{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T15:42:54Z","timestamp":1785512574621,"version":"3.56.0"},"publisher-location":"New York, NY, USA","reference-count":99,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,10,30]],"date-time":"2020-10-30T00:00:00Z","timestamp":1604016000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100007297","name":"Office of Naval Research","doi-asserted-by":"publisher","award":["N00014-16-1-2261, N00014-17-1-2788"],"award-info":[{"award-number":["N00014-16-1-2261, N00014-17-1-2788"]}],"id":[{"id":"10.13039\/100007297","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,10,30]]},"DOI":"10.1145\/3372297.3417289","type":"proceedings-article","created":{"date-parts":[[2020,11,2]],"date-time":"2020-11-02T18:27:02Z","timestamp":1604341622000},"page":"1871-1885","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":40,"title":["Speculative Probing"],"prefix":"10.1145","author":[{"given":"Enes","family":"G\u00f6ktas","sequence":"first","affiliation":[{"name":"Stevens Institute of Technology, Hoboken, NJ, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kaveh","family":"Razavi","sequence":"additional","affiliation":[{"name":"ETH Zurich, Zurich, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Georgios","family":"Portokalidis","sequence":"additional","affiliation":[{"name":"Stevens Institute of Technology, Hoboken, NJ, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Herbert","family":"Bos","sequence":"additional","affiliation":[{"name":"Vrije Universiteit Amsterdam, Amsterdam, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Cristiano","family":"Giuffrida","sequence":"additional","affiliation":[{"name":"Vrije Universiteit Amsterdam, Amsterdam, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2020,11,2]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"crossref","unstructured":"Mart'in Abadi Mihai Budiu \u00dalfar Erlingsson and Jay Ligatti. 2005. Control-flow integrity. In CCS .  Mart'in Abadi Mihai Budiu \u00dalfar Erlingsson and Jay Ligatti. 2005. Control-flow integrity. In CCS .","DOI":"10.1145\/1102120.1102165"},{"key":"e_1_3_2_1_2_1","unstructured":"Kristen Carlson Accardi. 2020. Function Granular KASLR. https:\/\/lwn.net\/Articles\/826539\/  Kristen Carlson Accardi. 2020. Function Granular KASLR. https:\/\/lwn.net\/Articles\/826539\/"},{"key":"e_1_3_2_1_3_1","volume-title":"Sohaib ul Hassan, Cesar Pereida Garc'ia, and Nicola Tuveri.","author":"Aldaya Alejandro Cabrera","year":"2019"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"crossref","unstructured":"Michael Backes Thorsten Holz Benjamin Kollenda Philipp Koppe Stefan N\u00fcrnberger and Jannik Pewny. 2014. You can run but you can't read: Preventing disclosure exploits in executable code. In CCS .  Michael Backes Thorsten Holz Benjamin Kollenda Philipp Koppe Stefan N\u00fcrnberger and Jannik Pewny. 2014. You can run but you can't read: Preventing disclosure exploits in executable code. In CCS .","DOI":"10.1145\/2660267.2660378"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"crossref","unstructured":"Koustubha Bhat Erik van der Kouwe Herbert Bos and Cristiano Giuffrida. 2019. ProbeGuard: Mitigating Probing Attacks Through Reactive Program Transformations. In ASPLOS.  Koustubha Bhat Erik van der Kouwe Herbert Bos and Cristiano Giuffrida. 2019. ProbeGuard: Mitigating Probing Attacks Through Reactive Program Transformations. In ASPLOS.","DOI":"10.1145\/3297858.3304073"},{"key":"e_1_3_2_1_6_1","unstructured":"Atri Bhattacharyya Andr\u00e9s S\u00e1nchez Esmaeil M Koruyeh Nael Abu-Ghazaleh Chengyu Song and Mathias Payer. 2020. SpecROP: Speculative Exploitation of ROP Chains. (2020).  Atri Bhattacharyya Andr\u00e9s S\u00e1nchez Esmaeil M Koruyeh Nael Abu-Ghazaleh Chengyu Song and Mathias Payer. 2020. SpecROP: Speculative Exploitation of ROP Chains. (2020)."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"crossref","unstructured":"David Bigelow Thomas Hobson Robert Rudd William Streilein and Hamed Okhravi. 2015. Timely rerandomization for mitigating memory disclosures. In CCS .  David Bigelow Thomas Hobson Robert Rudd William Streilein and Hamed Okhravi. 2015. Timely rerandomization for mitigating memory disclosures. In CCS .","DOI":"10.1145\/2810103.2813691"},{"key":"e_1_3_2_1_8_1","volume-title":"Hacking blind","author":"Bittau Andrea"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/1966913.1966919"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"crossref","unstructured":"Erik Bosman Kaveh Razavi Herbert Bos and Cristiano Giuffrida. 2016. Dedup Est Machina: Memory Deduplication as an Advanced Exploitation Vector. In S&P.  Erik Bosman Kaveh Razavi Herbert Bos and Cristiano Giuffrida. 2016. Dedup Est Machina: Memory Deduplication as an Advanced Exploitation Vector. In S&P.","DOI":"10.1109\/SP.2016.63"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"crossref","unstructured":"Kjell Braden Lucas Davi Christopher Liebchen Ahmad-Reza Sadeghi Stephen Crane Michael Franz and Per Larsen. 2016. Leakage-Resilient Layout Randomization for Mobile Devices. In NDSS .  Kjell Braden Lucas Davi Christopher Liebchen Ahmad-Reza Sadeghi Stephen Crane Michael Franz and Per Larsen. 2016. Leakage-Resilient Layout Randomization for Mobile Devices. In NDSS .","DOI":"10.14722\/ndss.2016.23364"},{"key":"e_1_3_2_1_12_1","unstructured":"Scott Brookes Robert Denz Martin Osterloh and Stephen Taylor. 2016. ExOShim: Preventing Memory Disclosure Using Execute-Only Kernel Code. In ICCWS .  Scott Brookes Robert Denz Martin Osterloh and Stephen Taylor. 2016. ExOShim: Preventing Memory Disclosure Using Execute-Only Kernel Code. In ICCWS ."},{"key":"e_1_3_2_1_13_1","volume-title":"Michael Schwarz, Moritz Lipp, Benjamin von","author":"Canella Claudio","year":"2019"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"crossref","unstructured":"Claudio Canella Daniel Genkin Lukas Giner Daniel Gruss Moritz Lipp Marina Minkin Daniel Moghimi Frank Piessens Michael Schwarz Berk Sunar et almbox. 2019 b. Fallout: Leaking data on meltdown-resistant cpus. In CCS .  Claudio Canella Daniel Genkin Lukas Giner Daniel Gruss Moritz Lipp Marina Minkin Daniel Moghimi Frank Piessens Michael Schwarz Berk Sunar et almbox. 2019 b. Fallout: Leaking data on meltdown-resistant cpus. In CCS .","DOI":"10.1145\/3319535.3363219"},{"key":"e_1_3_2_1_15_1","volume-title":"KASLR: Break It, Fix It, Repeat. In ASIACCS .","author":"Canella Claudio","year":"2016"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"crossref","unstructured":"Xi Chen Herbert Bos and Cristiano Giuffrida. 2017a. CodeArmor: Virtualizing the Code Space to Counter Disclosure Attacks. In EuroS&P.  Xi Chen Herbert Bos and Cristiano Giuffrida. 2017a. CodeArmor: Virtualizing the Code Space to Counter Disclosure Attacks. In EuroS&P.","DOI":"10.1109\/EuroSP.2017.17"},{"key":"e_1_3_2_1_17_1","volume-title":"NORAX: Enabling execute-only memory for COTS binaries on AArch64","author":"Chen Yaohui","year":"2017"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"crossref","unstructured":"Lucian Cojocar Kaveh Razavi Cristiano Giuffrida and Herbert Bos. 2019. Exploiting Correcting Codes: On the Effectiveness of ECC Memory Against Rowhammer Attacks. In S&P.  Lucian Cojocar Kaveh Razavi Cristiano Giuffrida and Herbert Bos. 2019. Exploiting Correcting Codes: On the Effectiveness of ECC Memory Against Rowhammer Attacks. In S&P.","DOI":"10.1109\/SP.2019.00089"},{"key":"e_1_3_2_1_19_1","unstructured":"Jonathan Corbet. 2018. Meltdown and Spectre mitigations: a February update. https:\/\/lwn.net\/Articles\/746551\/  Jonathan Corbet. 2018. Meltdown and Spectre mitigations: a February update. https:\/\/lwn.net\/Articles\/746551\/"},{"key":"e_1_3_2_1_20_1","volume-title":"Readactor: Practical code randomization resilient to memory disclosure","author":"Crane Stephen","year":"2015"},{"key":"e_1_3_2_1_21_1","volume-title":"Bjorn De Sutter, and Michael Franz","author":"Crane Stephen J","year":"2015"},{"key":"e_1_3_2_1_22_1","unstructured":"Craig Disselkoen David Kohlbrenner Leo Porter and Dean Tullsen. 2017. Prime  Craig Disselkoen David Kohlbrenner Leo Porter and Dean Tullsen. 2017. Prime"},{"key":"e_1_3_2_1_23_1","unstructured":"Abort: A Timer-Free High-Precision L3 Cache Attack using Intel TSX. In USENIX Security .  Abort: A Timer-Free High-Precision L3 Cache Attack using Intel TSX. In USENIX Security ."},{"key":"e_1_3_2_1_24_1","volume-title":"Missing the point(er): On the effectiveness of code pointer integrity","author":"Evans Isaac"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"crossref","unstructured":"Dmitry Evtyushkin Dmitry Ponomarev and Nael Abu-Ghazaleh. 2016. Jump over ASLR: Attacking branch predictors to bypass ASLR. In MICRO .  Dmitry Evtyushkin Dmitry Ponomarev and Nael Abu-Ghazaleh. 2016. Jump over ASLR: Attacking branch predictors to bypass ASLR. In MICRO .","DOI":"10.1109\/MICRO.2016.7783743"},{"key":"e_1_3_2_1_26_1","unstructured":"Dmitry Evtyushkin Ryan Riley Nael CSE Abu-Ghazaleh ECE and Dmitry Ponomarev. [n.d.]. BranchScope: A New Side-Channel Attack on Directional Branch Predictor. In ASPLOS'18 .  Dmitry Evtyushkin Ryan Riley Nael CSE Abu-Ghazaleh ECE and Dmitry Ponomarev. [n.d.]. BranchScope: A New Side-Channel Attack on Directional Branch Predictor. In ASPLOS'18 ."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"crossref","unstructured":"Pietro Frigo Cristiano Giuffrida Herbert Bos and Kaveh Razavi. 2018. Grand Pwning Unit: Accelerating Microarchitectural Attacks with the GPU. In S&P.  Pietro Frigo Cristiano Giuffrida Herbert Bos and Kaveh Razavi. 2018. Grand Pwning Unit: Accelerating Microarchitectural Attacks with the GPU. In S&P.","DOI":"10.1109\/SP.2018.00022"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"crossref","unstructured":"Pietro Frigo Emanuele Vannacci Hasan Hassan Victor van der Veen Onur Mutlu Cristiano Giuffrida Herbert Bos and Kaveh Razavi. 2020. TRRespass: Exploiting the Many Sides of Target Row Refresh. In S&P.  Pietro Frigo Emanuele Vannacci Hasan Hassan Victor van der Veen Onur Mutlu Cristiano Giuffrida Herbert Bos and Kaveh Razavi. 2020. TRRespass: Exploiting the Many Sides of Target Row Refresh. In S&P.","DOI":"10.1109\/SP40000.2020.00090"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"crossref","unstructured":"Robert Gawlik Benjamin Kollenda Philipp Koppe Behrad Garmany and Thorsten Holz. 2016. Enabling Client-Side Crash-Resistance to Overcome Diversification and Information Hiding. In NDSS .  Robert Gawlik Benjamin Kollenda Philipp Koppe Behrad Garmany and Thorsten Holz. 2016. Enabling Client-Side Crash-Resistance to Overcome Diversification and Information Hiding. In NDSS .","DOI":"10.14722\/ndss.2016.23262"},{"key":"e_1_3_2_1_30_1","unstructured":"C. Ge L. Xu W. Qiu Z. Huang J. Guo G. Liu and Z. Gong. [n.d.]. Optimized Password Recovery for SHA-512 on GPUs . In CSE'17 .  C. Ge L. Xu W. Qiu Z. Huang J. Guo G. Liu and Z. Gong. [n.d.]. Optimized Password Recovery for SHA-512 on GPUs . In CSE'17 ."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"crossref","unstructured":"Jason Gionta William Enck and Per Larsen. 2016. Preventing kernel code-reuse attacks through disclosure resistant code diversification. In CNS .  Jason Gionta William Enck and Per Larsen. 2016. Preventing kernel code-reuse attacks through disclosure resistant code diversification. In CNS .","DOI":"10.1109\/CNS.2016.7860485"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"crossref","unstructured":"Jason Gionta William Enck and Peng Ning. 2015. HideM: Protecting the contents of userspace memory in the face of disclosure vulnerabilities. In CODASPY .  Jason Gionta William Enck and Peng Ning. 2015. HideM: Protecting the contents of userspace memory in the face of disclosure vulnerabilities. In CODASPY .","DOI":"10.1145\/2699026.2699107"},{"key":"e_1_3_2_1_33_1","volume-title":"Tanenbaum","author":"Giuffrida Cristiano","year":"2012"},{"key":"e_1_3_2_1_34_1","unstructured":"Enes Goktas Robert Gawlik Benjamin Kollenda Elias Athanasopoulos Georgios Portokalidis Cristiano Giuffrida and Herbert Bos. 2016. Undermining Information Hiding (And What to do About it). In USENIX Security.  Enes Goktas Robert Gawlik Benjamin Kollenda Elias Athanasopoulos Georgios Portokalidis Cristiano Giuffrida and Herbert Bos. 2016. Undermining Information Hiding (And What to do About it). In USENIX Security."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"crossref","unstructured":"Enes Goktas Benjamin Kollenda Philipp Koppe Erik Bosman Georgios Portokalidis Thorsten Holz Herbert Bos and Cristiano Giuffrida. 2018. Position-independent Code Reuse: On the Effectiveness of ASLR in the Absence of Information Disclosure. In EuroS&P.  Enes Goktas Benjamin Kollenda Philipp Koppe Erik Bosman Georgios Portokalidis Thorsten Holz Herbert Bos and Cristiano Giuffrida. 2018. Position-independent Code Reuse: On the Effectiveness of ASLR in the Absence of Information Disclosure. In EuroS&P.","DOI":"10.1109\/EuroSP.2018.00024"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"crossref","unstructured":"Ben Gras Cristiano Giuffrida Michael Kurth Herbert Bos and Kaveh Razavi. 2020. ABSynthe: Automatic Blackbox Side-channel Synthesis on Commodity Microarchitectures. In NDSS.  Ben Gras Cristiano Giuffrida Michael Kurth Herbert Bos and Kaveh Razavi. 2020. ABSynthe: Automatic Blackbox Side-channel Synthesis on Commodity Microarchitectures. In NDSS.","DOI":"10.14722\/ndss.2020.23018"},{"key":"e_1_3_2_1_37_1","unstructured":"Ben Gras Kaveh Razavi Herbert Bos and Cristiano Giuffrida. 2018. Translation Leak-aside Buffer: Defeating Cache Side-channel Protections with TLB Attacks. In USENIX Security.  Ben Gras Kaveh Razavi Herbert Bos and Cristiano Giuffrida. 2018. Translation Leak-aside Buffer: Defeating Cache Side-channel Protections with TLB Attacks. In USENIX Security."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"crossref","unstructured":"Ben Gras Kaveh Razavi Erik Bosman Herbert Bos and Cristiano Giuffrida. 2017. ASLR on the Line: Practical Cache Attacks on the MMU. In NDSS.  Ben Gras Kaveh Razavi Erik Bosman Herbert Bos and Cristiano Giuffrida. 2017. ASLR on the Line: Practical Cache Attacks on the MMU. In NDSS.","DOI":"10.14722\/ndss.2017.23271"},{"key":"e_1_3_2_1_39_1","volume-title":"IskiOS: Lightweight defense against kernel-level code-reuse attacks. arXiv preprint arXiv:1903.04654","author":"Gravani Spyridoula","year":"2019"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"crossref","unstructured":"Daniel Gruss Cl\u00e9mentine Maurice Anders Fogh Moritz Lipp and Stefan Mangard. 2016b. Prefetch side-channel attacks: Bypassing SMAP and kernel ASLR. In CCS .  Daniel Gruss Cl\u00e9mentine Maurice Anders Fogh Moritz Lipp and Stefan Mangard. 2016b. Prefetch side-channel attacks: Bypassing SMAP and kernel ASLR. In CCS .","DOI":"10.1145\/2976749.2978356"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"crossref","unstructured":"Daniel Gruss Cl\u00e9mentine Maurice and Stefan Mangard. 2016a. Rowhammer.js: A remote software-induced fault attack in Javascript. In DIMVA .  Daniel Gruss Cl\u00e9mentine Maurice and Stefan Mangard. 2016a. Rowhammer.js: A remote software-induced fault attack in Javascript. In DIMVA .","DOI":"10.1007\/978-3-319-40667-1_15"},{"key":"e_1_3_2_1_42_1","volume-title":"Spectre Attacks: Exploiting Speculative Execution. https:\/\/googleprojectzero.blogspot.com\/2018\/01\/reading-privileged-memory-with-side.html","author":"Horn Jann","year":"2018"},{"key":"e_1_3_2_1_43_1","volume-title":"Prateek Saxena, and Zhenkai Liang.","author":"Hu Hong","year":"2016"},{"key":"e_1_3_2_1_44_1","volume-title":"Practical timing side channel attacks against kernel space ASLR","author":"Hund Ralf"},{"key":"e_1_3_2_1_45_1","unstructured":"Intel. 2018. Speculative Execution Side Channel Mitigations. https:\/\/software.intel.com\/security-software-guidance\/api-app\/sites\/default\/files\/336996-Speculative-Execution-Side-Channel-Mitigations.pdf  Intel. 2018. Speculative Execution Side Channel Mitigations. https:\/\/software.intel.com\/security-software-guidance\/api-app\/sites\/default\/files\/336996-Speculative-Execution-Side-Channel-Mitigations.pdf"},{"key":"e_1_3_2_1_46_1","unstructured":"Saad Islam Ahmad Moghimi Ida Bruhns Moritz Krebbel Berk Gulmezoglu Thomas Eisenbarth and Berk Sunar. 2019. $$SPOILER$$: Speculative Load Hazards Boost Rowhammer and Cache Attacks. In USENIX Security .  Saad Islam Ahmad Moghimi Ida Bruhns Moritz Krebbel Berk Gulmezoglu Thomas Eisenbarth and Berk Sunar. 2019. $$SPOILER$$: Speculative Load Hazards Boost Rowhammer and Cache Attacks. In USENIX Security ."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"crossref","unstructured":"Yeongjin Jang Sangho Lee and Taesoo Kim. 2016. Breaking kernel address space layout randomization with Intel TSX. In CCS .  Yeongjin Jang Sangho Lee and Taesoo Kim. 2016. Breaking kernel address space layout randomization with Intel TSX. In CCS .","DOI":"10.1145\/2976749.2978321"},{"key":"e_1_3_2_1_48_1","unstructured":"Vasileios P Kemerlis Michalis Polychronakis and Angelos D Keromytis. 2014. ret2dir: Rethinking kernel isolation. In USENIX Security .  Vasileios P Kemerlis Michalis Polychronakis and Angelos D Keromytis. 2014. ret2dir: Rethinking kernel isolation. In USENIX Security ."},{"key":"e_1_3_2_1_49_1","unstructured":"Vasileios P Kemerlis Georgios Portokalidis and Angelos D Keromytis. 2012. kGuard: lightweight kernel protection against return-to-user attacks. In USENIX Security .  Vasileios P Kemerlis Georgios Portokalidis and Angelos D Keromytis. 2012. kGuard: lightweight kernel protection against return-to-user attacks. In USENIX Security ."},{"key":"e_1_3_2_1_50_1","unstructured":"Khaled N. Khasawneh Esmaeil Mohammadian Koruyeh Chengyu Song Dmitry Evtyushkin Dmitry Ponomarev and Nael Abu-Ghazaleh. [n.d.]. SafeSpec: Banishing the Spectre of a Meltdown with Leakage-Free Speculation (DAC'19).  Khaled N. Khasawneh Esmaeil Mohammadian Koruyeh Chengyu Song Dmitry Evtyushkin Dmitry Ponomarev and Nael Abu-Ghazaleh. [n.d.]. SafeSpec: Banishing the Spectre of a Meltdown with Leakage-Free Speculation (DAC'19)."},{"key":"e_1_3_2_1_51_1","volume-title":"Speculative buffer overflows: Attacks and defenses. arXiv preprint arXiv:1807.03757","author":"Kiriansky Vladimir","year":"2018"},{"key":"e_1_3_2_1_52_1","volume-title":"Spectre Attacks: Exploiting Speculative Execution","author":"Kocher Paul","year":"2019"},{"key":"e_1_3_2_1_53_1","volume-title":"Cristiano Giuffrida, Herbert Bos, and Thorsten Holz.","author":"Kollenda Benjamin","year":"2017"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"crossref","unstructured":"Koen Koning Xi Chen Herbert Bos Cristiano Giuffrida and Elias Athanasopoulos. 2017. No Need to Hide: Protecting Safe Regions on Commodity Hardware. In EuroSys.  Koen Koning Xi Chen Herbert Bos Cristiano Giuffrida and Elias Athanasopoulos. 2017. No Need to Hide: Protecting Safe Regions on Commodity Hardware. In EuroSys.","DOI":"10.1145\/3064176.3064217"},{"key":"e_1_3_2_1_55_1","unstructured":"Andrey Konovalov. 2017. Exploiting the Linux kernel via packet sockets. https:\/\/googleprojectzero.blogspot.com\/2017\/05\/exploiting-linux-kernel-via-packet.html  Andrey Konovalov. 2017. Exploiting the Linux kernel via packet sockets. https:\/\/googleprojectzero.blogspot.com\/2017\/05\/exploiting-linux-kernel-via-packet.html"},{"key":"e_1_3_2_1_56_1","volume-title":"Compiler-assisted code randomization","author":"Koo Hyungjoon"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"crossref","unstructured":"Jakob Koschel Cristiano Giuffrida Herbert Bos and Kaveh Razavi. 2020. TagBleed: Breaking KASLR on the Isolated Kernel Address Space Using Tagged TLB. In EuroS&P.  Jakob Koschel Cristiano Giuffrida Herbert Bos and Kaveh Razavi. 2020. TagBleed: Breaking KASLR on the Isolated Kernel Address Space Using Tagged TLB. In EuroS&P.","DOI":"10.1109\/EuroSP48549.2020.00027"},{"key":"e_1_3_2_1_58_1","unstructured":"Donghyun Kwon Jangseop Shin Giyeol Kim Byoungyoung Lee Yeongpil Cho and Yunheung Paek. 2019. uXOM: Efficient eXecute-Only Memory on $$ARM$$ Cortex-M. In USENIX Security .  Donghyun Kwon Jangseop Shin Giyeol Kim Byoungyoung Lee Yeongpil Cho and Yunheung Paek. 2019. uXOM: Efficient eXecute-Only Memory on $$ARM$$ Cortex-M. In USENIX Security ."},{"key":"e_1_3_2_1_59_1","volume-title":"Michael Schwarz, Arthur Perais, Cl\u00e9mentine Maurice, and Daniel Gruss.","author":"Lipp Moritz","year":"2019"},{"key":"e_1_3_2_1_60_1","volume-title":"Meltdown: Reading Kernel Memory from User Space. In USENIX Security .","author":"Lipp Moritz","year":"2018"},{"key":"e_1_3_2_1_61_1","unstructured":"Hongjiu Lu Michael Matz Milind Girkar Jan Hubiaka Andreas Jaeger and Mark Mitchell. 2018. System V Application Binary Interface AMD64 Architecture Processor Supplement (With LP64 and ILP32 Programming Models) Version 1.0 . https:\/\/github.com\/hjl-tools\/x86-psABI\/wiki\/x86--64-psABI-1.0.pdf  Hongjiu Lu Michael Matz Milind Girkar Jan Hubiaka Andreas Jaeger and Mark Mitchell. 2018. System V Application Binary Interface AMD64 Architecture Processor Supplement (With LP64 and ILP32 Programming Models) Version 1.0 . https:\/\/github.com\/hjl-tools\/x86-psABI\/wiki\/x86--64-psABI-1.0.pdf"},{"key":"e_1_3_2_1_62_1","unstructured":"Kangjie Lu Wenke Lee Stefan N\u00fcrnberger and Michael Backes. 2016. How to Make ASLR Win the Clone Wars: Runtime Re-Randomization. In NDSS .  Kangjie Lu Wenke Lee Stefan N\u00fcrnberger and Michael Backes. 2016. How to Make ASLR Win the Clone Wars: Runtime Re-Randomization. In NDSS ."},{"key":"e_1_3_2_1_63_1","unstructured":"Giorgi Maisuradze Michael Backes and Christian Rossow. 2016. What cannot be read cannot be leveraged? revisiting assumptions of JIT-ROP defenses. In USENIX Security .  Giorgi Maisuradze Michael Backes and Christian Rossow. 2016. What cannot be read cannot be leveraged? revisiting assumptions of JIT-ROP defenses. In USENIX Security ."},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243761"},{"key":"e_1_3_2_1_65_1","volume-title":"Speculose: Analyzing the security implications of speculative execution in CPUs. arXiv preprint arXiv:1801.04084","author":"Maisuradze Giorgi","year":"2018"},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"crossref","unstructured":"Ahmad Moghimi Thomas Eisenbarth and Berk Sunar. 2018. MemJam: A False Dependency Attack Against Constant-Time Crypto Implementations in SGX. In CT-RSA .  Ahmad Moghimi Thomas Eisenbarth and Berk Sunar. 2018. MemJam: A False Dependency Attack Against Constant-Time Crypto Implementations in SGX. In CT-RSA .","DOI":"10.1007\/978-3-319-76953-0_2"},{"key":"e_1_3_2_1_67_1","unstructured":"Angelos Oikonomopoulos Elias Athanasopoulos Herbert Bos and Cristiano Giuffrida. 2016. Poking Holes in Information Hiding. In USENIX Security.  Angelos Oikonomopoulos Elias Athanasopoulos Herbert Bos and Cristiano Giuffrida. 2016. Poking Holes in Information Hiding. In USENIX Security."},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"crossref","unstructured":"Dag Arne Osvik Adi Shamir and Eran Tromer. 2006. Cache Attacks and Countermeasures: The Case of AES. In CT-RSA .  Dag Arne Osvik Adi Shamir and Eran Tromer. 2006. Cache Attacks and Countermeasures: The Case of AES. In CT-RSA .","DOI":"10.1007\/11605805_1"},{"key":"e_1_3_2_1_69_1","unstructured":"Soyeon Park Sangho Lee Wen Xu Hyungon Moon and Taesoo Kim. 2019. libmpk: Software Abstraction for Intel Memory Protection Keys (Intel $$MPK$$). In USENIX ATC .  Soyeon Park Sangho Lee Wen Xu Hyungon Moon and Taesoo Kim. 2019. libmpk: Software Abstraction for Intel Memory Protection Keys (Intel $$MPK$$). In USENIX ATC ."},{"key":"e_1_3_2_1_70_1","doi-asserted-by":"crossref","unstructured":"Marios Pomonis Theofilos Petsios Angelos D Keromytis Michalis Polychronakis and Vasileios P Kemerlis. 2017. kR^ X: Comprehensive kernel protection against just-in-time code reuse. In EuroSys .  Marios Pomonis Theofilos Petsios Angelos D Keromytis Michalis Polychronakis and Vasileios P Kemerlis. 2017. kR^ X: Comprehensive kernel protection against just-in-time code reuse. In EuroSys .","DOI":"10.1145\/3064176.3064216"},{"key":"e_1_3_2_1_71_1","unstructured":"Kaveh Razavi Ben Gras Erik Bosman Bart Preneel Cristiano Giuffrida and Herbert Bos. 2016. Flip Feng Shui: Hammering a Needle in the Software Stack. In USENIX Security.  Kaveh Razavi Ben Gras Erik Bosman Bart Preneel Cristiano Giuffrida and Herbert Bos. 2016. Flip Feng Shui: Hammering a Needle in the Software Stack. In USENIX Security."},{"key":"e_1_3_2_1_72_1","volume-title":"et almbox","author":"Rudd Robert","year":"2017"},{"key":"e_1_3_2_1_73_1","doi-asserted-by":"crossref","unstructured":"Felix Schuster Thomas Tendyck Christopher Liebchen Lucas Davi Ahmad-Reza Sadeghi and Thorsten Holz. 2015. Counterfeit Object-oriented Programming: On the Difficulty of Preventing Code Reuse Attacks in C  Felix Schuster Thomas Tendyck Christopher Liebchen Lucas Davi Ahmad-Reza Sadeghi and Thorsten Holz. 2015. Counterfeit Object-oriented Programming: On the Difficulty of Preventing Code Reuse Attacks in C","DOI":"10.1109\/SP.2015.51"},{"key":"e_1_3_2_1_74_1","unstructured":"Applications. In IEEE S&P .  Applications. In IEEE S&P ."},{"key":"e_1_3_2_1_75_1","volume-title":"Julian Stecklina, Thomas Prescher, and Daniel Gruss.","author":"Schwarz Michael","year":"2019"},{"key":"e_1_3_2_1_76_1","volume-title":"Exploiting the DRAM rowhammer bug to gain kernel privileges. Black Hat","author":"Seaborn Mark","year":"2015"},{"key":"e_1_3_2_1_77_1","unstructured":"Fermin J Serna. 201"},{"key":"e_1_3_2_1_78_1","doi-asserted-by":"crossref","unstructured":"Hovav Shacham. 2007. The Geometry of Innocent Flesh on the Bone: Return-into-libc Without Function Calls (on the x86). In CCS .  Hovav Shacham. 2007. The Geometry of Innocent Flesh on the Bone: Return-into-libc Without Function Calls (on the x86). In CCS .","DOI":"10.1145\/1315245.1315313"},{"key":"e_1_3_2_1_79_1","doi-asserted-by":"crossref","unstructured":"Hovav Shacham Matthew Page Ben Pfaff Eu-Jin Goh Nagendra Modadugu and Dan Boneh. 2004. On the effectiveness of address-space randomization. In CCS .  Hovav Shacham Matthew Page Ben Pfaff Eu-Jin Goh Nagendra Modadugu and Dan Boneh. 2004. On the effectiveness of address-space randomization. In CCS .","DOI":"10.1145\/1030083.1030124"},{"key":"e_1_3_2_1_80_1","volume-title":"Just-in-time code reuse: On the effectiveness of fine-grained address space layout randomization","author":"Snow Kevin Z"},{"key":"e_1_3_2_1_81_1","volume-title":"Return to the zombie gadgets: Undermining destructive code reads via code inference attacks","author":"Snow Kevin Z"},{"key":"e_1_3_2_1_82_1","unstructured":"Wei Song and Peng Liu. 2019. Dynamically Finding Minimal Eviction Sets Can Be Quicker Than You Think for Side-Channel Attacks against the LLC. In RAID .  Wei Song and Peng Liu. 2019. Dynamically Finding Minimal Eviction Sets Can Be Quicker Than You Think for Side-Channel Attacks against the LLC. In RAID ."},{"key":"e_1_3_2_1_83_1","doi-asserted-by":"crossref","unstructured":"Dean Sullivan Orlando Arias Travis Meade and Yier Jin. 2018. Microarchitectural Minefields: 4K-Aliasing Covert Channel and Multi-Tenant Detection in IaaS Clouds. In CCS .  Dean Sullivan Orlando Arias Travis Meade and Yier Jin. 2018. Microarchitectural Minefields: 4K-Aliasing Covert Channel and Multi-Tenant Detection in IaaS Clouds. In CCS .","DOI":"10.14722\/ndss.2018.23221"},{"key":"e_1_3_2_1_84_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813685"},{"key":"e_1_3_2_1_85_1","doi-asserted-by":"crossref","unstructured":"Andrei Tatar Cristiano Giuffrida Herbert Bos and Kaveh Razavi. 2018a. Defeating Software Mitigations against Rowhammer: A Surgical Precision Hammer. In RAID.  Andrei Tatar Cristiano Giuffrida Herbert Bos and Kaveh Razavi. 2018a. Defeating Software Mitigations against Rowhammer: A Surgical Precision Hammer. In RAID.","DOI":"10.1007\/978-3-030-00470-5_3"},{"key":"e_1_3_2_1_86_1","volume-title":"Elias Athanasopoulos, Cristiano Giuffrida, Herbert Bos, and Kaveh Razavi.","author":"Tatar Andrei","year":"2018"},{"key":"e_1_3_2_1_87_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-23644-0_7"},{"key":"e_1_3_2_1_88_1","unstructured":"Paul Turner. 2018. Retpoline: a software construct for preventing branch-target-injection. https:\/\/support.google.com\/faqs\/answer\/7625886  Paul Turner. 2018. Retpoline: a software construct for preventing branch-target-injection. https:\/\/support.google.com\/faqs\/answer\/7625886"},{"key":"e_1_3_2_1_89_1","unstructured":"Jo Van Bulck Marina Minkin Ofir Weisse Daniel Genkin Baris Kasikci Frank Piessens Mark Silberstein Thomas F. Wenisch Yuval Yarom and Raoul Strackx. [n.d.]. Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order Execution. In SEC'18 .  Jo Van Bulck Marina Minkin Ofir Weisse Daniel Genkin Baris Kasikci Frank Piessens Mark Silberstein Thomas F. Wenisch Yuval Yarom and Raoul Strackx. [n.d.]. Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order Execution. In SEC'18 ."},{"key":"e_1_3_2_1_90_1","volume-title":"LVI: Hijacking Transient Execution through Microarchitectural Load Value Injection. In S&P'20 .","author":"Bulck Jo Van","year":"2020"},{"key":"e_1_3_2_1_91_1","doi-asserted-by":"crossref","unstructured":"Victor van der Veen Dennis Andriesse Manolis Stamatogiannakis Xi Chen Herbert Bos and Cristiano Giuffrida. 2017. The Dynamics of Innocent Flesh on the Bone: Code Reuse Ten Years Later. In CCS.  Victor van der Veen Dennis Andriesse Manolis Stamatogiannakis Xi Chen Herbert Bos and Cristiano Giuffrida. 2017. The Dynamics of Innocent Flesh on the Bone: Code Reuse Ten Years Later. In CCS.","DOI":"10.1145\/3133956.3134026"},{"key":"e_1_3_2_1_92_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978406"},{"key":"e_1_3_2_1_93_1","unstructured":"Stephan van Schaik Cristiano Giuffrida Herbert Bos and Kaveh Razavi. 2018. Malicious Management Unit: Why Stopping Cache Attacks in Software is Harder Than You Think. In USENIX Security.  Stephan van Schaik Cristiano Giuffrida Herbert Bos and Kaveh Razavi. 2018. Malicious Management Unit: Why Stopping Cache Attacks in Software is Harder Than You Think. In USENIX Security."},{"key":"e_1_3_2_1_94_1","volume-title":"RIDL: Rogue In-flight Data Load. In S&P.","author":"van Schaik Stephan","year":"2019"},{"key":"e_1_3_2_1_95_1","volume-title":"Boris K\u00f6 pf, and Jos\u00e9 Francisco Morales","author":"Vila Pepe","year":"2019"},{"key":"e_1_3_2_1_96_1","doi-asserted-by":"publisher","DOI":"10.1145\/2897845.2897891"},{"key":"e_1_3_2_1_97_1","volume-title":"Shuffler: Fast and deployable continuous code re-randomization. In OSDI .","author":"Williams-King David","year":"2016"},{"key":"e_1_3_2_1_98_1","unstructured":"Yuval Yarom and Katrina Falkner. 2014. FLUSH  Yuval Yarom and Katrina Falkner. 2014. FLUSH"},{"key":"e_1_3_2_1_99_1","unstructured":"RELOAD\n  : A High Resolution Low Noise L3 Cache Side-Channel Attack. In USENIX Security .  RELOAD: A High Resolution Low Noise L3 Cache Side-Channel Attack. In USENIX Security ."}],"event":{"name":"CCS '20: 2020 ACM SIGSAC Conference on Computer and Communications Security","location":"Virtual Event USA","acronym":"CCS '20","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3372297.3417289","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3372297.3417289","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3372297.3417289","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:01:31Z","timestamp":1750197691000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3372297.3417289"}},"subtitle":["Hacking Blind in the Spectre Era"],"short-title":[],"issued":{"date-parts":[[2020,10,30]]},"references-count":99,"alternative-id":["10.1145\/3372297.3417289","10.1145\/3372297"],"URL":"https:\/\/doi.org\/10.1145\/3372297.3417289","relation":{},"subject":[],"published":{"date-parts":[[2020,10,30]]},"assertion":[{"value":"2020-11-02","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}