REVIEW 2 major objections 5 minor 86 references
Pacer: Comprehensive Network Side-Channel Mitigation in the Cloud
T0 review · 2 major / 5 minor · reviewed 2026-08-14 · deepseek-v4-flash
Pith's one-line read Pacer reshapes traffic outside guest VMs so packet timing and sizes carry no secret-dependent signal, and proves it with a noninterference theorem.
desk verdict A serious systems paper with a real proof gap: the prototype's interrupt-handler timestamps violate the noninterference theorem's secrecy assumption. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing mechanism is the cloaked tunnel, a schedule-driven shaping layer that wraps each flow outside the application and makes packet timing and size secret-independent by design. The security argument turns on HyPace's masking discipline: an event handler scheduled at $t_n - \delta_{\mathrm{xmit}}$ spins until $t_n$ and then writes the NIC doorbell, so any variability in handler execution is hidden as long as the observed worst-case delay $\delta_{\mathrm{xmit}}=35\,\mu\mathrm{s}$ is a true bound; batched, epoch-based transmission amortizes the cost of this masking. GPace enforces a second bound, $\delta_{\mathrm{delay}}=20\,\mathrm{ms}$, for the guest's processing of inbound packets and timers, so that causally related network events are never observably closer than the bound. Together these mechanisms ensure that each of the paper's properties S1–S5 — schedule choice, activation, updates, deviations, and transport responses — is either secret-independent or unobservable to a network adversary.
What would settle it
Run two Pacer-protected servers that differ only in their private guest state while a co-resident adversary generates heavy DMA, bus, and PCIe traffic, and record every NIC doorbell-write delay relative to the scheduled transmission time; if any delay exceeds $\delta_{\mathrm{xmit}}=35\,\mu\mathrm{s}$, or if a classifier trained on the packet traces identifies the private state better than random guessing, Theorem 3's premise is falsified.
Extended reading notes
Core claim
The paper's central claim is that network side-channel leaks can be removed by construction rather than by adding noise. Pacer wraps a tenant's flows in a cloaked tunnel whose shaping layer decides every transmission: packets are padded to MTU size, transmission follows a schedule anchored to public events such as a request arrival or a prechosen class, and a dummy packet is sent whenever the guest has not produced payload in time. HyPace, a small hypervisor component, enforces the schedule and masks any secret-dependent delay in its own execution by spinning until the scheduled time before writing the NIC doorbell, batching packets in epochs to keep line rate. GPace, a kernel module in the guest, pads payloads, shares per-flow congestion windows and sequence numbers, and masks processing delays between causally related network events. The formal appendix proves Theorem 3: from identical public states, runs with different private guest states produce observationally identical environment states, so an adversary observing traffic shape learns nothing about guest secrets.
Load-bearing premise
Security rests on the empirical bounds $\delta_{\mathrm{xmit}}=35\,\mu\mathrm{s}$ for the delay between a scheduled transmission and the NIC doorbell write and $\delta_{\mathrm{delay}}=20\,\mathrm{ms}$ for guest processing; the paper concedes that secret-dependent bus or PCIe contention on general-purpose hardware cannot be ruled out, so an adversary who can reliably trigger such delays could break the masking assumption.
Editorial extensions
If this is right
- A tenant who rents a dedicated CPU socket and runs Pacer can expose its outbound traffic to colocated or on-path observers without leaking secret-dependent information through packet timing, sizes, or counts.
- Workloads can be partitioned into public classes such as video resolution or document clusters; each class may use its own efficient schedule, and only the public class membership is revealed, not the specific object.
- Because Pacer honors congestion signals, flow-control windows, and retransmissions, it can sustain elastic bandwidth sharing and TCP-friendliness, which fixed-rate dummy traffic cannot.
- The quantitative costs are two hypervisor cores, modest memory, and bandwidth overhead that depends on how coarsely or finely the tenant clusters its content; the paper reports roughly 4x padding on videos and 142.8% on medical pages with the tested clusters.
- If the proof and measurements hold, a CNN classifier that would identify shielded videos in the clear at over 99% accuracy is reduced to predictions no better than random on Pacer-shaped traffic.
Reading between the lines
- If NICs ever expose a hardware 'transmit at this timestamp' primitive, Pacer's $\delta_{\mathrm{xmit}}$ bound could become a hardware guarantee instead of an empirical measurement, closing the residual bus- and PCIe-contention gap the paper explicitly leaves open.
- The same tunnel abstraction can be mirrored at the client end, which the paper notes as a trivial extension; that would hide request timing and sizes as well as responses, at the cost of client-side GPace installation.
- Pacer's guarantee is stated for a threat model that already excludes microarchitectural channels by dedicated-socket rental; combining it with CPU-cache and memory isolation would give a stronger end-to-end confidentiality claim for the whole server, not just the network path.
- The 99th/90th-percentile schedule synthesis in ProfPace is tuned for web-style workloads; applying Pacer to interactive protocols such as VoIP or remote procedure calls would require re-measuring those percentiles, since the latency overhead of tail-shaped schedules may dominate for short exchanges.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper presents Pacer, a system aimed at eliminating network side channels (NSCs) in public IaaS clouds by shaping traffic outside the guest VM. The core abstraction is a cloaked tunnel that makes packet timing and size independent of secrets. Pacer is implemented as a paravirtualized extension: HyPace in the hypervisor handles transmission scheduling, encryption, padding, and dummy generation; GPace in the guest kernel shares network state and timestamps; ProfPace generates transmission schedules. The paper includes a formal noninterference model and proof in Appendix E, and an experimental evaluation on two web workloads showing moderate overhead and successful defense against a CNN classifier. The abstract claims that Pacer is the first system to eliminate NSC leaks end-to-end and that it provides provable security.
Significance. If the security claim holds, Pacer is a significant advance over prior NSC mitigations: it explicitly addresses host-level internal side channels (requirement R6), respects network flow control, congestion control, and loss recovery (R5), and provides a formal noninterference theorem. The formal model in Appendix E is a genuine proof with clearly stated assumptions, and the evaluation is thorough in its coverage of latency, throughput, and bandwidth overheads. The paper is also honest about several limitations, most notably the possibility of secret-dependent bus/PCIe interference. However, the significance of the contribution is conditional on closing a substantial gap between the assumptions of the formal model and the behavior of the implemented prototype, as detailed below.
major comments (2)
- [§4.2 and Appendix E (Figure 11, assumption (2))] The prototype violates the formal model's assumption that schedule effective times are secret-independent. GPace timestamps inbound packets in the vNIC interrupt handler, so the timestamp used to anchor a default schedule is taken after an interrupt-delivery delay d that may depend on the guest's secret-dependent computation (e.g., interrupts disabled while processing a secret). The schedule start time is thus T_arrival + d, and the first response is transmitted at T_arrival + d + δ, where δ = ε + δdelay. The request-to-response interval observed by a network adversary includes the secret-dependent component d; adding the constant δdelay after the timestamp shifts but does not cancel its variation. This violates assumption (2) of the formal model (Figure 11), which requires the effective time Tei to be secret-independent, so Theorem 3 does not apply to the implementation as described. The masking rule of §4.2 only hides guest processing that occurs after the timestamp is taken, not the delay before the timestamp, so the central claim that Pacer's prototype achieves noninterference is not supported.
- [§4.1 and Appendix E (assumption (7))] The claimed end-to-end guarantee is not established for the hardware transmission path. The paper states that delays between the doorbell write and the actual wire transmission caused by concurrent secret-dependent bus/PCIe transactions 'cannot be ruled out on general-purpose hardware' (§4.1). The formal model abstracts away the NIC and bus: assumption (7) concerns only Fo_H's logical output timing, not the physical time at which a packet appears on the wire. Consequently, Theorem 3 proves noninterference only up to the HyPace doorbell write, and the prototype's security on real hardware depends on the empirically measured bound δxmit = 35 µs, which the authors concede is an assumption rather than a guarantee. The abstract's unqualified claim that Pacer 'eliminates NSC leaks in public IaaS Clouds end-to-end' is therefore too strong for the current prototype; the security result is conditional on empirical delay bounds that the paper itself says may be violated by an adversary able to induce bus contention.
minor comments (5)
- [§4.2] The definition of δdelay as the 'empirical maximum inbound packet- and timer-processing time' is ambiguous about whether it includes the latency from packet arrival at the NIC to the entry of the vNIC interrupt handler; the paper should state precisely what was measured and whether the 20 ms bound covers that interval.
- [§6.3] The empirical security evaluation uses only four videos from a single cluster and reports that classifier probabilities are near 25% for each label; the paper should provide a confidence interval or error analysis and clarify that this is a sanity check rather than a validation of the noninterference guarantee.
- [§5] The statement that an inadequate schedule 'cannot leak secrets' should be justified for the case where an actual response exceeds the scheduled packet count, since excess payload may be dropped or deferred and could trigger secret-dependent retransmissions or connection timeouts that alter traffic shape.
- [Appendix E] There is a garbled line of characters immediately before Figure 8 in the provided text that appears to be a rendering artifact; the authors should ensure the final version contains no such corruption.
- [§2.1] The prototype assumptions state that client request traffic reveals no secrets through its shape; this is a strong assumption for the bidirectional case and should be highlighted earlier, since it limits the 'end-to-end' claim to server-side shaping only.
Circularity Check
No significant circularity: Pacer's noninterference theorem is a conditional compositional proof with explicit component-level assumptions, not a fitted or self-citational derivation.
full rationale
Pacer's central security claim is Theorem 3 in Appendix E, which states a noninterference property for the composed system. The proof is a standard relational invariant argument: it assumes component-level conditions (e.g., assumption (1) that the environment's observable behavior is secret-independent, assumption (2) that profile update contents and effective times are secret-independent, assumption (6) that profile updates respect their effective times, and assumption (7) that HyPace's output function Fo_H emits same packet timings given same profiles regardless of packet queue contents) and derives the system-level conclusion. These assumptions are not introduced as predictions or as outputs of the derivation; they are explicit hypotheses of the model. In particular, assumption (7) is a formal abstraction of the §4.1 masking mechanism, not a restatement of Theorem 3, because it concerns only the low-level Fo_H step and still requires the proof (Lemma 2) to show that the profiles [sigma_H'] are equal across runs before it can be applied. The empirical bounds delta_xmit and delta_delay are presented as measured estimates with explicit caveats that hardware interference 'cannot be ruled out on general-purpose hardware'; they are not fitted parameters being relabeled as predictions. The CNN evaluation is an empirical sanity check, not a derivation from fitted values. No load-bearing self-citation or imported uniqueness theorem appears. Accordingly, no step in the paper's derivation chain is circular; the main caveats are unproven hardware assumptions, which are correctness and validation concerns rather than circularity.
Assumptions & free parameters
free parameters (5)
- δxmit (transmission masking delay bound) =
35 µs
- δdelay (guest processing delay bound) =
20 ms
- Epoch length ε =
120 µs
- Max batch size B =
38 packets per HyPace handler
- Schedule percentile parameters =
99th percentile initial delay, 90th percentile inter-packet spacing, 100th percentile packet count +10%
assumptions (6)
- domain assumption Clients do not leak secrets through request timing or payload-visible behavior (assumption (1), Figure 10).
- domain assumption The guest does not leak secrets through profile update effective times, only through queueing times (assumption (2), Figure 11).
- domain assumption Propagation delays are respected: Tui ≤ Tei for all profile updates (assumption (3)).
- ad hoc to paper Event handler delays are bounded by the empirically measured δxmit and guest delays by δdelay.
- ad hoc to paper HyPace's output function Fo_H itself does not leak secrets (assumption (7), Figure 13).
- domain assumption Chosen traffic shapes (schedules) are secret-independent (S1, §3.3).
Cite this review
Pith. "Pith review of Pacer: Comprehensive Network Side-Channel Mitigation in the Cloud." pith.science (2026). https://pith.science/paper/V6J4JUI5
@misc{pith2026190811568,
author = {Pith},
title = {Pith review of: Pacer: Comprehensive Network Side-Channel Mitigation in the Cloud},
year = {2026},
howpublished = {\url{https://pith.science/paper/V6J4JUI5}},
note = {Machine review of arXiv:1908.11568}
}
read the original abstract
Network side channels (NSCs) leak secrets through packet timing and packet sizes. They are of particular concern in public IaaS Clouds, where any tenant may be able to colocate and indirectly observe a victim's traffic shape. We present Pacer, the first system that eliminates NSC leaks in public IaaS Clouds end-to-end. It builds on the principled technique of shaping guest traffic outside the guest to make the traffic shape independent of secrets by design. However, Pacer also addresses important concerns that have not been considered in prior work -- it prevents internal side-channel leaks from affecting reshaped traffic, and it respects network flow control, congestion control and loss recovery signals. Pacer is implemented as a paravirtualizing extension to the host hypervisor, requiring modest changes to the hypervisor and the guest kernel, and only optional, minimal changes to applications. We present Pacer's key abstraction of a cloaked tunnel, describe its design and implementation, prove the security of important design aspects through a formal model, and show through an experimental evaluation that Pacer imposes moderate overheads on bandwidth, client latency, and server throughput, while thwarting attacks based on state-of-the-art CNN classifiers.
Figures
Figures from the paper (11 more)
Reference graph
Works this paper leans on
-
[1]
https://www.mediawiki.org/wiki/MediaWiki_1
MediaWiki. https://www.mediawiki.org/wiki/MediaWiki_1
-
[2]
https://www.medicinenet.com/script/main/hp
MedicineNet. https://www.medicinenet.com/script/main/hp. asp. Last accessed on 16 Sep 2020
2020
-
[3]
https: //www.napatech.com/support/resources/data-sheets/ napatech-smartnic-feature-overview/
NapaTech SmartNIC, Feature Overview Data Sheet. https: //www.napatech.com/support/resources/data-sheets/ napatech-smartnic-feature-overview/
-
[4]
https://github.com/giltene/wrk2
wrk2: A constant throughput, correct latency recording variant of wrk. https://github.com/giltene/wrk2
-
[5]
https://patchwork.kernel.org/patch/ 9669405/
Xen Null scheduler. https://patchwork.kernel.org/patch/ 9669405/
-
[6]
Moving in next door: Network flooding as a side channel in cloud environments
Yatharth Agarwal, Vishnu Murale, Jason Hennessey, Kyle Hogan, and Mayank Varia. Moving in next door: Network flooding as a side channel in cloud environments. In Intl. Conf. on Cryptology and Network Security (CANS), 2016
work page 2016
-
[7]
Fine grain Cross-VM Attacks on Xen and VMware are possible! In IEEE Intl
Gorka Irazoqui Apecechea, Mehmet Sinan Inci, Thomas Eisenbarth, and Berk Sunar. Fine grain Cross-VM Attacks on Xen and VMware are possible! In IEEE Intl. Conf. on Big Data and Cloud Computing (BDCLOUD), 2014
work page 2014
-
[8]
Predictive black- box mitigation of timing channels
Aslan Askarov, Danfeng Zhang, and Andrew C Myers. Predictive black- box mitigation of timing channels. In ACM Conf. on Computer and Communications Security (CCS), 2010
work page 2010
Show all 86 references
-
[9]
Mitigating network side channel leakage for stream processing systems in trusted execution environments
Muhammad Bilal, Hassan Alsibyani, and Marco Canini. Mitigating network side channel leakage for stream processing systems in trusted execution environments. In ACM Intl. Conf. on Distributed and Event- based Systems (DEBS), 2018
2018
-
[10]
Robust and effi- cient elimination of cache and timing side channels
Benjamin A Braun, Suman Jana, and Dan Boneh. Robust and effi- cient elimination of cache and timing side channels. arXiv preprint arXiv:1506.00189, 2015
2015 arXiv
-
[11]
Remote timing attacks are still practical
Billy Bob Brumley and Nicola Tuveri. Remote timing attacks are still practical. In European Symposium on Research in Computer Security (ESORICS), 2011
2011
-
[12]
Remote timing attacks are practical
David Brumley and Dan Boneh. Remote timing attacks are practical. Computer Networks, 48(5), 2005
2005
-
[13]
Cs-buflo: A conges- tion sensitive website fingerprinting defense
Xiang Cai, Rishab Nithyanand, and Rob Johnson. Cs-buflo: A conges- tion sensitive website fingerprinting defense. In Workshop on Privacy in the Electronic Society (WPES), 2014
2014
-
[14]
A systematic approach to developing and evaluating website fingerprinting defenses
Xiang Cai, Rishab Nithyanand, Tao Wang, Rob Johnson, and Ian Gold- berg. A systematic approach to developing and evaluating website fingerprinting defenses. In ACM SIGSAC Conference on Computer and Communications Security (CCS), 2014
2014
-
[15]
Touching from a distance: Website fingerprinting attacks and defenses
Xiang Cai, Xin Cheng Zhang, Brijesh Joshi, and Rob Johnson. Touching from a distance: Website fingerprinting attacks and defenses. In ACM Conf. on Computer and Communications Security (CCS), 2012
2012
-
[16]
Side- channel leaks in web applications: A reality today, a challenge tomorrow
Shuo Chen, Rui Wang, XiaoFeng Wang, and Kehuan Zhang. Side- channel leaks in web applications: A reality today, a challenge tomorrow. In IEEE Symposium on Security and Privacy (SP), 2010
2010
-
[17]
Traffic analysis of ssl encrypted web browsing, 1998
Heyning Cheng and Ron Avnur. Traffic analysis of ssl encrypted web browsing, 1998
1998
-
[18]
Howie Huang
Ron Chi-Lung Chiang, Sundaresan Rajasekaran, Nan Zhang, and H. Howie Huang. Swiper: Exploiting virtual machine vulnerability in third-party clouds with competition for I/O resources. IEEE Trans. on Parallel and Distributed Systems (TPDS), 26(6), 2015
2015
-
[19]
Obladi: Oblivious serializable transac- tions in the cloud
Natacha Crooks, Matthew Burke, Ethan Cecchetti, Sitar Harel, Rachit Agarwal, and Lorenzo Alvisi. Obladi: Oblivious serializable transac- tions in the cloud. In USENIX Symposium on Operating Systems Design and Implementation (OSDI), 2018
2018
-
[20]
Traffic Analysis of the HTTP Protocol over TLS
George Danezis. Traffic Analysis of the HTTP Protocol over TLS. http://www0.cs.ucl.ac.uk/staff/G.Danezis/papers/ TLSanon.pdf, 2009. 13
2009
-
[21]
Peek-a-boo, I still see you: Why efficient traffic analysis coun- termeasures fail
Kevin P Dyer, Scott E Coull, Thomas Ristenpart, and Thomas Shrimp- ton. Peek-a-boo, I still see you: Why efficient traffic analysis coun- termeasures fail. In IEEE Symposium on Security and Privacy (SP) , 2012.[22] Kevin P Dyer, Scott E Coull, Thomas Ristenpart, and Thomas Shrim...
2012
-
[23]
An oblivious general-purpose SQL database for the cloud
Saba Eskandarian and Matei Zaharia. An oblivious general-purpose SQL database for the cloud. CoRR, abs/1710.00458, 2017
2017 arXiv
-
[24]
Jump over ASLR: Attacking branch predictors to bypass ASLR
Dmitry Evtyushkin, Dmitry Ponomarev, and Nael Abu-Ghazaleh. Jump over ASLR: Attacking branch predictors to bypass ASLR. InIEEE/ACM Intl. Symposium on Microarchitecture (MICRO), 2016
2016
-
[25]
Suppressing the oblivious ram tim- ing channel while making information leakage and program efficiency trade-offs
Christopher W Fletchery, Ling Ren, Xiangyao Yu, Marten Van Dijk, Omer Khan, and Srinivas Devadas. Suppressing the oblivious ram tim- ing channel while making information leakage and program efficiency trade-offs. In IEEE International Symposium on High Performance Computer Arch...
2014
-
[26]
A survey of microarchitectural timing attacks and countermeasures on contemporary hardware
Qian Ge, Yuval Yarom, David Cock, and Gernot Heiser. A survey of microarchitectural timing attacks and countermeasures on contemporary hardware. Journal of Cryptographic Engineering, 2016
2016
-
[27]
Accessed 31 Aug 2020
2020
-
[28]
Website detection using remote traffic analysis
Xun Gong, Nikita Borisov, Negar Kiyavash, and Nabil Schear. Website detection using remote traffic analysis. In Privacy Enhancing Technolo- gies Symposium (PETS), 2012
2012
-
[29]
Quantifying the information leakage in timing side channels in deterministic work-conserving schedulers
Xun Gong and Negar Kiyavash. Quantifying the information leakage in timing side channels in deterministic work-conserving schedulers. IEEE/ACM Trans. on Networking (TON), 24(3), 2016
2016
-
[30]
k-fingerprinting: A robust scalable website fingerprinting technique
Jamie Hayes and George Danezis. k-fingerprinting: A robust scalable website fingerprinting technique. In USENIX Security Symposium, 2016
2016
-
[31]
Fingerprinting websites using traffic analysis
Andrew Hintz. Fingerprinting websites using traffic analysis. In Conf. on Privacy Enhancing Technologies (PETS), 2002
2002
-
[32]
Seriously, get off my cloud! cross- vm rsa key recovery in a public cloud
Mehmet Sinan Inci, Berk Gülmezoglu, Gorka Irazoqui Apecechea, Thomas Eisenbarth, and Berk Sunar. Seriously, get off my cloud! cross- vm rsa key recovery in a public cloud. IACR Cryptology ePrint Archive, 2015(1-15), 2015
2015
-
[33]
Efficient, adversarial neighbor discovery using logical channels on microsoft azure
Mehmet Sinan ˙Inci, Gorka Irazoqui, Thomas Eisenbarth, and Berk Sunar. Efficient, adversarial neighbor discovery using logical channels on microsoft azure. In Annual Conf. on Computer Security Applications (ACSAC), 2016
2016
-
[34]
S$A: A Shared Cache Attack That Works across Cores and Defies VM Sandboxing–and Its Application to AES
Gorka Irazoqui, Thomas Eisenbarth, and Berk Sunar. S$A: A Shared Cache Attack That Works across Cores and Defies VM Sandboxing–and Its Application to AES. In IEEE Symposium on Security and Privacy (SP), 2015
2015
-
[35]
Silo: Predictable message latency in the cloud
Keon Jang, Justine Sherry, Hitesh Ballani, and Toby Moncaster. Silo: Predictable message latency in the cloud. In ACM Conf. on Special Interest Group on Data Communication (SIGCOMM), 2015
2015
-
[36]
Miti- gating timing side channel in shared schedulers
Sachin Kadloor, Negar Kiyavash, and Parv Venkitasubramaniam. Miti- gating timing side channel in shared schedulers. IEEE/ACM Trans. on Networking (TON), 24(3), 2016
2016
-
[37]
Adam: A Method for Stochastic Optimization
Diederik P Kingma and Jimmy Ba. Adam: A Method for Stochastic Optimization. http://arxiv.org/abs/1412.6980, 2014
2014 arXiv
-
[38]
Timing attacks on implementations of Diffie-Hellman, RSA, DSS, and other systems
Paul Kocher. Timing attacks on implementations of Diffie-Hellman, RSA, DSS, and other systems. In Advances in Cryptology – CRYPTO, 1996.[38] Adam Langley, Alistair Riddoch, Alyssa Wilk, Antonio Vicente, Charles Krasic, Dan Zhang, Fan Yang, Fedor Kouranov, Ian Swett, Janardhan I...
1996
-
[39]
Karaoke: Distributed private messaging immune to passive traffic analysis
David Lazar, Yossi Gilad, and Nickolai Zeldovich. Karaoke: Distributed private messaging immune to passive traffic analysis. InUSENIX Sympo- sium on Operating Systems Design and Implementation (OSDI), 2018
2018
-
[40]
Yodel: strong metadata security for voice calls
David Lazar, Yossi Gilad, and Nickolai Zeldovich. Yodel: strong metadata security for voice calls. In ACM Symposium on Operating Systems Principles (SOSP), 2019
2019
-
[41]
Herd: A scalable, traffic analysis resistant anonymity network for V oIP systems
Stevens Le Blond, David Choffnes, William Caldwell, Peter Druschel, and Nicholas Merritt. Herd: A scalable, traffic analysis resistant anonymity network for V oIP systems. In ACM Conf. on Special In- terest Group on Data Communication (SIGCOMM), 2015
2015
-
[42]
Stopwatch: a cloud archi- tecture for timing channel mitigation
Peng Li, Debin Gao, and Michael K Reiter. Stopwatch: a cloud archi- tecture for timing channel mitigation. ACM Trans. on Information and System Security (TISSEC), 17(2), 2014
2014
-
[43]
Measuring information leakage in website fingerprinting attacks and defenses
Shuai Li, Huajun Guo, and Nicholas Hopper. Measuring information leakage in website fingerprinting attacks and defenses. In ACM Conf. on Computer and Communications Security (CCS), 2018
2018
-
[44]
Last-level cache side-channel attacks are practical
Fangfei Liu, Yuval Yarom, Qian Ge, Gernot Heiser, and Ruby B Lee. Last-level cache side-channel attacks are practical. In IEEE Symposium on Security and Privacy (SP), 2015
2015
-
[45]
On-demand time blurring to support side-channel defense
Weijie Liu, Debin Gao, and Michael K Reiter. On-demand time blurring to support side-channel defense. In European Symposium on Research in Computer Security (ESORICS), 2017
2017
-
[46]
Shroud: Ensuring private access to large-scale data in the data center
Jacob R Lorch, Bryan Parno, James Mickens, Mariana Raykova, and Joshua Schiffman. Shroud: Ensuring private access to large-scale data in the data center. InUSENIX Conference on File and Storage Technologies (FAST), 2013
2013
-
[47]
Dynaflow: An efficient website fingerprinting defense based on dynamically- adjusting flows
David Lu, Sanjit Bhat, Albert Kwon, and Srinivas Devadas. Dynaflow: An efficient website fingerprinting defense based on dynamically- adjusting flows. In Workshop on Privacy in the Electronic Society (WPES), 2018
2018
-
[48]
HTTPOS: Sealing Information Leaks with Browser-side Obfuscation of Encrypted Flows
Xiapu Luo, Peng Zhou, Edmond WW Chan, Wenke Lee, Rocky KC Chang, and Roberto Perdisci. HTTPOS: Sealing Information Leaks with Browser-side Obfuscation of Encrypted Flows. In Network and Distributed System Security Symposium (NDSS), volume 11, 2011
2011
-
[49]
Timewarp: Rethinking timekeeping and performance monitoring mechanisms to mitigate side-channel attacks
Robert Martin, John Demme, and Simha Sethumadhavan. Timewarp: Rethinking timekeeping and performance monitoring mechanisms to mitigate side-channel attacks. In Intl. Symposium on Computer Archi- tecture (ISCA), 2012
2012
-
[50]
Skypemorph: Protocol obfuscation for tor bridges
Hooman Mohajeri Moghaddam, Baiyu Li, Mohammad Derakhshani, and Ian Goldberg. Skypemorph: Protocol obfuscation for tor bridges. In ACM Conf. on Computer and Communications Security (CCS), 2012
2012
-
[51]
Glove: A bespoke website fingerprinting defense
Rishab Nithyanand, Xiang Cai, and Rob Johnson. Glove: A bespoke website fingerprinting defense. In Workshop on Privacy in the Electronic Society (WPES), 2014
2014
-
[52]
Scheduling I/O in virtual machine monitors
Diego Ongaro, Alan L Cox, and Scott Rixner. Scheduling I/O in virtual machine monitors. In ACM SIGPLAN/SIGOPS Intl. Conf. on Virtual Execution Environments (VEE), 2008
2008
-
[53]
Website fingerprinting in onion routing based anonymization networks
Andriy Panchenko, Lukas Niessen, Andreas Zinnen, and Thomas Engel. Website fingerprinting in onion routing based anonymization networks. In ACM Workshop on Privacy in the Electronic Society (WPES), 2011
2011
-
[54]
DRAMA: Exploiting DRAM Addressing for Cross- CPU Attacks
Peter Pessl, Daniel Gruss, Clementine Maurice, Michael Schwarz, and Stefan Mangard. DRAMA: Exploiting DRAM Addressing for Cross- CPU Attacks. In USENIX Security Symposium, 2016
2016
-
[55]
Who Is Your Neighbor: Net I/O Perfor- mance Interference in Virtualized Clouds
Xing Pu, Ling Liu, Yiduo Mei, Sankaran Sivathanu, Younggyun Koh, Calton Pu, and Yuanda Cao. Who Is Your Neighbor: Net I/O Perfor- mance Interference in Virtualized Clouds. IEEE Trans. on Services Computing, 6(3), 2013
2013
-
[56]
A Hardware/Software Approach for Miti- gating Performance Interference Effects in Virtualized Environments Using SR-IOV
Andre Richter, Christian Herber, Stefan Wallentowitz, Thomas Wild, and Andreas Herkersdorf. A Hardware/Software Approach for Miti- gating Performance Interference Effects in Virtualized Environments Using SR-IOV. In IEEE Intl. Conf. on Cloud Computing (CLOUD) , 2015
2015
-
[57]
Hey, You, Get off of My Cloud: Exploring Information Leakage in Third-party Compute Clouds
Thomas Ristenpart, Eran Tromer, Hovav Shacham, and Stefan Savage. Hey, You, Get off of My Cloud: Exploring Information Leakage in Third-party Compute Clouds. In ACM Conf. on Computer and Commu- nications Security (CCS), 2009
2009
-
[58]
Devices that tell on you: Privacy trends in con- sumer ubiquitous computing
T Scott Saponas, Jonathan Lester, Carl Hartung, Sameer Agarwal, Ta- dayoshi Kohno, et al. Devices that tell on you: Privacy trends in con- sumer ubiquitous computing. In USENIX Security Symposium, 2007
2007
-
[59]
Beauty and the Burst: Remote Identification of Encrypted Video Streams
Roei Schuster, Vitaly Shmatikov, and Eran Tromer. Beauty and the Burst: Remote Identification of Encrypted Video Streams. In USENIX Security Symposium, 2017
2017
-
[60]
Net- Spectre: Read Arbitrary Memory over Network
Michael Schwarz, Martin Schwarzl, Moritz Lipp, and Daniel Gruss. Net- Spectre: Read Arbitrary Memory over Network. CoRR, abs/1807.10535, 2018
2018 arXiv
-
[61]
Principles of secure information flow analysis
Geoffrey Smith. Principles of secure information flow analysis. In Mihai Christodorescu, Somesh Jha, Douglas Maughan, Dawn Song, and Cliff Wang, editors, Malware Detection, volume 27 of Advances in Information Security, pages 291–307. Springer, 2007
2007
-
[62]
Timing anal- ysis of keystrokes and timing attacks on ssh
Dawn Xiaodong Song, David Wagner, and Xuqing Tian. Timing anal- ysis of keystrokes and timing attacks on ssh. In USENIX Security Symposium, 2001
2001
-
[63]
Simon, Yi-Min Wang, Wilf Russell, Venkata N
Qixiang Sun, Daniel R. Simon, Yi-Min Wang, Wilf Russell, Venkata N. Padmanabhan, and Lili Qiu. Statistical identification of encrypted web browsing traffic. In IEEE Symposium on Security and Privacy (SP) , 2002
2002
-
[64]
Tor: The Second-Generation Onion Router
Paul Syverson, Roger Dingledine, and Nick Mathewson. Tor: The Second-Generation Onion Router. In Usenix Security, 2004
2004
-
[65]
Vuvuzela: Scalable private messaging resistant to traffic analy- sis
Jelle Van Den Hooff, David Lazar, Matei Zaharia, and Nickolai Zel- dovich. Vuvuzela: Scalable private messaging resistant to traffic analy- sis. In Symposium on Operating Systems Principles (SOSP), 2015
2015
-
[66]
Scheduler-based defenses against cross-vm side-channels
Venkatanathan Varadarajan, Thomas Ristenpart, and Michael M Swift. Scheduler-based defenses against cross-vm side-channels. In USENIX Security Symposium, 2014
2014
-
[67]
Eliminating fine grained timers in xen
Bhanu C Vattikonda, Sambit Das, and Hovav Shacham. Eliminating fine grained timers in xen. In ACM workshop on Cloud Computing Security Workshop, 2011
2011
-
[68]
Practical TDMA for Datacenter Ethernet
Bhanu Chandra Vattikonda, George Porter, Amin Vahdat, and Alex C Snoeren. Practical TDMA for Datacenter Ethernet. In ACM European Conference on Computer Systems (EuroSys), 2012
2012
-
[69]
Loophole: Timing attacks on shared event loops in chrome
Pepe Vila and Boris Köpf. Loophole: Timing attacks on shared event loops in chrome. In USENIX Security Symposium, 2017. 14
2017
-
[70]
Effective attacks and provable defenses for website fingerprinting
Tao Wang, Xiang Cai, Rishab Nithyanand, Rob Johnson, and Ian Gold- berg. Effective attacks and provable defenses for website fingerprinting. In USENIX Security Symposium, 2014
2014
-
[71]
Walkie-talkie: An efficient defense against passive website fingerprinting attacks
Tao Wang and Ian Goldberg. Walkie-talkie: An efficient defense against passive website fingerprinting attacks. In USENIX Security Symposium, 2017
2017
-
[72]
Scramblesuit: A poly- morphic network protocol to circumvent censorship
Philipp Winter, Tobias Pulls, and Juergen Fuss. Scramblesuit: A poly- morphic network protocol to circumvent censorship. In ACM Workshop on Privacy in the Electronic Society (WPES), 2013
2013
-
[73]
Spot me if you can: Uncovering spoken phrases in encrypted V oIP conversations
Charles V Wright, Lucas Ballard, Scott E Coull, Fabian Monrose, and Gerald M Masson. Spot me if you can: Uncovering spoken phrases in encrypted V oIP conversations. InIEEE Symposium on Security and Privacy (SP), 2008
2008
-
[74]
Wright, Scott E
Charles V . Wright, Scott E. Coull, and Fabian Monrose. Traffic morph- ing: An efficient defense against statistical traffic analysis. In Network and Distributed System Security Symposium (NDSS), 2009
2009
-
[75]
On inferring application protocol behaviors in encrypted network traffic
Charles V Wright, Fabian Monrose, and Gerald M Masson. On inferring application protocol behaviors in encrypted network traffic. Journal of Machine Learning Research (JMLR), 7, Dec 2006
2006
-
[76]
Deterministically deterring timing attacks in deterland
Weiyi Wu and Bryan Ford. Deterministically deterring timing attacks in deterland. arXiv preprint arXiv:1504.07070, 2015
2015 arXiv
-
[77]
Controlled-channel attacks: Deterministic side channels for untrusted operating systems
Yuanzhong Xu, Weidong Cui, and Marcus Peinado. Controlled-channel attacks: Deterministic side channels for untrusted operating systems. In IEEE Symposium on Security and Privacy (SP), 2015
2015
-
[78]
FLUSH+RELOAD: A High Resolu- tion, Low Noise, L3 Cache Side-Channel Attack
Yuval Yarom and Katrina Falkner. FLUSH+RELOAD: A High Resolu- tion, Low Noise, L3 Cache Side-Channel Attack. In USENIX Security Symposium, 2014
2014
-
[79]
CacheBleed: a tim- ing attack on OpenSSL constant-time RSA
Yuval Yarom, Daniel Genkin, and Nadia Heninger. CacheBleed: a tim- ing attack on OpenSSL constant-time RSA. Journal of Cryptographic Engineering, 7(2), 2017
2017
-
[80]
Predictive Mitigation of Timing Channels in Interactive Systems
Danfeng Zhang, Aslan Askarov, and Andrew C Myers. Predictive Mitigation of Timing Channels in Interactive Systems. In ACM Conf. on Computer and Communications Security (CCS), 2011
2011
-
[81]
Cross-VM side channels and their use to extract private keys
Yinqian Zhang, Ari Juels, Michael K Reiter, and Thomas Ristenpart. Cross-VM side channels and their use to extract private keys. In ACM Conf. on Computer and Communications Security (CCS), 2012
2012
-
[82]
Mitts: Memory inter-arrival time traffic shaping
Yanqi Zhou and David Wentzlaff. Mitts: Memory inter-arrival time traffic shaping. ACM SIGARCH Computer Architecture News, 44(3), 2016. A. Network Side-Channel Attack Here, we briefly describe a proof-of-concept NSC attack. To carry out such an attack, an adversary must be able t...
2016
-
[83]
Environment acts The environment acts by consuming a subset of events in the queue QE, processing them to update its internal state and adding new events to the queue QG
and FE(QE2, σE2, Tg) = (QE′ 2, QG′′ 2, σE′ 2) ⇒ QE′ 1∼ QE′ 2 and QG′′ 1∼ QG′′ 2 and σE′ 1∼ σE′ 2 Transition FE(QE, σE, Tg) = (QE ′, QG ′′, σE ′) (σE, σG, σH, QG, QH, QE, Tg) ↝E (σE ′, σG, σH, QG∪ QG ′′, QH, QE ′, Tg) env Figure 10: Assumptions and transition of the environment...
-
[84]
Tui≤ Tei (4) FG(QG, Temax, Qp H, σG, Tg) = (QG′, Qu H ′′, Temax′, Qp H ′, σG′) ⇒ Iemax(Qu H ′′, Temax′) where Iemax(Qu H, Temax)≜∀(f↦→ U)∈ Qu H.∀(Tui, Eui, Tei)∈ U
and FG(QG2, Temax2, Qp H2, σG2, Tg) = (QG′ 2, Qu H ′′ 2, Temax′ 2, Qp H ′ 2, σG′ 2) ⇒ QG′ 1∼ QG′ 2 and Qu H ′′ 1∼ Qu H ′′ 2 and σG′ 1∼ σG′ 2 (3) FG(QG, Temax, Qp H, σG, Tg) = (QG′, Qu H ′, Temax′, Qp H ′, σG′) ⇒ Idelay(Qu H ′) where Idelay(Qu H)≜∀(f↦→ U)∈ Qu H.∀(Tui, Eui, Tei)...
-
[85]
(Non-consumption of future inputs) FG should not remove future events from its input queue, QG
and Fo H(Qp H2,s2) = (Qp H ′ 2, QE′′ 2) ⇒ QE′′ 1∼ QE′′ 2 Transition σH ={flowi↦→ Φi}N i=1 Qu H ={flowi↦→ Ui}N i=1 (Φ′ i, U′ i) = update_prof(Φi, Ui, Tg) σH ′←{ flowi↦→ Φ′ i}N i=1 [σH ′]Tg≜{flowi↦→ [Φ′ i]Tg}N i=1 Fo H(Qp H, [σH ′]Tg) = (Qp H ′, QE ′′) Qu H ′←{ flowi↦→ U′ i}N i=...
-
[86]
QE1∼ QE2 by assump- tion about the invariant holding before the transition, so we only need to prove that QE′′ 1∼ QE′′
-
[87]
We already know from the invariant be- fore the transition that Tg1 = Tg2 = Tg (say) and, following the definition of [σH′]Tg, we only need to show that for every i∈{ 1,
Now, again following the rule, QE′′ i (for i = 1,2) is obtained from the function Fo H, so by assumption (7) of Figure 13, we only need to show that [σH′ 1]Tg1 = [σH′ 2]Tg2. We already know from the invariant be- fore the transition that Tg1 = Tg2 = Tg (say) and, following the...
Reviewed August 14, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.