Fetching the paper…
Reading the bibliography…
In this paper, we explore a new, yet critical, side-channel attack against Intel Software Guard Extension (SGX), called a branch shadowing attack, which can reveal fine-grained control flows (i.e., each branch) of an enclave program running on real SGX hardware.
S. McFarling, “Combining branch predictors,” 1993
1993
Earlier work this paper cites.
P. C. Kocher, “Timing attacks on implementations of diffie-hellman, rsa, dss, and other systems,” in Annual International Cryptology Conference , 1996
1996
Earlier work this paper cites.
J. Kelsey, B. Schneier, D. Wagner, and C. Hall, “Side channel cryptanalysis of product ciphers,” in Proceedings of the 5th European Symposium on Research in Computer Security (ESORICS) , Belgium, Sep. 1998
1998
Earlier work this paper cites.
S. M. Hand, “Self-paging in the Nemesis operating system,” in Proceedings of the 3rd USENIX Symposium on Operating Systems Design and Implementation (OSDI) , New Orleans, LA, Feb. 1999
1999
Earlier work this paper cites.
D. Page, “Theoretical use of cache memory as a cryptanalytic side-channel.” IACR Cryptology ePrint Archive , 2002
2002
Earlier work this paper cites.
D. Brumley and D. Boneh, “Remote timing attacks are practical,” in Proceedings of the 12th USENIX Security Symposium (Security) , Washington, DC, Aug. 2003
2003
Earlier work this paper cites.
O. Aciicmez, K. Koc, and J. Seifert, “On the power of simple branch prediction analysis,” in Proceedings of the 2nd ACM Symposium on Information, Computer and Communications Security (ASIACCS) , 2007
2007
Earlier work this paper cites.
T. Ristenpart, E. Tromer, H. Shacham, and S. Savage, “Hey, you, get off of my cloud: exploring information leakage in third-party compute clouds,” in Proceedings of the 16th ACM Conference on Computer and Communications Security (CCS) , Chicago, IL, Nov. 2009
2009
Earlier work this paper cites.
V. Uzelac and A. Milenkovic, “Experiment flows and microbenchmarks for reverse engineering of branch predictor structures,” in Performance Analysis of Systems and Software, 2009. ISPASS 2009. IEEE International Symposium on . IEEE, 2009, pp. 207–217
2009
Earlier work this paper cites.
2011
Earlier work this paper cites.
C. Giuffrida, A. Kuijsten, and A. S. Tanenbaum, “Enhanced operating system security through efficient and fine-grained address space randomization,” in Proceedings of the 21st USENIX Security Symposium (Security) , Bellevue, WA, Aug. 2012
2012
Earlier work this paper cites.
R. Hund, C. Willems, and T. Holz, “Practical timing side channel attacks against kernel space ASLR,” in Proceedings of the 34th IEEE Symposium on Security and Privacy (Oakland) , San Francisco, CA, May 2013
2013
Earlier work this paper cites.
M. Maas, E. Love, E. Stefanov, M. Tiwari, E. Shi, K. Asanović, J. Kubiatowicz, and D. Song, “PHANTOM: Practical oblivious computation in a secure processor,” in Proceedings of the 20th ACM Conference on Computer and Communications Security (CCS) , Berlin, Germany, Oct. 2013
2013
Earlier work this paper cites.
E. Stefanov, M. Van Dijk, E. Shi, C. Fletcher, L. Ren, X. Yu, and S. Devadas, “Path ORAM: An extremely simple oblivious RAM protocol,” in Proceedings of the 20th ACM Conference on Computer and Communications Security (CCS) , Berlin, Germany, Oct. 2013
2013
Earlier work this paper cites.
A. Baumann, M. Peinado, and G. Hunt, “Shielding applications from an untrusted cloud with Haven,” in Proceedings of the 11th USENIX Symposium on Operating Systems Design and Implementation (OSDI) , Broomfield, Colorado, Oct. 2014
2014
Earlier work this paper cites.
——, “Intel software guard extensions programming reference (rev2),” Oct. 2014, 329298-002US
2014
Earlier work this paper cites.
R. A. Popa, “Building practical systems that compute on encrypted data,” Ph.D. dissertation, Massachusetts Institute of Technology, 2014
2014
Earlier work this paper cites.
T. T. A. Dinh, P. Saxena, E.-C. Cang, B. C. Ooi, and C. Zhang, “M2R: Enabling stronger privacy in MapReduce computation,” in Proceedings of the 24th USENIX Security Symposium (Security) , Washington, DC, Aug. 2015
2015
Earlier work this paper cites.
D. Evtyushkin, D. Ponomarev, and N. Abu-Ghazalch, “Covert channels through branch predictors: A feasibility study,” in Proceedings of the 4th Workshop on Hardware and Architectural Support for Security and Privacy (HASP) , 2015
2015
Earlier work this paper cites.
G. Irazoqui, T. Eisenbarth, and B. Sunar, “S$A: A shared cache attack that works across cores and defies VM sandboxing—and its application to AES,” in Proceedings of the 36th IEEE Symposium on Security and Privacy (Oakland) , San Jose, CA, May 2015
2015
Cited alongside, same era.
C. Liu, A. Harris, M. Maas, M. Hicks, M. Tiwari, and E. Shi, “GhostRider: A hardware-software system for memory trace oblivious computation,” in Proceedings of the 20th ACM International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS) , Istanbul, Turkey, Mar. 2015
2015
Cited alongside, same era.
F. Liu, Y. Yarom, Q. Ge, G. Heiser, and R. B. Lee, “Last-level cache side-channel attacks are practical,” in Proceedings of the 36th IEEE Symposium on Security and Privacy (Oakland) , San Jose, CA, May 2015
2015
Cited alongside, same era.
M. Naveed, S. Kamara, and C. V. Wright, “Inference attacks on property-preserving encrypted databases,” in Proceedings of the 22nd ACM Conference on Computer and Communications Security (CCS) , Denver, Colorado, Oct. 2015
Y. Jang, S. Lee, and T. Kim, “Breaking kernel address space layout randomization with Intel TSX,” in Proceedings of the 23rd ACM Conference on Computer and Communications Security (CCS) , Vienna, Austria, Oct. 2016
2016
Closest in time.
S. Johnson, V. Scarlata, C. Rozas, E. Brickell, and F. Mckeen, “Intel software guard extensions: EPID provisioning and attestation services,” https://software.intel.com/en-us/blogs/2016/03/09/intel-sgx-epid-provisioning-and-attestation-services
2016
Closest in time.
A. Kleen, “Advanced usage of last branch records,” 2016, https://lwn.net/Articles/680996/
2016
Closest in time.
——, “An introduction to last branch records,” 2016, https://lwn.net/Articles/680985/
2016
Closest in time.
K. Lu, C. Song, T. Kim, and W. Lee, “UniSan: Proactive kernel memory initialization to eliminate data leakages,” in Proceedings of the 23rd ACM Conference on Computer and Communications Security (CCS) , Vienna, Austria, Oct. 2016
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2015
Cited alongside, same era.
A. Rane, C. Lin, and M. Tiwari, “Raccoon: Closing digital side-channels through obfuscated execution,” in Proceedings of the 24th USENIX Security Symposium (Security) , Washington, DC, Aug. 2015
2015
Cited alongside, same era.
F. Schuster, M. Costa, C. Fournet, C. Gkantsidis, M. Peinado, G. Mainar-Ruiz, and M. Russinovich, “VC3: Trustworthy data analytics in the cloud using SGX,” in Proceedings of the 36th IEEE Symposium on Security and Privacy (Oakland) , San Jose, CA, May 2015
2015
Cited alongside, same era.
R. Sinha, S. Rajamani, S. Seshia, and K. Vaswani, “Moat: Verifying confidentiality of enclave program,” in Proceedings of the 22nd ACM Conference on Computer and Communications Security (CCS) , Denver, Colorado, Oct. 2015
2015
Cited alongside, same era.
Y. Xu, W. Cui, and M. Peinado, “Controlled-channel attacks: Deterministic side channels for untrusted operating systems,” in Proceedings of the 36th IEEE Symposium on Security and Privacy (Oakland) , San Jose, CA, May 2015
2015
Cited alongside, same era.
“The BTB in contemporary Intel chips—Matt Godbolt’s blog,” http://xania.org/201602/bpu-part-three , (Accessed on 11/10/2016)
2016
Cited alongside, same era.
S. Arnautox, B. Tarch, F. Gregor, T. Knauth, A. Martin, C. Priebe, , J. Lind, D. Muthukumaran, D. O’Keeffe, M. L. Stillwell, D. Goltzsche, D. Eyers, R. Kapitza, P. Pietzuch, and C. Fetzer, “SCONE: Secure Linux containers with Intel SGX,” in Proceedings of the 12th USENIX Symposium on Operating Systems Design and Implementation (OSDI) , Savannah, GA, Nov. 2016
2016
Cited alongside, same era.
S. Brenner, C. Wulf, M. Lorenz, N. Weichbrodt, D. Goltzsche, C. Fetzer, P. Pietzuch, and R. Kapitza, “SecureKeeper: Confidential ZooKeeper using Intel SGX,” in Proceedings of the 16th Annual Middleware Conference (Middleware) , 2016
2016
Cited alongside, same era.
V. Costan and S. Devadas, “Intel SGX explained,” Cryptology ePrint Archive, Report 2016/086, 2016, http://eprint.iacr.org/2016/086.pdf
2016
Cited alongside, same era.
2016
Closest in time.
O. Ohrimenko, C. F. Manuel Costa, S. Nowozin, A. Mehta, F. Schuster, and K. Vaswani, “SGX-enabled oblivious machine learning,” in Proceedings of the 25th USENIX Security Symposium (Security) , Austin, TX, Aug. 2016
2016
Closest in time.
R. Pires, M. Pasin, P. Felber, and C. Fetzer, “Secure content-based routing using Intel Software Guard Extensions,” in Proceedings of the 16th Annual Middleware Conference (Middleware) , 2016
2016
Closest in time.
D. Pouliot and C. V. Wright, “The shadow nemesis: Inference attacks on efficiently deployable, efficiently searchable encryption,” in Proceedings of the 23rd ACM Conference on Computer and Communications Security (CCS) , Vienna, Austria, Oct. 2016
2016
Closest in time.
Q.Ge, Y. Yarom, D. Cock, and G. Heiser, “A survey of microarchitectural timing attacks and countermeasures on contemporary hardware,” Cryptology ePrint Archive, Report 2016/613, 2016, http://eprint.iacr.org/2016/613.pdf
2016
Closest in time.
M.-W. Shih, M. Kumar, T. Kim, and A. Gavrilovska, “S-NFV: Securing NFV states by using SGX,” in Proceedings of the 1st ACM International Workshop on Security in SDN and NFV , New Orleans, LA, Mar. 2016
2016
Closest in time.
S. Shinde, Z. L. Chua, V. Narayanan, and P. Saxena, “Preventing your faults from telling your secrets,” in Proceedings of the 11th ACM Symposium on Information, Computer and Communications Security (ASIACCS) , Xi’an, China, May–Jun. 2016
2016
Closest in time.
R. Sinha, M. Costa, A. Lal, N. P. Lopes, S. Rajamani, S. A. Seshia, and K. Vaswani, “A design and verification methodology for secure isolated regions,” in Proceedings of the 2016 ACM SIGPLAN Conference on Programming Language Design and Implementation (PLDI) , Santa Barbara, CA, Jun. 2016
2016
Closest in time.
C. Song, B. Lee, K. Lu, W. R. Harris, T. Kim, and W. Lee, “Enforcing Kernel Security Invariants with Data Flow Integrity,” in Proceedings of the 23rd Annual Network and Distributed System Security Symposium (NDSS) , San Diego, CA, Feb. 2016
2016
Closest in time.
A. Waterman, Y. Lee, R. Avizienis, D. A. Patterson, and K. Asanović, “The RISC-V instruction set manual volume II: Privileged architecture version 1.9,” EECS Department, University of California, Berkeley, Tech. Rep. UCB/EECS-2016-129, Jul 2016. [Online]. Available: http://www2.eecs.berkeley.edu/Pubs/TechRpts/2016/EECS-2016-129.html
2016
Closest in time.
A. Waterman, Y. Lee, D. A. Patterson, and K. Asanović, “The RISC-V instruction set manual, volume I: User-level ISA, version 2.1,” EECS Department, University of California, Berkeley, Tech. Rep. UCB/EECS-2016-118, May 2016. [Online]. Available: http://www2.eecs.berkeley.edu/Pubs/TechRpts/2016/EECS-2016-118.html
2016
Closest in time.
N. Weichbrodt, A. Kurmus, P. Pietzuch, and R. Kapitza, “AsyncShock: Exploiting synchronisation bugs in Intel SGX enclaves,” in Proceedings of the 21th European Symposium on Research in Computer Security (ESORICS) , Heraklion, Greece, Sep. 2016
2016
Closest in time.
K. Yang, M. Hicks, Q. Dong, T. Austin, and D. Sylvester, “A2: Analog malicious hardware,” in Proceedings of the 37th IEEE Symposium on Security and Privacy (Oakland) , San Jose, CA, May 2016
2016
Closest in time.
J. Seo, B. Lee, S. Kim, M.-W. Shih, I. Shin, D. Han, and T. Kim, “SGX-Shield: Enabling address space layout randomization for SGX programs (to appear),” in Proceedings of the 2017 Annual Network and Distributed System Security Symposium (NDSS) , San Diego, CA, Feb.–Mar. 2017
2017
Closest in time.
M.-W. Shih, S. Lee, T. Kim, and M. Peinado, “T-SGX: Eradicating controlled-channel attacks against enclave programs (to appear),” in Proceedings of the 2017 Annual Network and Distributed System Security Symposium (NDSS) , San Diego, CA, Feb.–Mar. 2017
2017
Closest in time.