Title
Plugging side-channel leaks with timing information flow control
Abstract
The cloud model's dependence on massive parallelism and resource sharing exacerbates the security challenge of timing side-channels. Timing Information Flow Control (TIFC) is a novel adaptation of IFC techniques that may offer a way to reason about, and ultimately control, the flow of sensitive information through systems via timing channels. With TIFC, objects such as files, messages, and processes carry not just content labels describing the ownership of the object's "bits," but also timing labels describing information contained in timing events affecting the object, such as process creation/termination or message reception. With two system design tools--deterministic execution and pacing queues--TIFC enables the construction of "timing-hardened" cloud infrastructure that permits statistical multiplexing, while aggregating and rate-limiting timing information leakage between hosted computations.
Year
Venue
Keywords
2012
HotCloud'12 Proceedings of the 4th USENIX conference on Hot Topics in Cloud Ccomputing
cloud model,timing side-channels,content label,timing information flow control,timing event,timing channel,side-channel leak,sensitive information,cloud infrastructure,ifc technique,rate-limiting timing information leakage
DocType
Volume
ISSN
Conference
abs/1203.3428
4th USENIX Workshop on Hot Topics in Cloud Computing (HotCloud '12), June 12-13, 2012
Citations 
PageRank 
References 
7
0.47
14
Authors
6
Name
Order
Citations
PageRank
Bryan Ford11573149.56
M Yu270.81
A Sharma370.47
ramesh govindan4154302144.86
C Krintz570.47
H Wu670.81