{"id":"https://openalex.org/W2061354941","doi":"https://doi.org/10.1145/2810103.2813708","title":"The Spy in the Sandbox","display_name":"The Spy in the Sandbox","publication_year":2015,"publication_date":"2015-10-06","ids":{"openalex":"https://openalex.org/W2061354941","doi":"https://doi.org/10.1145/2810103.2813708","mag":"2061354941"},"language":"en","primary_location":{"id":"doi:10.1145/2810103.2813708","is_oa":false,"landing_page_url":"https://doi.org/10.1145/2810103.2813708","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5002731103","display_name":"Yossi Oren","orcid":"https://orcid.org/0000-0002-0423-802X"},"institutions":[{"id":"https://openalex.org/I78577930","display_name":"Columbia University","ror":"https://ror.org/00hj8s172","country_code":"US","type":"education","lineage":["https://openalex.org/I78577930"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Yossef Oren","raw_affiliation_strings":["Columbia University, New York, NY, USA"],"affiliations":[{"raw_affiliation_string":"Columbia University, New York, NY, USA","institution_ids":["https://openalex.org/I78577930"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5006944216","display_name":"Vasileios P. Kemerlis","orcid":"https://orcid.org/0000-0002-6528-437X"},"institutions":[{"id":"https://openalex.org/I78577930","display_name":"Columbia University","ror":"https://ror.org/00hj8s172","country_code":"US","type":"education","lineage":["https://openalex.org/I78577930"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Vasileios P. Kemerlis","raw_affiliation_strings":["Columbia University, New York, NY, USA"],"affiliations":[{"raw_affiliation_string":"Columbia University, New York, NY, USA","institution_ids":["https://openalex.org/I78577930"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5030436580","display_name":"Simha Sethumadhavan","orcid":"https://orcid.org/0000-0002-6180-7153"},"institutions":[{"id":"https://openalex.org/I78577930","display_name":"Columbia University","ror":"https://ror.org/00hj8s172","country_code":"US","type":"education","lineage":["https://openalex.org/I78577930"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Simha Sethumadhavan","raw_affiliation_strings":["Columbia University, New York, NY, USA"],"affiliations":[{"raw_affiliation_string":"Columbia University, New York, NY, USA","institution_ids":["https://openalex.org/I78577930"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5023057383","display_name":"Angelos D. Keromytis","orcid":"https://orcid.org/0000-0003-3815-5932"},"institutions":[{"id":"https://openalex.org/I78577930","display_name":"Columbia University","ror":"https://ror.org/00hj8s172","country_code":"US","type":"education","lineage":["https://openalex.org/I78577930"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Angelos D. Keromytis","raw_affiliation_strings":["Columbia University, New York, NY, USA"],"affiliations":[{"raw_affiliation_string":"Columbia University, New York, NY, USA","institution_ids":["https://openalex.org/I78577930"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5002731103"],"corresponding_institution_ids":["https://openalex.org/I78577930"],"apc_list":null,"apc_paid":null,"fwci":37.8101,"has_fulltext":false,"cited_by_count":259,"citation_normalized_percentile":{"value":0.99772457,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":96,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"1406","last_page":"1418"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9980000257492065,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9973999857902527,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7972520589828491},{"id":"https://openalex.org/keywords/side-channel-attack","display_name":"Side channel attack","score":0.7875744700431824},{"id":"https://openalex.org/keywords/sandbox","display_name":"Sandbox (software development)","score":0.7772613763809204},{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.6684942245483398},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.6620722413063049},{"id":"https://openalex.org/keywords/timing-attack","display_name":"Timing attack","score":0.5991292595863342},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.5374022722244263},{"id":"https://openalex.org/keywords/scalability","display_name":"Scalability","score":0.4788358509540558},{"id":"https://openalex.org/keywords/compromise","display_name":"Compromise","score":0.4523780941963196},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.4429513216018677},{"id":"https://openalex.org/keywords/threat-model","display_name":"Threat model","score":0.4131677448749542},{"id":"https://openalex.org/keywords/cryptography","display_name":"Cryptography","score":0.2509217858314514},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.1608843207359314}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7972520589828491},{"id":"https://openalex.org/C49289754","wikidata":"https://www.wikidata.org/wiki/Q2267081","display_name":"Side channel attack","level":3,"score":0.7875744700431824},{"id":"https://openalex.org/C167981075","wikidata":"https://www.wikidata.org/wiki/Q2667186","display_name":"Sandbox (software development)","level":2,"score":0.7772613763809204},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.6684942245483398},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.6620722413063049},{"id":"https://openalex.org/C28420585","wikidata":"https://www.wikidata.org/wiki/Q2665075","display_name":"Timing attack","level":4,"score":0.5991292595863342},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.5374022722244263},{"id":"https://openalex.org/C48044578","wikidata":"https://www.wikidata.org/wiki/Q727490","display_name":"Scalability","level":2,"score":0.4788358509540558},{"id":"https://openalex.org/C46355384","wikidata":"https://www.wikidata.org/wiki/Q726686","display_name":"Compromise","level":2,"score":0.4523780941963196},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.4429513216018677},{"id":"https://openalex.org/C140547941","wikidata":"https://www.wikidata.org/wiki/Q7797194","display_name":"Threat model","level":2,"score":0.4131677448749542},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.2509217858314514},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.1608843207359314},{"id":"https://openalex.org/C36289849","wikidata":"https://www.wikidata.org/wiki/Q34749","display_name":"Social science","level":1,"score":0.0},{"id":"https://openalex.org/C144024400","wikidata":"https://www.wikidata.org/wiki/Q21201","display_name":"Sociology","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/2810103.2813708","is_oa":false,"landing_page_url":"https://doi.org/10.1145/2810103.2813708","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.8199999928474426}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":25,"referenced_works":["https://openalex.org/W200116028","https://openalex.org/W1447175589","https://openalex.org/W1488058190","https://openalex.org/W1494212869","https://openalex.org/W1495989020","https://openalex.org/W1553308705","https://openalex.org/W1580550895","https://openalex.org/W1600693085","https://openalex.org/W1607006990","https://openalex.org/W1613874182","https://openalex.org/W1684730140","https://openalex.org/W1934458198","https://openalex.org/W1964281299","https://openalex.org/W1992291252","https://openalex.org/W2001759130","https://openalex.org/W2095610745","https://openalex.org/W2107691219","https://openalex.org/W2119028650","https://openalex.org/W2124350608","https://openalex.org/W2137243422","https://openalex.org/W2144219822","https://openalex.org/W2146573211","https://openalex.org/W2951031141","https://openalex.org/W6674628898","https://openalex.org/W6764402087"],"related_works":["https://openalex.org/W1971956962","https://openalex.org/W2188560665","https://openalex.org/W4297042454","https://openalex.org/W3028997697","https://openalex.org/W3192308411","https://openalex.org/W2538033728","https://openalex.org/W2887442533","https://openalex.org/W4289792807","https://openalex.org/W4387031668","https://openalex.org/W3171718976"],"abstract_inverted_index":{"We":[0,126],"present":[1],"a":[2,100,152,160],"micro-architectural":[3],"side-channel":[4],"attack":[5,21,55],"that":[6,48,162],"runs":[7],"entirely":[8],"in":[9,17,151],"the":[10,25,31,36,38,75,91,117,122,128,174,186],"browser.":[11,125,187],"In":[12,138],"contrast":[13],"to":[14,27,34,42,44,64,73,90,103,107,147],"previous":[15],"work":[16],"this":[18,168],"genre,":[19],"our":[20,54,131],"does":[22],"not":[23],"require":[24],"attacker":[26,157],"install":[28],"software":[29],"on":[30,116,182],"victim's":[32],"machine;":[33],"facilitate":[35],"attack,":[37,85,132],"victim":[39,123,161],"needs":[40],"only":[41],"browse":[43],"an":[45,88,156,179],"untrusted":[46],"webpage":[47],"contains":[49],"attacker-controlled":[50],"content.":[51],"This":[52],"makes":[53],"model":[56],"highly":[57],"scalable,":[58],"and":[59,62,111,133],"extremely":[60],"relevant":[61],"practical":[63],"today's":[65],"Web,":[66],"as":[67],"most":[68],"desktop":[69],"browsers":[70],"currently":[71],"used":[72,146],"access":[74],"Internet":[76],"are":[77],"affected":[78],"by":[79],"such":[80],"side":[81,169],"channel":[82,170],"threats.":[83],"Our":[84],"which":[86],"is":[87,171],"extension":[89],"last-level":[92],"cache":[93],"attacks":[94],"of":[95,185],"Liu":[96],"et":[97],"al.,":[98],"allows":[99],"remote":[101],"adversary":[102],"recover":[104],"information":[105],"belonging":[106],"other":[108],"processes,":[109],"users,":[110],"even":[112],"virtual":[113],"machines":[114],"running":[115],"same":[118],"physical":[119],"host":[120],"with":[121],"web":[124],"describe":[127],"fundamentals":[129],"behind":[130],"evaluate":[134],"its":[135],"performance":[136],"characteristics.":[137],"addition,":[139],"we":[140],"show":[141],"how":[142],"it":[143],"can":[144,177],"be":[145],"compromise":[148],"user":[149],"privacy":[150],"common":[153],"setting,":[154],"letting":[155],"spy":[158],"after":[159],"uses":[163,184],"private":[164],"browsing.":[165],"Defending":[166],"against":[167],"possible,":[172],"but":[173],"required":[175],"countermeasures":[176],"exact":[178],"impractical":[180],"cost":[181],"benign":[183]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":19},{"year":2024,"cited_by_count":11},{"year":2023,"cited_by_count":22},{"year":2022,"cited_by_count":22},{"year":2021,"cited_by_count":33},{"year":2020,"cited_by_count":30},{"year":2019,"cited_by_count":37},{"year":2018,"cited_by_count":20},{"year":2017,"cited_by_count":35},{"year":2016,"cited_by_count":22},{"year":2015,"cited_by_count":7}],"updated_date":"2026-04-04T16:13:02.066488","created_date":"2025-10-10T00:00:00"}
