{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/108227"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/108227","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Leveraging concurrency for performance and security","abstract":"\"In this thesis we explore methods for exploiting concurrency to improve the security and performance of computing systems. We put forth four proposals: the Concurrency Accelerator (ConcAcl), Record-and-Replay Safe (RnRSafe), ReplayConfusion, and ReplayEndurance. With ConcAcl we accelerate concurrency management operations by creating a dedicated layer that is programmed by supervisor software (e.g. Operating System kernels or multi-threading runtimes). This layer is provisioned with dedicated compute and memory resources which are replicated across all cores in a multi-core processor. ConcAcl hosts procedures which are designed to exploit this unique arrangement to accelerate synchronization-heavy operations that are critical for concurrency. We use ConcAcl to offload functions related to event-synchronization, cross-core remote procedure calls, and task scheduling. In addition to improving concurrency management we also explore techniques which exploit concurrency to extract security benefits. The difficulty of implementing hardware-enforced security policies is exacerbated by a trade-off between implementation intrusiveness and completeness of methods. Methods which can guarantee detection will often require radical architectural changes. In addition, security systems need to be flexible, as security threats continuously evolve. To help address these requirements, we propose utilizing a novel framework where ``Record and Deterministic Replay\"\" (RnR) is used to {\\em complement} hardware security features. We call our approach RnRSafe. By recording non-deterministic behaviors concurrent replay can be used to investigate potential alarms. Thus, RnRSafe reduces the cost of security hardware by allowing it to be less precise at detecting attacks, potentially reporting false positives. We show how RnRSafe can be used to defend against Return Oriented Programming (ROP) attacks with minimal changes to the processor architecture. We also propose exploiting concurrent record and replay to enable the detection of otherwise undetectable covert channel attacks using two techniques -- ReplayConfusion and ReplayEndurance. %These techniques allow the detection of covert channels which flow across the Last Level Cache or across the speculative execution boundary. Covert channels encode secret values in sub-architectural features like caches and buffers. To detect covert channels we propose techniques similar to our RnR-Safe approach. First, the original instruction execution is recorded. Then, in either offline or online fashion, a replay is performed under a slightly altered configuration designed to alter sub-architectural behaviors. Thus, by comparing the original instruction execution to the modified replay-time execution, a signal can be extracted which measures the divergence between the recorded and replayed program in order to estimate the program's sensitivity to sub-architectural behaviors. With ReplayConfusion we alter parameters which organize the last-level cache and with ReplayEndurance we modify those which govern speculative execution. Altogether, this enables the construction of robust defenses against these attacks which can defend systems despite insecure hardware.\"","abstract_html":"&quot;In this thesis we explore methods for exploiting concurrency to improve the security and performance of computing systems. We put forth four proposals: the Concurrency Accelerator (ConcAcl), Record-and-Replay Safe (RnRSafe), ReplayConfusion, and ReplayEndurance. With ConcAcl we accelerate concurrency management operations by creating a dedicated layer that is programmed by supervisor software (e.g. Operating System kernels or multi-threading runtimes). This layer is provisioned with dedicated compute and memory resources which are replicated across all cores in a multi-core processor. ConcAcl hosts procedures which are designed to exploit this unique arrangement to accelerate synchronization-heavy operations that are critical for concurrency. We use ConcAcl to offload functions related to event-synchronization, cross-core remote procedure calls, and task scheduling. In addition to improving concurrency management we also explore techniques which exploit concurrency to extract security benefits. The difficulty of implementing hardware-enforced security policies is exacerbated by a trade-off between implementation intrusiveness and completeness of methods. Methods which can guarantee detection will often require radical architectural changes. In addition, security systems need to be flexible, as security threats continuously evolve. To help address these requirements, we propose utilizing a novel framework where ``Record and Deterministic Replay&quot;&quot; (RnR) is used to {\\em complement} hardware security features. We call our approach RnRSafe. By recording non-deterministic behaviors concurrent replay can be used to investigate potential alarms. Thus, RnRSafe reduces the cost of security hardware by allowing it to be less precise at detecting attacks, potentially reporting false positives. We show how RnRSafe can be used to defend against Return Oriented Programming (ROP) attacks with minimal changes to the processor architecture. We also propose exploiting concurrent record and replay to enable the detection of otherwise undetectable covert channel attacks using two techniques -- ReplayConfusion and ReplayEndurance. %These techniques allow the detection of covert channels which flow across the Last Level Cache or across the speculative execution boundary. Covert channels encode secret values in sub-architectural features like caches and buffers. To detect covert channels we propose techniques similar to our RnR-Safe approach. First, the original instruction execution is recorded. Then, in either offline or online fashion, a replay is performed under a slightly altered configuration designed to alter sub-architectural behaviors. Thus, by comparing the original instruction execution to the modified replay-time execution, a signal can be extracted which measures the divergence between the recorded and replayed program in order to estimate the program&#x27;s sensitivity to sub-architectural behaviors. With ReplayConfusion we alter parameters which organize the last-level cache and with ReplayEndurance we modify those which govern speculative execution. Altogether, this enables the construction of robust defenses against these attacks which can defend systems despite insecure hardware.&quot;","abstract_has_math":false,"creators":["Shalabi, Yasser"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"Ph.D.","degree_level":"Dissertation","degree_discipline":"Electrical & Computer Engr","degree_department":null,"school":null,"contributors":["Torrellas, Josep","Hwu, Wen-Mei","Fletcher, Christopher","Huang, Jian"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2020,"date_issued":"2020-08-27T00:46:51Z","date_published":"2020-08-27T00:46:51Z","updated_at":"2026-07-22T22:24:48Z","subjects":["Concurrency","record and replay","security","return oriented programming","side channel attack","prime and probe","spectre"],"languages":["en"],"rights":["Copyright 2020 Yasser Shalabi"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/108227","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Torrellas, Josep","Hwu, Wen-Mei","Fletcher, Christopher","Huang, Jian"]},{"key":"dc:creator","label":"Author","values":["Shalabi, Yasser"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2020-08-27T00:46:51Z","2022-08-27T00:51:40Z","2020-03-09","2020-05"]},{"key":"dc:type","label":"Dc Type","values":["text","Thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Electrical & Computer Engr"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Ph.D."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Concurrency","record and replay","security","return oriented programming","side channel attack","prime and probe","spectre"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2020 Yasser Shalabi"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/108227"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["\"In this thesis we explore methods for exploiting concurrency to improve the security and performance of computing systems. We put forth four proposals: the Concurrency Accelerator (ConcAcl), Record-and-Replay Safe (RnRSafe), ReplayConfusion, and ReplayEndurance. With ConcAcl we accelerate concurrency management operations by creating a dedicated layer that is programmed by supervisor software (e.g. Operating System kernels or multi-threading runtimes). This layer is provisioned with dedicated compute and memory resources which are replicated across all cores in a multi-core processor. ConcAcl hosts procedures which are designed to exploit this unique arrangement to accelerate synchronization-heavy operations that are critical for concurrency. We use ConcAcl to offload functions related to event-synchronization, cross-core remote procedure calls, and task scheduling. In addition to improving concurrency management we also explore techniques which exploit concurrency to extract security benefits. The difficulty of implementing hardware-enforced security policies is exacerbated by a trade-off between implementation intrusiveness and completeness of methods. Methods which can guarantee detection will often require radical architectural changes. In addition, security systems need to be flexible, as security threats continuously evolve. To help address these requirements, we propose utilizing a novel framework where ``Record and Deterministic Replay\"\" (RnR) is used to {\\em complement} hardware security features. We call our approach RnRSafe. By recording non-deterministic behaviors concurrent replay can be used to investigate potential alarms. Thus, RnRSafe reduces the cost of security hardware by allowing it to be less precise at detecting attacks, potentially reporting false positives. We show how RnRSafe can be used to defend against Return Oriented Programming (ROP) attacks with minimal changes to the processor architecture. We also propose exploiting concurrent record and replay to enable the detection of otherwise undetectable covert channel attacks using two techniques -- ReplayConfusion and ReplayEndurance. %These techniques allow the detection of covert channels which flow across the Last Level Cache or across the speculative execution boundary. Covert channels encode secret values in sub-architectural features like caches and buffers. To detect covert channels we propose techniques similar to our RnR-Safe approach. First, the original instruction execution is recorded. Then, in either offline or online fashion, a replay is performed under a slightly altered configuration designed to alter sub-architectural behaviors. Thus, by comparing the original instruction execution to the modified replay-time execution, a signal can be extracted which measures the divergence between the recorded and replayed program in order to estimate the program's sensitivity to sub-architectural behaviors. With ReplayConfusion we alter parameters which organize the last-level cache and with ReplayEndurance we modify those which govern speculative execution. Altogether, this enables the construction of robust defenses against these attacks which can defend systems despite insecure hardware.\"","Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2022-05-01","The student, Yasser Shalabi, accepted the attached license on 2020-03-07 at 08:45.","The student, Yasser Shalabi, submitted this Dissertation for approval on 2020-03-07 at 08:55.","This Dissertation was approved for publication on 2020-03-09 at 10:36.","DSpace SAF Submission Ingestion Package generated from Vireo submission #14887 on 2020-08-25 at 17:38:56","Made available in DSpace on 2020-08-27T00:46:51Z (GMT). No. of bitstreams: 2 SHALABI-DISSERTATION-2020.pdf: 3339643 bytes, checksum: 4512d8dde05facb76decedbe0f5b3410 (MD5) LICENSE.txt: 4211 bytes, checksum: 51a1dd7acfca1a46277b77694e453d50 (MD5) Previous issue date: 2020-03-09","Embargo set by: Seth Robbins for item 115840 Lift date: 2022-08-27T00:46:59Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Embargo set by: Seth Robbins for item 115840 Lift date: 2022-08-27T00:50:22Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Embargo set by: Seth Robbins for item 115840 Lift date: 2022-08-27T00:51:40Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Author requested closed access (OA after 2yrs) in Vireo ETD system","Limited"]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Leveraging concurrency for performance and security"]}]}],"canonical_facts":{"dc:contributor":["Torrellas, Josep","Hwu, Wen-Mei","Fletcher, Christopher","Huang, Jian"],"dc:creator":["Shalabi, Yasser"],"dc:date":["2020-08-27T00:46:51Z","2022-08-27T00:51:40Z","2020-03-09","2020-05"],"dc:description":["\"In this thesis we explore methods for exploiting concurrency to improve the security and performance of computing systems. We put forth four proposals: the Concurrency Accelerator (ConcAcl), Record-and-Replay Safe (RnRSafe), ReplayConfusion, and ReplayEndurance. With ConcAcl we accelerate concurrency management operations by creating a dedicated layer that is programmed by supervisor software (e.g. Operating System kernels or multi-threading runtimes). This layer is provisioned with dedicated compute and memory resources which are replicated across all cores in a multi-core processor. ConcAcl hosts procedures which are designed to exploit this unique arrangement to accelerate synchronization-heavy operations that are critical for concurrency. We use ConcAcl to offload functions related to event-synchronization, cross-core remote procedure calls, and task scheduling. In addition to improving concurrency management we also explore techniques which exploit concurrency to extract security benefits. The difficulty of implementing hardware-enforced security policies is exacerbated by a trade-off between implementation intrusiveness and completeness of methods. Methods which can guarantee detection will often require radical architectural changes. In addition, security systems need to be flexible, as security threats continuously evolve. To help address these requirements, we propose utilizing a novel framework where ``Record and Deterministic Replay\"\" (RnR) is used to {\\em complement} hardware security features. We call our approach RnRSafe. By recording non-deterministic behaviors concurrent replay can be used to investigate potential alarms. Thus, RnRSafe reduces the cost of security hardware by allowing it to be less precise at detecting attacks, potentially reporting false positives. We show how RnRSafe can be used to defend against Return Oriented Programming (ROP) attacks with minimal changes to the processor architecture. We also propose exploiting concurrent record and replay to enable the detection of otherwise undetectable covert channel attacks using two techniques -- ReplayConfusion and ReplayEndurance. %These techniques allow the detection of covert channels which flow across the Last Level Cache or across the speculative execution boundary. Covert channels encode secret values in sub-architectural features like caches and buffers. To detect covert channels we propose techniques similar to our RnR-Safe approach. First, the original instruction execution is recorded. Then, in either offline or online fashion, a replay is performed under a slightly altered configuration designed to alter sub-architectural behaviors. Thus, by comparing the original instruction execution to the modified replay-time execution, a signal can be extracted which measures the divergence between the recorded and replayed program in order to estimate the program's sensitivity to sub-architectural behaviors. With ReplayConfusion we alter parameters which organize the last-level cache and with ReplayEndurance we modify those which govern speculative execution. Altogether, this enables the construction of robust defenses against these attacks which can defend systems despite insecure hardware.\"","Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2022-05-01","The student, Yasser Shalabi, accepted the attached license on 2020-03-07 at 08:45.","The student, Yasser Shalabi, submitted this Dissertation for approval on 2020-03-07 at 08:55.","This Dissertation was approved for publication on 2020-03-09 at 10:36.","DSpace SAF Submission Ingestion Package generated from Vireo submission #14887 on 2020-08-25 at 17:38:56","Made available in DSpace on 2020-08-27T00:46:51Z (GMT). No. of bitstreams: 2 SHALABI-DISSERTATION-2020.pdf: 3339643 bytes, checksum: 4512d8dde05facb76decedbe0f5b3410 (MD5) LICENSE.txt: 4211 bytes, checksum: 51a1dd7acfca1a46277b77694e453d50 (MD5) Previous issue date: 2020-03-09","Embargo set by: Seth Robbins for item 115840 Lift date: 2022-08-27T00:46:59Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Embargo set by: Seth Robbins for item 115840 Lift date: 2022-08-27T00:50:22Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Embargo set by: Seth Robbins for item 115840 Lift date: 2022-08-27T00:51:40Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Author requested closed access (OA after 2yrs) in Vireo ETD system","Limited"],"dc:format":["application/pdf"],"dc:identifier":["http://hdl.handle.net/2142/108227"],"dc:language":["en"],"dc:rights":["Copyright 2020 Yasser Shalabi"],"dc:subject":["Concurrency","record and replay","security","return oriented programming","side channel attack","prime and probe","spectre"],"dc:title":["Leveraging concurrency for performance and security"],"dc:type":["text","Thesis"],"thesis:degree_discipline":["Electrical & Computer Engr"],"thesis:degree_level":["Dissertation"],"thesis:degree_name":["Ph.D."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:24:48Z"}