_1_91_1","unstructured":"WebAssembly. 2019. Features to add after the MVP. https:\/\/github.com\/WebAssembly\/design\/blob\/master\/FutureFeatures.md  WebAssembly. 2019. Features to add after the MVP. https:\/\/github.com\/WebAssembly\/design\/blob\/master\/FutureFeatures.md"},{"key":"e_1_3_2_1_92_1","doi-asserted-by":"crossref","unstructured":"Nico Weichbrodt Anil Kurmus Peter Pietzuch and R\u00fcdiger Kapitza. 2016. AsyncShock: Exploiting Synchronisation Bugs in Intel SGX Enclaves. In ESORICS.  Nico Weichbrodt Anil Kurmus Peter Pietzuch and R\u00fcdiger Kapitza. 2016. AsyncShock: Exploiting Synchronisation Bugs in Intel SGX Enclaves. In ESORICS.","DOI":"10.1007\/978-3-319-45744-4_22"},{"key":"e_1_3_2_1_93_1","volume-title":"Marina Minkin, Daniel Genkin, Baris Kasikci, Frank Piessens, Mark Silberstein, Raoul Strackx, Thomas F. Wenisch, and Yuval Yarom.","author":"Weisse Ofir","year":"2018"},{"key":"e_1_3_2_1_94_1","volume-title":"Whispers in the Hyper-space: High-bandwidth and Reliable Covert Channel Attacks inside the Cloud","author":"Wu Zhenyu","year":"2014"},{"key":"e_1_3_2_1_95_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046660.2046670"},{"key":"e_1_3_2_1_96_1","volume-title":"USENIX Security Symposium.","author":"Yarom Yuval","year":"2014"},{"key":"e_1_3_2_1_97_1","doi-asserted-by":"crossref","unstructured":"Yinqian Zhang Ari Juels Michael K. Reiter and Thomas Ristenpart. 2014. Cross-Tenant Side-Channel Attacks in PaaS Clouds. In CCS.  Yinqian Zhang Ari Juels Michael K. Reiter and Thomas Ristenpart. 2014. Cross-Tenant Side-Channel Attacks in PaaS Clouds. In CCS.","DOI":"10.1145\/2660267.2660356"},{"key":"e_1_3_2_1_98_1","unstructured":"Peter Zijlstra. 2019. Implement support for TSX Force Abort. https:\/\/lkml.org\/lkml\/2019\/3\/12\/1352  Peter Zijlstra. 2019. Implement support for TSX Force Abort. https:\/\/lkml.org\/lkml\/2019\/3\/12\/1352"}],"event":{"name":"ASIA CCS '20: The 15th ACM Asia Conference on Computer and Communications Security","location":"Taipei Taiwan","acronym":"ASIA CCS '20","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 15th ACM Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3320269.3384747","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3320269.3384747","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:41:27Z","timestamp":1750200087000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3320269.3384747"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,10,5]]},"references-count":98,"alternative-id":["10.1145\/3320269.3384747","10.1145\/3320269"],"URL":"https:\/\/doi.org\/10.1145\/3320269.3384747","relation":{},"subject":[],"published":{"date-parts":[[2020,10,5]]},"assertion":[{"value":"2020-10-05","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}