{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T15:32:06Z","timestamp":1785511926604,"version":"3.56.0"},"publisher-location":"New York, NY, USA","reference-count":134,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,3,25]],"date-time":"2023-03-25T00:00:00Z","timestamp":1679702400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-2145888"],"award-info":[{"award-number":["CNS-2145888"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,3,25]]},"DOI":"10.1145\/3623278.3624763","type":"proceedings-article","created":{"date-parts":[[2024,2,7]],"date-time":"2024-02-07T19:28:26Z","timestamp":1707334106000},"page":"378-393","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":10,"title":["Veil: A Protected Services Framework for Confidential Virtual Machines"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-4097-3205","authenticated-orcid":false,"given":"Adil","family":"Ahmad","sequence":"first","affiliation":[{"name":"Arizona State University, Tempe, United States of America"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-3539-6873","authenticated-orcid":false,"given":"Botong","family":"Ou","sequence":"additional","affiliation":[{"name":"Purdue University, West Lafayette, Indiana, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5774-0809","authenticated-orcid":false,"given":"Congyu","family":"Liu","sequence":"additional","affiliation":[{"name":"Purdue University, West Lafayette, Indiana, United States of America"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4646-7146","authenticated-orcid":false,"given":"Xiaokuan","family":"Zhang","sequence":"additional","affiliation":[{"name":"George Mason University, Fairfax, Virginia, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2480-4487","authenticated-orcid":false,"given":"Pedro","family":"Fonseca","sequence":"additional","affiliation":[{"name":"Purdue University, West Lafayette, Indiana, United States of America"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,2,7]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"AMDESE\/AMDSEV: AMD Secure Encrypted Virtualization. https:\/\/github.com\/AMDESE\/AMDSEV."},{"key":"e_1_3_2_1_2_1","unstructured":"auditctl(8) - Linux Manpage. https:\/\/linux.die.net\/man\/8\/auditctl\/."},{"key":"e_1_3_2_1_3_1","unstructured":"Gzip - GNU Project Free Software Foundation. https:\/\/www.gnu.org\/software\/gzip\/."},{"key":"e_1_3_2_1_4_1","unstructured":"Linux Kernel CVEs | All CVEs. https:\/\/www.linuxkernelcves.com\/cves."},{"key":"e_1_3_2_1_5_1","unstructured":"Linux Test Project. https:\/\/github.com\/linux-test-project\/ltp."},{"key":"e_1_3_2_1_6_1","unstructured":"Linux Test Project: ltp\/testcases\/kernel. https:\/\/github.com\/linux-test-project\/ltp\/tree\/master\/testcases\/kernel."},{"key":"e_1_3_2_1_7_1","unstructured":"Linux TestProject: ltp\/testcases\/kernel\/device-drivers. https:\/\/github.com\/linux-test-project\/ltp\/tree\/master\/testcases\/kernel\/device-drivers."},{"key":"e_1_3_2_1_8_1","unstructured":"Linux Test Project: ltp\/testcases\/kernel\/syscalls. https:\/\/github.com\/linux-test-project\/ltp\/tree\/master\/testcases\/kernel\/syscalls."},{"key":"e_1_3_2_1_9_1","unstructured":"Linux Test Project: ltp\/testcases\/kernel\/tracing. https:\/\/github.com\/linux-test-project\/ltp\/tree\/master\/testcases\/kernel\/tracing."},{"key":"e_1_3_2_1_10_1","unstructured":"mbedtls. https:\/\/tls.mbed.org."},{"key":"e_1_3_2_1_11_1","unstructured":"Memcached - A Distributed Memory Object Caching System. https:\/\/memcached.org\/."},{"key":"e_1_3_2_1_12_1","unstructured":"UnQLite - An Embedded NoSQL Database Engine. https:\/\/unqlite.org\/."},{"key":"e_1_3_2_1_13_1","unstructured":"Virtio - KVM. https:\/\/www.linux-kvm.org\/page\/Virtio."},{"key":"e_1_3_2_1_14_1","unstructured":"01org. Intel(R) Software Guard Extensions for Linux* OS (source code). https:\/\/github.com\/01org\/linux-sgx."},{"key":"e_1_3_2_1_15_1","volume-title":"Proceedings of the 30th USENIX Security Symposium (Security) (Virtual Event","author":"Abubakar M.","year":"2021","unstructured":"Abubakar, M., Ahmad, A., Fonseca, P., and Xu, D. SHARD: Fine-Grained Kernel Specialization with Context-Aware Hardening. In Proceedings of the 30th USENIX Security Symposium (Security) (Virtual Event, Aug. 2021)."},{"key":"e_1_3_2_1_16_1","volume-title":"Proceedings of the 2010 USENIX Annual Technical Conference (ATC)","author":"Accetta M. J.","year":"2010","unstructured":"Accetta, M. J., Baron, R. V., Bolosky, W. J., Golub, D. B., Rashid, R. F., Tevanian, A., and Young, M. Mach: A New Kernel Foundation for UNIX Development. In Proceedings of the 2010 USENIX Annual Technical Conference (ATC) (Boston, MA, June 2010)."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23513"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24057"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23284"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3445814.3446727"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833745"},{"key":"e_1_3_2_1_22_1","volume-title":"Proceedings of the 17th USENIX Symposium on Operating Systems Design and Implementation (OSDI) (Jul","author":"Ahmad A.","year":"2023","unstructured":"Ahmad, A., Schultz, A., Lee, B., and Fonseca, P. An Extensible Orchestration and Protection Framework for Confidential Cloud Computing. In Proceedings of the 17th USENIX Symposium on Operating Systems Design and Implementation (OSDI) (Jul 2023)."},{"key":"e_1_3_2_1_23_1","unstructured":"AMD. AMD SEV-SNP: Strengthening SEV with Integrity Protections and More. https:\/\/www.amd.com\/system\/files\/TechDocs\/SEV-SNP-strengthening-vm-isolation-with-integrity-protection-and-more.pdf."},{"key":"e_1_3_2_1_24_1","unstructured":"AMD. AMDESE\/linux-svsm. https:\/\/github.com\/AMDESE\/linux-svsm."},{"key":"e_1_3_2_1_25_1","unstructured":"AMD. SEV-ES Guest-Hypervisor Communication Block Standardization. https:\/\/developer.amd.com\/wp-content\/resources\/56421.pdf."},{"key":"e_1_3_2_1_26_1","unstructured":"AMD. SEV Secure Nested Paging Firmware ABI Specification. https:\/\/www.amd.com\/system\/files\/TechDocs\/56860.pdf."},{"key":"e_1_3_2_1_27_1","volume-title":"AMD to Launch 3rd Generation EPYC on March 15: Milan with Zen 3. https:\/\/www.anandtech.com\/show\/16537\/amd-to-launch-3rd-generation-epyc-on-march-15th-milan-with-zen-3","author":"AnandTech","unstructured":"AnandTech. AMD to Launch 3rd Generation EPYC on March 15: Milan with Zen 3. https:\/\/www.anandtech.com\/show\/16537\/amd-to-launch-3rd-generation-epyc-on-march-15th-milan-with-zen-3."},{"key":"e_1_3_2_1_28_1","volume-title":"https:\/\/www.arm.com\/architecture\/security-features\/arm-confidential-compute-architecture","author":"Arm","year":"2022","unstructured":"ARM. Arm confidential compute architecture. https:\/\/www.arm.com\/architecture\/security-features\/arm-confidential-compute-architecture, 2022."},{"key":"e_1_3_2_1_29_1","volume-title":"SCONE: Secure Linux Containers with Intel SGX. In Proceedings of the 12th USENIX Symposium on Operating Systems Design and Implementation (OSDI)","author":"Arnautov S.","year":"2016","unstructured":"Arnautov, S., Trach, B., Gregor, F., Knauth, T., Martin, A., Priebe, C., Lind, J., Muthukumaran, D., O'Keeffe, D., Stillwell, M., et al. SCONE: Secure Linux Containers with Intel SGX. In Proceedings of the 12th USENIX Symposium on Operating Systems Design and Implementation (OSDI) (Savannah, GA, November 2016)."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660350"},{"key":"e_1_3_2_1_31_1","unstructured":"Azure M. DCasv5 and ECasv5 Series Confidential VMs. https:\/\/learn.microsoft.com\/en-us\/azure\/confidential-computing\/confidential-vm-overview."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.5555\/2685048.2685070"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484779"},{"key":"e_1_3_2_1_34_1","volume-title":"Proceedings of the 27th USENIX Security Symposium (Security) (August","author":"Bulck J. V.","year":"2018","unstructured":"Bulck, J. V., Minkin, M., Weisse, O., Genkin, D., Kasikci, B., Piessens, F., Silberstein, M., Wenisch, T. F., Yarom, Y., and Strackx, R. Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order Execution. In Proceedings of the 27th USENIX Security Symposium (Security) (August 2018)."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00061"},{"key":"e_1_3_2_1_36_1","volume-title":"Proceedings of the 2017 USENIX Annual Technical Conference (ATC)","author":"Tsai C.","year":"2017","unstructured":"che Tsai, C., Porter, D. E., and Vij, M. Graphene-SGX: A Practical Library OS for Unmodified Applications on SGX. In Proceedings of the 2017 USENIX Annual Technical Conference (ATC) (Santa Clara, CA, July 2017)."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/2451116.2451145"},{"key":"e_1_3_2_1_38_1","volume-title":"Tamper-Resistant Execution in an Untrusted Operating System Using A Virtual Machine Monitor","author":"Chen H.","year":"2007","unstructured":"Chen, H., Zhang, F., Chen, C., Yang, Z., Chen, R., Zang, B., and Mao, W. Tamper-Resistant Execution in an Untrusted Operating System Using A Virtual Machine Monitor, 2007."},{"key":"e_1_3_2_1_39_1","volume-title":"Proceedings of the 24th ACM Conference on Computer and Communications Security (CCS)","author":"Chen S.","year":"2017","unstructured":"Chen, S., Zhang, X., Reiter, M. K., and Zhang, Y. Detecting Privileged Side-Channel Attacks in Shielded Execution with D\u00e9j\u00e1 Vu. In Proceedings of the 24th ACM Conference on Computer and Communications Security (CCS) (Dallas, TX, Oct.-Nov. 2017)."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/1346281.1346284"},{"key":"e_1_3_2_1_41_1","volume-title":"Proceedings of the 25th USENIX Security Symposium (Security)","author":"Costan V.","year":"2016","unstructured":"Costan, V., Lebedev, I., and Devadas, S. Sanctum: Minimal Hardware Extensions for Strong Software Isolation. In Proceedings of the 25th USENIX Security Symposium (Security) (Austin, TX, August 2016)."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/2541940.2541986"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/1294261.1294295"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24328"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/2694344.2694386"},{"key":"e_1_3_2_1_46_1","volume-title":"Proceedings of the 27th USENIX Security Symposium (Security)","author":"Dong X.","year":"2018","unstructured":"Dong, X., Shen, Z., Criswell, J., Cox, A. L., and Dwarkadas, S. Shielding Software from Privileged Side-Channel Attacks. In Proceedings of the 27th USENIX Security Symposium (Security) (Baltimore, MD, Aug 2018)."},{"key":"e_1_3_2_1_47_1","unstructured":"Enarx. AMD SEV Remote Attestation Protocol. https:\/\/enarx.dev\/docs\/technical\/amd-sev-attestation."},{"key":"e_1_3_2_1_48_1","volume-title":"Proceedings of the 15th USENIX Symposium on Operating Systems Design and Implementation (OSDI) (Jul","author":"Feng E.","year":"2021","unstructured":"Feng, E., Lu, X., Du, D., Yang, B., Jiang, X., Xia, Y., Zang, B., and Chen, H. Scalable Memory Protection in the PENGLAI Enclave. In Proceedings of the 15th USENIX Symposium on Operating Systems Design and Implementation (OSDI) (Jul 2021)."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/3132747.3132782"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/3190508.3190529"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/3064176.3064183"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.5555\/3620237.3620260"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560592"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/TCC.2014.2358236"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/3477132.3483549"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/3600006.3613148"},{"key":"e_1_3_2_1_57_1","unstructured":"Google. google\/syzkaller: syzkaller is an unsupervised coverage-guided kernel fuzzer. https:\/\/github.com\/google\/syzkaller."},{"key":"e_1_3_2_1_58_1","unstructured":"Google. Introducing Google cloud confidential computing with confidential VMs. https:\/\/cloud.google.com\/blog\/products\/identity-security\/introducing-google-cloud-confidential-computing-with-confidential-vms."},{"key":"e_1_3_2_1_59_1","unstructured":"Google Cloud. Confidential computing concepts | Google Cloud. https:\/\/cloud.google.com\/confidential-computing\/confidential-vm\/docs\/about-cvm."},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/3471621.3471849"},{"key":"e_1_3_2_1_61_1","volume-title":"Proceedings of the 27th USENIX Security Symposium (Security)","author":"Gruss D.","year":"2017","unstructured":"Gruss, D., Lettner, J., Schuster, F., Ourimenko, O., Haller, I., and Costa, M. Strong and Efficient Cache Side-Channel Protection using Hardware Transactional Memory. In Proceedings of the 27th USENIX Security Symposium (Security) (Vancouver, BC, 2017)."},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/3081333.3081349"},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00096"},{"key":"e_1_3_2_1_64_1","volume-title":"Security Analysis of Encrypted Virtual Machines. ACM SIGPLAN Notices","author":"Hetzelt F.","year":"2017","unstructured":"Hetzelt, F., and Buhren, R. Security Analysis of Encrypted Virtual Machines. ACM SIGPLAN Notices (2017)."},{"key":"e_1_3_2_1_65_1","volume-title":"Proceedings of the 16th USENIX Symposium on Operating Systems Design and Implementation (OSDI)","author":"Hof A. V.","year":"2022","unstructured":"Hof, A. V., and Nieh, J. BlackBox: A Container Security Monitor for Protecting Containers on Untrusted Operating Systems. In Proceedings of the 16th USENIX Symposium on Operating Systems Design and Implementation (OSDI) (Carlsbad, CA, July 2022)."},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/2451116.2451146"},{"key":"e_1_3_2_1_67_1","volume-title":"USENIX security symposium","author":"Hua Z.","year":"2017","unstructured":"Hua, Z., Gu, J., Xia, Y., Chen, H., Zang, B., and Guan, H. vTZ: Virtualizing ARM TrustZone. In USENIX security symposium (2017)."},{"key":"e_1_3_2_1_68_1","unstructured":"Intel. Intel 64 and ia-32 architectures software developer's manual. Volume 3A: System Programming Guide (2016)."},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053034"},{"key":"e_1_3_2_1_70_1","volume-title":"Proceedings of the 21st USENIX Security Symposium (Security)","author":"Kim T.","year":"2012","unstructured":"Kim, T., Peinado, M., and Mainar-Ruiz, G. STEALTHMEM: System-Level Protection Against Cache-Based Side Channel Attacks in the Cloud. In Proceedings of the 21st USENIX Security Symposium (Security) (Bellevue, WA, Aug. 2012)."},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1145\/1629575.1629596"},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00002"},{"key":"e_1_3_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1145\/3447786.3456248"},{"key":"e_1_3_2_1_74_1","volume-title":"Proceedings of the Privacy Enhancing Technologies Symposium (PETS)","author":"Le D. V.","year":"2020","unstructured":"Le, D. V., Hurtado, L. T., Ahmad, A., Minaei, M., Lee, B., and Kate, A. A Tale of Two Trees: One Writes, and Other Reads. Optimized Oblivious Accesses to Large-Scale Blockchains. In Proceedings of the Privacy Enhancing Technologies Symposium (PETS) (2020)."},{"key":"e_1_3_2_1_75_1","unstructured":"Lea D. Dlmalloc 2010."},{"key":"e_1_3_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.5555\/3489212.3489240"},{"key":"e_1_3_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1145\/3342195.3387532"},{"key":"e_1_3_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243748"},{"key":"e_1_3_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.5555\/3241189.3241233"},{"key":"e_1_3_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833768"},{"key":"e_1_3_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485253"},{"key":"e_1_3_2_1_82_1","volume-title":"28th USENIX Security Symposium (USENIX Security)","author":"Li M.","year":"2019","unstructured":"Li, M., Zhang, Y., Lin, Z., and Solihin, Y. Exploiting Unprotected I\/O Operations in AMD's Secure Encrypted Virtualization. In 28th USENIX Security Symposium (USENIX Security) (2019)."},{"key":"e_1_3_2_1_83_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Li M.","year":"2021","unstructured":"Li, M., Zhang, Y., Wang, H., Li, K., and Cheng, Y. CIPHERLEAKS: Breaking Constant-time Cryptography on AMD SEV via the Ciphertext Side Channel. In 30th USENIX Security Symposium (USENIX Security 21) (2021)."},{"key":"e_1_3_2_1_84_1","volume-title":"TLB Poisoning Attacks on AMD Secure Encrypted Virtualization. In Annual Computer Security Applications Conference","author":"Li M.","year":"2021","unstructured":"Li, M., Zhang, Y., Wang, H., Li, K., and Cheng, Y. TLB Poisoning Attacks on AMD Secure Encrypted Virtualization. In Annual Computer Security Applications Conference (2021)."},{"key":"e_1_3_2_1_85_1","doi-asserted-by":"publisher","DOI":"10.5555\/3361338.3361433"},{"key":"e_1_3_2_1_86_1","unstructured":"Lighttpd. Lighttpd - fly light. https:\/\/www.lightttpd.net\/."},{"key":"e_1_3_2_1_87_1","volume-title":"Proceedings of the 27th USENIX Security Symposium (Security) (July","author":"Lipp M.","year":"2018","unstructured":"Lipp, M., Schwarz, M., Gruss, D., Prescher, T., Haas, W., Fogh, A., Horn, J., Mangard, S., Kocher, P., Genkin, D., Yarom, Y., and Hamburg, M. Meltdown: Reading Kernel Memory from User Space. In Proceedings of the 27th USENIX Security Symposium (Security) (July 2018)."},{"key":"e_1_3_2_1_88_1","doi-asserted-by":"publisher","DOI":"10.1145\/3575693.3575731"},{"key":"e_1_3_2_1_89_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.43"},{"key":"e_1_3_2_1_90_1","volume-title":"Proceedings of the 2018 USENIX Annual Technical Conference (ATC)","author":"Ma S.","year":"2018","unstructured":"Ma, S., Zhai, J., Kwon, Y., Lee, K. H., Zhang, X., Ciocarlie, G., Gehani, A., Yegneswaran, V., Xu, D., and Jha, S. Kernel-Supported Cost-Effective Audit Logging for Causality Tracking. In Proceedings of the 2018 USENIX Annual Technical Conference (ATC) (Boston, MA, July 2018)."},{"key":"e_1_3_2_1_91_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA.2012.6237011"},{"key":"e_1_3_2_1_92_1","doi-asserted-by":"publisher","DOI":"10.1145\/2487726.2488368"},{"key":"e_1_3_2_1_93_1","unstructured":"Microsoft. Azure Confidential VMs Using SEV-SNP (DCasv5\/ECasv5) are Now Generally Available. https:\/\/techcommunity.microsoft.com\/t5\/azure-confidential-computing\/azure-confidential-vms-using-sev-snp-dcasv5-ecasv5-are-now\/ba-p\/3573747."},{"key":"e_1_3_2_1_94_1","unstructured":"Microsoft Docs. Virtualization-Based Security (VBS). htttps:\/\/docs.microsoft.com\/en-us\/windows-hardware\/design\/device-experiences\/oem-vbs."},{"key":"e_1_3_2_1_95_1","doi-asserted-by":"publisher","DOI":"10.1145\/3292006.3300022"},{"key":"e_1_3_2_1_96_1","doi-asserted-by":"publisher","DOI":"10.1145\/3193111.3193112"},{"key":"e_1_3_2_1_97_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00057"},{"key":"e_1_3_2_1_98_1","volume-title":"musl-libc","author":"Musl-Libc","year":"2017","unstructured":"Musl-Libc. musl-libc, 2017. https:\/\/www.musl-libc.org."},{"key":"e_1_3_2_1_99_1","doi-asserted-by":"publisher","DOI":"10.1145\/3381052.3381328"},{"key":"e_1_3_2_1_100_1","unstructured":"NGINX Inc. NGINX High Performance Load Balancer Web Server & Reverse Proxy. https:\/\/www.nginx.com."},{"key":"e_1_3_2_1_101_1","doi-asserted-by":"publisher","DOI":"10.1145\/3064176.3064219"},{"key":"e_1_3_2_1_102_1","doi-asserted-by":"publisher","DOI":"10.1007\/11605805_1"},{"key":"e_1_3_2_1_103_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24065"},{"key":"e_1_3_2_1_104_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417862"},{"key":"e_1_3_2_1_105_1","volume-title":"Partitioned Cache Architecture as a Side-Channel Defence Mechanism. Cryptology ePrint Archive","author":"Page D.","year":"2005","unstructured":"Page, D. Partitioned Cache Architecture as a Side-Channel Defence Mechanism. Cryptology ePrint Archive (2005)."},{"key":"e_1_3_2_1_106_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179284"},{"key":"e_1_3_2_1_107_1","unstructured":"Phoronix. 7-Zip Compression. https:\/\/openbenchmarking.org\/test\/pts\/compress-7zip-1.9.0."},{"key":"e_1_3_2_1_108_1","unstructured":"Phoronix. OpenSSL Benchmark. https:\/\/openbenchmarking.org\/test\/pts\/openssl."},{"key":"e_1_3_2_1_109_1","unstructured":"Phoronix. SQLite SpeedTest Benchmark. https:\/\/openbenchmarking.org\/test\/pts\/sqlite-speedtest."},{"key":"e_1_3_2_1_110_1","volume-title":"Proceedings of the 24th USENIX Security Symposium (Security)","author":"Rane A.","year":"2015","unstructured":"Rane, A., Lin, C., and Tiwari, M. Raccoon: Closing Digital Side-Channels through Obfuscated Execution. In Proceedings of the 24th USENIX Security Symposium (Security) (Washington, DC, Aug. 2015)."},{"key":"e_1_3_2_1_111_1","volume-title":"Guest-Transparent Prevention of Kernel Rootkits with VMM-based Memory Shadowing. In Recent Advances in Intrusion Detection: 11th International Symposium (RAID)","author":"Riley R.","year":"2008","unstructured":"Riley, R., Jiang, X., and Xu, D. Guest-Transparent Prevention of Kernel Rootkits with VMM-based Memory Shadowing. In Recent Advances in Intrusion Detection: 11th International Symposium (RAID) (2008)."},{"key":"e_1_3_2_1_112_1","doi-asserted-by":"publisher","DOI":"10.1145\/1294261.1294294"},{"key":"e_1_3_2_1_113_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSNW.2011.5958812"},{"key":"e_1_3_2_1_114_1","volume-title":"Deconstructing Xen. In Proceedings of the 2017 Annual Network and Distributed System Security Symposium (NDSS)","author":"Shi L.","year":"2017","unstructured":"Shi, L., Wu, Y., Xia, Y., Dautenhahn, N., Chen, H., Zang, B., and Li, J. Deconstructing Xen. In Proceedings of the 2017 Annual Network and Distributed System Security Symposium (NDSS) (San Diego, CA, Feb. 2017)."},{"key":"e_1_3_2_1_115_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23193"},{"key":"e_1_3_2_1_116_1","volume-title":"Proceedings of the 9th USENIX Symposium on Operating Systems Design and Implementation (OSDI)","author":"Soares L.","year":"2010","unstructured":"Soares, L., and Stumm, M. FlexSC: Flexible System Call Scheduling with Exception-Less System Calls. In Proceedings of the 9th USENIX Symposium on Operating Systems Design and Implementation (OSDI) (Vancouver, Canada, Oct. 2010)."},{"key":"e_1_3_2_1_117_1","volume-title":"SPEC CPU 2006","author":"SPEC.","year":"2006","unstructured":"SPEC. SPEC CPU 2006. https:\/\/www.spec.org\/cpu2006\/."},{"key":"e_1_3_2_1_118_1","unstructured":"SQLite Consortium. SQLite home page."},{"key":"e_1_3_2_1_119_1","unstructured":"SUSE. Understanding Linux Audit. https:\/\/documentation.suse.com\/sles\/12-SP4\/html\/SLES-all\/cha-audit-comp.html."},{"key":"e_1_3_2_1_120_1","doi-asserted-by":"publisher","DOI":"10.1145\/945445.945466"},{"key":"e_1_3_2_1_121_1","unstructured":"The Apache Software Foundation. ab - Apache HTTP Server Benchmark Tool. https:\/\/httpd.apache.org\/docs\/2.4\/programs\/ab.html."},{"key":"e_1_3_2_1_122_1","doi-asserted-by":"publisher","DOI":"10.1145\/2592798.2592812"},{"key":"e_1_3_2_1_123_1","doi-asserted-by":"publisher","DOI":"10.1145\/2901318.2901341"},{"key":"e_1_3_2_1_124_1","volume-title":"Proceedings of the 26th USENIX Security Symposium (Security) (August","author":"Van Bulck J.","year":"2017","unstructured":"Van Bulck, J., Weichbrodt, N., Kapitza, R., Piessens, F., and Strackx, R. Telling your Secrets without Page Faults: Stealthy Page Table-Based Attacks on Enclaved Execution. In Proceedings of the 26th USENIX Security Symposium (Security) (August 2017)."},{"key":"e_1_3_2_1_125_1","doi-asserted-by":"publisher","DOI":"10.1145\/3321705.3329820"},{"key":"e_1_3_2_1_126_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00080"},{"key":"e_1_3_2_1_127_1","volume-title":"Proceedings of the 25th USENIX Security Symposium (Security) (August","author":"Xiao Y.","year":"2016","unstructured":"Xiao, Y., Zhang, X., Zhang, Y., and Teodorescu, R. One Bit Flips, One Cloud Flops: Cross-VM Row Hammer Attacks and Privilege Escalation. In Proceedings of the 25th USENIX Security Symposium (Security) (August 2016)."},{"key":"e_1_3_2_1_128_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-41284-4_6"},{"key":"e_1_3_2_1_129_1","doi-asserted-by":"publisher","DOI":"10.1145\/1266840.1266852"},{"key":"e_1_3_2_1_130_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.45"},{"key":"e_1_3_2_1_131_1","doi-asserted-by":"publisher","DOI":"10.1145\/3447786.3456258"},{"key":"e_1_3_2_1_132_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833694"},{"key":"e_1_3_2_1_133_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978324"},{"key":"e_1_3_2_1_134_1","unstructured":"Zhuang M. and Aker B. memaslap - Load Testing and Benchmarking a Server. http:\/\/docs.libmemcached.org\/bin\/memaslap.html."}],"event":{"name":"ASPLOS '23: 28th ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Volume 4","location":"Vancouver BC Canada","acronym":"ASPLOS '23","sponsor":["SIGARCH ACM Special Interest Group on Computer Architecture","SIGOPS ACM Special Interest Group on Operating Systems","SIGPLAN ACM Special Interest Group on Programming Languages","SIGBED ACM Special Interest Group on Embedded Systems"]},"container-title":["Proceedings of the 28th ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Volume 4"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3623278.3624763","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3623278.3624763","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3623278.3624763","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:36:26Z","timestamp":1750178186000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3623278.3624763"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,3,25]]},"references-count":134,"alternative-id":["10.1145\/3623278.3624763","10.1145\/3623278"],"URL":"https:\/\/doi.org\/10.1145\/3623278.3624763","relation":{},"subject":[],"published":{"date-parts":[[2023,3,25]]},"assertion":[{"value":"2024-02-07","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}