{"id":"https://openalex.org/W2988979713","doi":"https://doi.org/10.1145/3319535.3354250","title":"Principled Unearthing of TCP Side Channel Vulnerabilities","display_name":"Principled Unearthing of TCP Side Channel Vulnerabilities","publication_year":2019,"publication_date":"2019-11-06","ids":{"openalex":"https://openalex.org/W2988979713","doi":"https://doi.org/10.1145/3319535.3354250","mag":"2988979713"},"language":"en","primary_location":{"id":"doi:10.1145/3319535.3354250","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3319535.3354250","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3319535.3354250","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3319535.3354250","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5102747897","display_name":"Yue Cao","orcid":"https://orcid.org/0000-0002-5826-3095"},"institutions":[{"id":"https://openalex.org/I103635307","display_name":"University of California, Riverside","ror":"https://ror.org/03nawhv43","country_code":"US","type":"education","lineage":["https://openalex.org/I103635307"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Yue Cao","raw_affiliation_strings":["University of California, Riverside, Riverside, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California, Riverside, Riverside, CA, USA","institution_ids":["https://openalex.org/I103635307"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100738314","display_name":"Zhongjie Wang","orcid":"https://orcid.org/0000-0002-4925-2941"},"institutions":[{"id":"https://openalex.org/I103635307","display_name":"University of California, Riverside","ror":"https://ror.org/03nawhv43","country_code":"US","type":"education","lineage":["https://openalex.org/I103635307"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Zhongjie Wang","raw_affiliation_strings":["University of California, Riverside, Riverside, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California, Riverside, Riverside, CA, USA","institution_ids":["https://openalex.org/I103635307"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5022038961","display_name":"Zhiyun Qian","orcid":"https://orcid.org/0000-0003-1506-2522"},"institutions":[{"id":"https://openalex.org/I103635307","display_name":"University of California, Riverside","ror":"https://ror.org/03nawhv43","country_code":"US","type":"education","lineage":["https://openalex.org/I103635307"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Zhiyun Qian","raw_affiliation_strings":["University of California, Riverside, Riverside, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California, Riverside, Riverside, CA, USA","institution_ids":["https://openalex.org/I103635307"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5005972298","display_name":"Chengyu Song","orcid":"https://orcid.org/0000-0001-6617-3068"},"institutions":[{"id":"https://openalex.org/I103635307","display_name":"University of California, Riverside","ror":"https://ror.org/03nawhv43","country_code":"US","type":"education","lineage":["https://openalex.org/I103635307"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Chengyu Song","raw_affiliation_strings":["University of California, Riverside, Riverside, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California, Riverside, Riverside, CA, USA","institution_ids":["https://openalex.org/I103635307"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5086268637","display_name":"Srikanth V. Krishnamurthy","orcid":"https://orcid.org/0000-0002-6533-4381"},"institutions":[{"id":"https://openalex.org/I103635307","display_name":"University of California, Riverside","ror":"https://ror.org/03nawhv43","country_code":"US","type":"education","lineage":["https://openalex.org/I103635307"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Srikanth V. Krishnamurthy","raw_affiliation_strings":["University of California, Riverside, Riverside, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California, Riverside, Riverside, CA, USA","institution_ids":["https://openalex.org/I103635307"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5000981358","display_name":"Paul Yu","orcid":"https://orcid.org/0000-0003-1577-3914"},"institutions":[{"id":"https://openalex.org/I2802705668","display_name":"United States Army Combat Capabilities Development Command","ror":"https://ror.org/02rdkx920","country_code":"US","type":"other","lineage":["https://openalex.org/I1304082316","https://openalex.org/I1330347796","https://openalex.org/I2802705668","https://openalex.org/I4210154437"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Paul Yu","raw_affiliation_strings":["U.S. Army Combat Capabilities Development Command Army Research Laboratory, Adelphi, MD, USA"],"affiliations":[{"raw_affiliation_string":"U.S. Army Combat Capabilities Development Command Army Research Laboratory, Adelphi, MD, USA","institution_ids":["https://openalex.org/I2802705668"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5102747897"],"corresponding_institution_ids":["https://openalex.org/I103635307"],"apc_list":null,"apc_paid":null,"fwci":1.3006,"has_fulltext":true,"cited_by_count":18,"citation_normalized_percentile":{"value":0.86013257,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":94,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"211","last_page":"224"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.9986000061035156,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11005","display_name":"Radiation Effects in Electronics","score":0.9973000288009644,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/side-channel-attack","display_name":"Side channel attack","score":0.7228143215179443},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6281116008758545},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.541656494140625},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.47723865509033203},{"id":"https://openalex.org/keywords/channel","display_name":"Channel (broadcasting)","score":0.4194721579551697},{"id":"https://openalex.org/keywords/cryptography","display_name":"Cryptography","score":0.09458312392234802}],"concepts":[{"id":"https://openalex.org/C49289754","wikidata":"https://www.wikidata.org/wiki/Q2267081","display_name":"Side channel attack","level":3,"score":0.7228143215179443},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6281116008758545},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.541656494140625},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.47723865509033203},{"id":"https://openalex.org/C127162648","wikidata":"https://www.wikidata.org/wiki/Q16858953","display_name":"Channel (broadcasting)","level":2,"score":0.4194721579551697},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.09458312392234802}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3319535.3354250","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3319535.3354250","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3319535.3354250","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3319535.3354250","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3319535.3354250","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3319535.3354250","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"},"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.7400000095367432}],"awards":[{"id":"https://openalex.org/G2043895709","display_name":null,"funder_award_id":"W911NF-13-2-0045","funder_id":"https://openalex.org/F4320338295","funder_display_name":"Army Research Laboratory"},{"id":"https://openalex.org/G3693556586","display_name":null,"funder_award_id":"2-004","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G3732666562","display_name":null,"funder_award_id":"W911NF-13","funder_id":"https://openalex.org/F4320338295","funder_display_name":"Army Research Laboratory"},{"id":"https://openalex.org/G4307486606","display_name":null,"funder_award_id":"W911NF-13-2-0045 (ARL Cyber Security CRA)","funder_id":"https://openalex.org/F4320338295","funder_display_name":"Army Research Laboratory"},{"id":"https://openalex.org/G5124561427","display_name":null,"funder_award_id":"1652954","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G5259331294","display_name":null,"funder_award_id":"W911NF","funder_id":"https://openalex.org/F4320338295","funder_display_name":"Army Research Laboratory"},{"id":"https://openalex.org/G5979736433","display_name":null,"funder_award_id":"W911NF-13-2-0045 (ARL Cyber Security CRA)","funder_id":"https://openalex.org/F4320338456","funder_display_name":"DEVCOM Army Research Laboratory"},{"id":"https://openalex.org/G8000996158","display_name":null,"funder_award_id":"W911NF-13-2-0045","funder_id":"https://openalex.org/F4320338456","funder_display_name":"DEVCOM Army Research Laboratory"},{"id":"https://openalex.org/G8727049869","display_name":null,"funder_award_id":"W911NF-13","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G8763038417","display_name":null,"funder_award_id":"Cooperative Agreement Number W911NF-13-2-0045","funder_id":"https://openalex.org/F4320338295","funder_display_name":"Army Research Laboratory"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"},{"id":"https://openalex.org/F4320315784","display_name":"U.S. Army Combat Capabilities Development Command Soldier Center","ror":"https://ror.org/02rdkx920"},{"id":"https://openalex.org/F4320338295","display_name":"Army Research Laboratory","ror":"https://ror.org/011hc8f90"},{"id":"https://openalex.org/F4320338456","display_name":"DEVCOM Army Research Laboratory","ror":null}],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W2988979713.pdf","grobid_xml":"https://content.openalex.org/works/W2988979713.grobid-xml"},"referenced_works_count":45,"referenced_works":["https://openalex.org/W207759855","https://openalex.org/W327452528","https://openalex.org/W1510110825","https://openalex.org/W1517351977","https://openalex.org/W1535237014","https://openalex.org/W1590315663","https://openalex.org/W1593428110","https://openalex.org/W1593884111","https://openalex.org/W1596552075","https://openalex.org/W1607141595","https://openalex.org/W1710734607","https://openalex.org/W1750494731","https://openalex.org/W1838445804","https://openalex.org/W1904404804","https://openalex.org/W1976878954","https://openalex.org/W1977764760","https://openalex.org/W2013901835","https://openalex.org/W2053597677","https://openalex.org/W2065675749","https://openalex.org/W2067877212","https://openalex.org/W2070670160","https://openalex.org/W2087321129","https://openalex.org/W2106243315","https://openalex.org/W2111419012","https://openalex.org/W2115309705","https://openalex.org/W2117009500","https://openalex.org/W2126220112","https://openalex.org/W2129498954","https://openalex.org/W2133467782","https://openalex.org/W2138703291","https://openalex.org/W2147491888","https://openalex.org/W2153185479","https://openalex.org/W2161246680","https://openalex.org/W2170682382","https://openalex.org/W2473007119","https://openalex.org/W2500302530","https://openalex.org/W2706122055","https://openalex.org/W2753573171","https://openalex.org/W2791547242","https://openalex.org/W2792107537","https://openalex.org/W2795192879","https://openalex.org/W2888230423","https://openalex.org/W2889367186","https://openalex.org/W2895482461","https://openalex.org/W2925685215"],"related_works":["https://openalex.org/W2130966263","https://openalex.org/W3196561854","https://openalex.org/W1548040509","https://openalex.org/W2159609636","https://openalex.org/W4297884308","https://openalex.org/W3108685829","https://openalex.org/W2981727040","https://openalex.org/W3100675173","https://openalex.org/W2359317704","https://openalex.org/W3009105181"],"abstract_inverted_index":{"Recent":[0],"work":[1,33,50],"has":[2],"showcased":[3],"the":[4,38,63,74,82,85,155,168,205,216,230,236,240,257,266],"presence":[5],"of":[6,41,66,76,84,101,133,171,179,207,244,259,280],"subtle":[7],"TCP":[8,69,90,156,217],"side":[9,262],"channels":[10],"in":[11,99,144,199,220,229,265],"modern":[12],"operating":[13],"systems,":[14],"that":[15,59,73,125,186,195,214,253,283],"can":[16,60],"be":[17],"exploited":[18],"by":[19,114,235],"off-path":[20,285],"adversaries":[21],"to":[22,34,62,108,137,152,162,224,256,289],"launch":[23],"pernicious":[24],"attacks":[25],"such":[26,42,67,78,119],"as":[27],"hijacking":[28],"a":[29,56,97,109,128,184,200,221,227,273],"connection.":[30],"Unfortunately,":[31],"most":[32],"date":[35],"is":[36,81,127,209,287],"on":[37,306],"manual":[39],"discovery":[40,65,258],"side-channels,":[43],"and":[44,160,165,174,239,242,268],"patching":[45],"them":[46],"subsequently.":[47],"In":[48,271],"this":[49],"we":[51,54,123,187],"ask":[52],"\"Can":[53],"develop":[55,183],"principled":[57],"approach":[58],"lead":[61],"automated":[64,202,211],"hard-to-find":[68],"side-channels?\"":[70],"We":[71,182],"identify":[72],"crux":[75],"why":[77],"side-channels":[79],"exist":[80,94,141],"violation":[83],"non-interference":[86,120],"property":[87,121],"between":[88],"simultaneous":[89],"connections":[91],"i.e.,":[92],"there":[93,140],"cases":[95],"wherein":[96],"change":[98],"state":[100,231],"one":[102,278],"connection":[103,111],"implicitly":[104],"leaks":[105],"some":[106],"information":[107],"different":[110],"(controlled":[112],"possibly":[113],"an":[115,210,284],"attacker).":[116],"To":[117],"find":[118],"violations,":[122],"argue":[124],"model-checking":[126],"natural":[129],"fit.":[130],"However,":[131],"because":[132],"limitations":[134],"with":[135,277,297],"regards":[136],"its":[138],"scalability,":[139],"many":[142],"challenges":[143,150,198],"using":[145],"model":[146,163,172,237],"checking.":[147],"Specifically,":[148],"these":[149,197],"relate":[151],"(a)":[153],"making":[154],"code":[157,180,218],"base":[158,219],"self-contained":[159],"amenable":[161],"checking":[164,173],"(b)":[166],"limiting":[167],"search":[169],"space":[170,232],"yet":[175],"achieving":[176],"reasonable":[177],"levels":[178],"coverage.":[181],"tool":[185],"call":[188],"SCENT":[189,208,254],"(for":[190],"Side":[191],"Channel":[192],"Excavation":[193],"Tool)":[194],"addresses":[196],"mostly":[201],"way.":[203],"At":[204],"heart":[206],"downscaling":[212],"component":[213],"transforms":[215],"consistent":[222],"way":[223],"achieve":[225],"both":[226],"reduction":[228],"complexity":[233],"encountered":[234],"checker":[238],"number":[241],"types":[243],"inputs":[245],"needed":[246],"for":[247],"verification.":[248],"Our":[249],"extensive":[250],"evaluations":[251],"show":[252],"leads":[255],"12":[260],"new":[261],"channel":[263],"vulnerabilities":[264,281],"Linux":[267],"FreeBSD":[269],"kernels.":[270],"particular,":[272],"real":[274],"world":[275],"validation":[276],"class":[279],"shows":[282],"attacker":[286],"able":[288],"infer":[290],"whether":[291],"two":[292],"arbitrary":[293],"hosts":[294],"are":[295],"communicating":[296],"each":[298],"other,":[299],"within":[300],"slightly":[301],"more":[302],"than":[303],"1":[304],"minute,":[305],"average.":[307]},"counts_by_year":[{"year":2025,"cited_by_count":5},{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":2},{"year":2022,"cited_by_count":2},{"year":2021,"cited_by_count":5},{"year":2020,"cited_by_count":2}],"updated_date":"2026-04-10T15:06:20.359241","created_date":"2025-10-10T00:00:00"}
