{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/90967"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/90967","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Cauldron: a framework to defend against cache-based side-channel attacks in clouds","abstract":"Cache-based side-channel attacks have garnered much interest in recent literature. Such attacks are particularly relevant for cloud computing platforms due to high levels of multi-tenancy. In fact, there exists recent work that demonstrates such attacks on real cloud platforms (e.g., DotCloud). In this thesis we present Cauldron, a framework to defend against such cache-based side-channel attacks. Cauldron uses a combination of smart scheduling techniques and microarchitectural mechanisms to achieve this goal. We are able to demonstrate improved defenses against both cross-core side channel attacks that target shared caches as well as same-core attacks. Furthermore, Cauldron is transparent to the user - requiring no modi cation (or even recompilation) of users' application binaries by integrating directly with the popular container runtime framework, Docker. Preliminary evaluation results show that the proposed approach is effective for cloud computing applications.","abstract_html":"Cache-based side-channel attacks have garnered much interest in recent literature. Such attacks are particularly relevant for cloud computing platforms due to high levels of multi-tenancy. In fact, there exists recent work that demonstrates such attacks on real cloud platforms (e.g., DotCloud). In this thesis we present Cauldron, a framework to defend against such cache-based side-channel attacks. Cauldron uses a combination of smart scheduling techniques and microarchitectural mechanisms to achieve this goal. We are able to demonstrate improved defenses against both cross-core side channel attacks that target shared caches as well as same-core attacks. Furthermore, Cauldron is transparent to the user - requiring no modi cation (or even recompilation) of users&#x27; application binaries by integrating directly with the popular container runtime framework, Docker. Preliminary evaluation results show that the proposed approach is effective for cloud computing applications.","abstract_has_math":false,"creators":["Ahmad, Mohammad"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Campbell, Roy H.","Bobba, Rakesh B."],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2016,"date_issued":"2016-07-07T21:18:08Z","date_published":"2016-07-07T21:18:08Z","updated_at":"2026-07-22T22:26:34Z","subjects":["Cache-based side-channel attacks","Cloud computing","Containers","Virtualization","Docker"],"languages":["en"],"rights":["Copyright 2016 Mohammad Ahmad"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/90967","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Campbell, Roy H.","Bobba, Rakesh B."]},{"key":"dc:creator","label":"Author","values":["Ahmad, Mohammad"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2016-07-07T21:18:08Z","2018-07-08T09:15:33Z","2016-04-27","2016-05"]},{"key":"dc:type","label":"Dc Type","values":["text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Cache-based side-channel attacks","Cloud computing","Containers","Virtualization","Docker"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2016 Mohammad Ahmad"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/90967"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Cache-based side-channel attacks have garnered much interest in recent literature. Such attacks are particularly relevant for cloud computing platforms due to high levels of multi-tenancy. In fact, there exists recent work that demonstrates such attacks on real cloud platforms (e.g., DotCloud). In this thesis we present Cauldron, a framework to defend against such cache-based side-channel attacks. Cauldron uses a combination of smart scheduling techniques and microarchitectural mechanisms to achieve this goal. We are able to demonstrate improved defenses against both cross-core side channel attacks that target shared caches as well as same-core attacks. Furthermore, Cauldron is transparent to the user - requiring no modi cation (or even recompilation) of users' application binaries by integrating directly with the popular container runtime framework, Docker. Preliminary evaluation results show that the proposed approach is effective for cloud computing applications.","Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2018-05-01","The student, Mohammad Ahmad, accepted the attached license on 2016-04-26 at 21:46.","The student, Mohammad Ahmad, submitted this Thesis for approval on 2016-04-26 at 22:00.","This Thesis was approved for publication on 2016-04-27 at 10:59.","DSpace SAF Submission Ingestion Package generated from Vireo submission #9535 on 2016-07-07 at 14:18:06","Made available in DSpace on 2016-07-07T21:18:08Z (GMT). No. of bitstreams: 2 AHMAD-THESIS-2016.pdf: 1307873 bytes, checksum: 804d464c1bb31b008f15039a3642a809 (MD5) LICENSE.txt: 4211 bytes, checksum: fda05c741c625610c1fa35bbcd126867 (MD5) Previous issue date: 2016-04-27","Embargo set by: Seth Robbins for item 93322 Lift date: 2018-07-07T21:18:16Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Limited Restriction Lifted for Item 93322 on 2018-07-08T09:15:33Z."]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Cauldron: a framework to defend against cache-based side-channel attacks in clouds"]}]}],"canonical_facts":{"dc:contributor":["Campbell, Roy H.","Bobba, Rakesh B."],"dc:creator":["Ahmad, Mohammad"],"dc:date":["2016-07-07T21:18:08Z","2018-07-08T09:15:33Z","2016-04-27","2016-05"],"dc:description":["Cache-based side-channel attacks have garnered much interest in recent literature. Such attacks are particularly relevant for cloud computing platforms due to high levels of multi-tenancy. In fact, there exists recent work that demonstrates such attacks on real cloud platforms (e.g., DotCloud). In this thesis we present Cauldron, a framework to defend against such cache-based side-channel attacks. Cauldron uses a combination of smart scheduling techniques and microarchitectural mechanisms to achieve this goal. We are able to demonstrate improved defenses against both cross-core side channel attacks that target shared caches as well as same-core attacks. Furthermore, Cauldron is transparent to the user - requiring no modi cation (or even recompilation) of users' application binaries by integrating directly with the popular container runtime framework, Docker. Preliminary evaluation results show that the proposed approach is effective for cloud computing applications.","Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2018-05-01","The student, Mohammad Ahmad, accepted the attached license on 2016-04-26 at 21:46.","The student, Mohammad Ahmad, submitted this Thesis for approval on 2016-04-26 at 22:00.","This Thesis was approved for publication on 2016-04-27 at 10:59.","DSpace SAF Submission Ingestion Package generated from Vireo submission #9535 on 2016-07-07 at 14:18:06","Made available in DSpace on 2016-07-07T21:18:08Z (GMT). No. of bitstreams: 2 AHMAD-THESIS-2016.pdf: 1307873 bytes, checksum: 804d464c1bb31b008f15039a3642a809 (MD5) LICENSE.txt: 4211 bytes, checksum: fda05c741c625610c1fa35bbcd126867 (MD5) Previous issue date: 2016-04-27","Embargo set by: Seth Robbins for item 93322 Lift date: 2018-07-07T21:18:16Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Limited Restriction Lifted for Item 93322 on 2018-07-08T09:15:33Z."],"dc:format":["application/pdf"],"dc:identifier":["http://hdl.handle.net/2142/90967"],"dc:language":["en"],"dc:rights":["Copyright 2016 Mohammad Ahmad"],"dc:subject":["Cache-based side-channel attacks","Cloud computing","Containers","Virtualization","Docker"],"dc:title":["Cauldron: a framework to defend against cache-based side-channel attacks in clouds"],"dc:type":["text"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:26:34Z"}