Skip to main content

Mitigating access-driven timing channels in clouds using StopWatch

Publication ,  Conference
Li, P; Gao, D; Reiter, MK
Published in: Proceedings of the International Conference on Dependable Systems and Networks
September 9, 2013

This paper presents StopWatch , a system that defends against timing-based side-channel attacks that arise from coresidency of victims and attackers in infrastructure-as-a-service clouds. StopWatch triplicates each cloud-resident guest virtual machine (VM) and places replicas so that the three replicas of a guest VM are coresident with nonoverlapping sets of (replicas of) other VMs. StopWatch uses the timing of I/O events at a VM's replicas collectively to determine the timings observed by each one or by an external observer, so that observable timing behaviors are similarly likely in the absence of any other individual, coresident VM. We detail the design and implementation of StopWatch in Xen, evaluate the factors that influence its performance, and address the problem of placing VM replicas in a cloud under the constraints of StopWatch so as to still enable adequate cloud utilization. © 2013 IEEE.

Duke Scholars

Published In

Proceedings of the International Conference on Dependable Systems and Networks

DOI

Publication Date

September 9, 2013
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Li, P., Gao, D., & Reiter, M. K. (2013). Mitigating access-driven timing channels in clouds using StopWatch. In Proceedings of the International Conference on Dependable Systems and Networks. https://doi.org/10.1109/DSN.2013.6575299
Li, P., D. Gao, and M. K. Reiter. “Mitigating access-driven timing channels in clouds using StopWatch.” In Proceedings of the International Conference on Dependable Systems and Networks, 2013. https://doi.org/10.1109/DSN.2013.6575299.
Li P, Gao D, Reiter MK. Mitigating access-driven timing channels in clouds using StopWatch. In: Proceedings of the International Conference on Dependable Systems and Networks. 2013.
Li, P., et al. “Mitigating access-driven timing channels in clouds using StopWatch.” Proceedings of the International Conference on Dependable Systems and Networks, 2013. Scopus, doi:10.1109/DSN.2013.6575299.
Li P, Gao D, Reiter MK. Mitigating access-driven timing channels in clouds using StopWatch. Proceedings of the International Conference on Dependable Systems and Networks. 2013.

Published In

Proceedings of the International Conference on Dependable Systems and Networks

DOI

Publication Date

September 9, 2013