Skip to main content

Stop watch: A cloud architecture for timing channel mitigation

Publication ,  Journal Article
Li, P; Gao, D; Reiter, MK
Published in: ACM Transactions on Information and System Security
November 1, 2014

This article presents StopWatch, a system that defends against timing-based side-channel attacks that arise from coresidency of victims and attackers in infrastructure-as-a-service clouds. StopWatch triplicates each cloud-resident guest virtual machine (VM) and places replicas so that the three replicas of a guest VM are coresident with nonoverlapping sets of (replicas of) other VMs. StopWatch uses the timing of I/O events at a VM's replicas collectively to determine the timings observed by each one or by an external observer, so that observable timing behaviors are similarly likely in the absence of any other individual, coresident VMs. We detail the design and implementation of StopWatch in Xen, evaluate the factors that influence its performance, demonstrate its advantages relative to alternative defenses against timing side channels with commodity hardware, and address the problem of placing VM replicas in a cloud under the constraints of StopWatch so as to still enable adequate cloud utilization.

Duke Scholars

Published In

ACM Transactions on Information and System Security

DOI

EISSN

1557-7406

ISSN

1094-9224

Publication Date

November 1, 2014

Volume

17

Issue

2

Related Subject Headings

  • Strategic, Defence & Security Studies
  • 4609 Information systems
  • 4604 Cybersecurity and privacy
  • 0806 Information Systems
  • 0804 Data Format
  • 0803 Computer Software
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Li, P., Gao, D., & Reiter, M. K. (2014). Stop watch: A cloud architecture for timing channel mitigation. ACM Transactions on Information and System Security, 17(2). https://doi.org/10.1145/2670940
Li, P., D. Gao, and M. K. Reiter. “Stop watch: A cloud architecture for timing channel mitigation.” ACM Transactions on Information and System Security 17, no. 2 (November 1, 2014). https://doi.org/10.1145/2670940.
Li P, Gao D, Reiter MK. Stop watch: A cloud architecture for timing channel mitigation. ACM Transactions on Information and System Security. 2014 Nov 1;17(2).
Li, P., et al. “Stop watch: A cloud architecture for timing channel mitigation.” ACM Transactions on Information and System Security, vol. 17, no. 2, Nov. 2014. Scopus, doi:10.1145/2670940.
Li P, Gao D, Reiter MK. Stop watch: A cloud architecture for timing channel mitigation. ACM Transactions on Information and System Security. 2014 Nov 1;17(2).

Published In

ACM Transactions on Information and System Security

DOI

EISSN

1557-7406

ISSN

1094-9224

Publication Date

November 1, 2014

Volume

17

Issue

2

Related Subject Headings

  • Strategic, Defence & Security Studies
  • 4609 Information systems
  • 4604 Cybersecurity and privacy
  • 0806 Information Systems
  • 0804 Data Format
  • 0803 Computer Software