Debadatta Mishra

dblp:144/4955 · DBLP profile ↗
← Back
21ranked-venue papers
3as first author
14since 2021 · last 2025
0000-0003-4411-167XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 13 · 2 first-author · 8 since 2021Software engineering, systems software and programming languages · 5 · 1 first-author · 4 since 2021Security and privacy · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021
YearPublicationVenuePosition
2025 FlexClone: Efficient, Flexible and Pluggable File Cloning Support for Filesystems
abstract
Efficient cloning is crucial for many contemporary applications and computing environments, such as performing backups, cloning virtual machines, provisioning containers, etc. Although filesystems such as Btrfs and XFS support space-efficient file cloning, they suffer from memory inefficiency due to duplicate caching of shared disk blocks. Moreover, existing cloning solutions provide restrictive cloning support, typically limited by their design goal of achieving copy-on-write (CoW) at block granularity. In this paper, we propose FlexClone, an alternate design approach to support efficient file cloning for filesystems while addressing the limitations of existing cloning solutions. FlexClone identifies the limitations of existing solutions and proposes novel techniques to provide an efficient and flexible file cloning middleware that can be easily integrated with filesystems lacking specialized support for cloning. Furthermore, while FlexClone employs deferred processing for improved file I/O performance, it ensures consistency and efficient recovery using specialized design techniques. FlexClone integration with the Ext4 filesystem enables efficient file cloning in Ext4. FlexClone improves SQLite performance by up to ~2.17x, OverlayFS copy-up performance by up to 15x, and enhances resource efficiency in various application scenarios.
Debadatta Mishra
Middleware2
2025 LeakyRand: An Efficient High-fidelity Covert Channel in Fully Associative Last-level Caches with Random Eviction
abstract
Recent studies on secure last-level cache (LLC) have advocated the fully associative organization to defend against conflict-based side-channel attacks. In a fully associative LLC, an attacker cannot extract any information about the cache location of the addresses evicted due to cross-core conflict. Use of the random replacement policy further guards against any deterministic eviction patterns. However, the fully associative LLC design remains vulnerable against timing-based covert channel attacks. In this article, we present LeakyRand , a high-bandwidth covert communication mechanism that exploits the fully associative LLC with random replacement while guaranteeing an ultra-low bit error rate (BER). Our proposal is a union of three unique contributions. First, we present an efficient algorithm with strong analytical guarantees that enables the attacker to quickly occupy nearly the whole LLC with high probability, a prerequisite for achieving high bandwidth and high fidelity. Second, we present a novel covert communication protocol that allows the attacker to maintain high LLC occupancy. Third, our proposal detects error syndromes and efficiently takes corrective measures leading to an ultra-low expected BER. Exploiting a 2 MB fully associative LLC with random replacement policy to set up a covert channel, LeakyRand experiences an average BER of 10 -4 or less while offering 3.3× to 5.7× higher channel bandwidth compared to the recently proposed Stochastic Prime+Probe attack. We also demonstrate that LeakyRand can be adopted to mount high-precision fine-grain fingerprinting attacks.
Yashika Verma, Debadatta Mishra, Mainak Chaudhuri
ACM Trans. Embed. Comput. Syst.2
2024 PCLive: Pipelined Restoration of Application Containers for Reduced Service Downtime
abstract
Application containers are widely used in contemporary cloud computing environments. Migration of containers across hosts provides cost-effective cloud management by enabling improved server consolidation, load balancing and enhanced fault tolerance. One of the primary objectives of container migration is to reduce the service downtime of applications hosted in containers. The service downtime depends on performing the migration activities efficiently, specifically from the time the container is stopped on the source host till it is restored and fully functional at the destination host.
Shiv Bhushan Tripathi, Debadatta Mishra
SoCC2
2024 Prosper: Program Stack Persistence in Hybrid Memory Systems
abstract
A persistent and crash-consistent execution state is essential for systems to guarantee resilience against power failures and abrupt system crashes. The availability of nonvolatile memory (NVM) with read/write latency comparable to DRAM allows designing efficient checkpoint mechanisms for process persistence. Operating system (OS) level checkpoint solutions require capturing the change in the execution state of a process in an efficient manner. One of the crucial components of the execution state of any process is its memory state consisting of mutable stack and heap segments. Tracking modifications to the program stack is interesting because of its unique grow/shrink usage pattern and activation record write characteristics. Moreover, the stack is used in a programmer-agnostic manner where the compiler makes use of the support provided by the underlying ISA to use the stack and the OS manages the memory used by the stack region in an on-demand fashion. In this paper, we show the benefit of a checkpoint-based mechanism for stack persistence and the inefficiency of adapting existing generic memory persistence mechanisms for the stack region. We propose Prosper, a hardware-software (OS) codesigned checkpoint approach for stack persistence. Prosper tracks stack changes at sub-page byte granularity in hardware, allowing symbiosis with OS to realize efficient checkpoints of the stack region. Prosper significantly reduces (on average ∼4 ×) the amount of data copied during checkpoint and improves the overall checkpoint time with minimum overhead (less than 1% on average). Integration of Prosper with existing state-of-theart memory persistence mechanisms (such as SSP) for heap provides 2.6 × improvement over solely using the state-of-the-art mechanism for the entire memory area persistence.
K. P. Arun 0002, Debadatta Mishra, Biswabandan Panda
HPCA2
2023 KalpaVriksh: Efficient and Cost-effective GUI Application Hosting using Singleton Snapshots
abstract
Hosting popular GUI applications in different virtual machines (VMs) in a cloud can provide strong intra- application isolation and enhance the security of end-user devices. In this context, micro-VMs can be a very good fit where different applications are hosted in different micro-VMs hosted in the cloud. However, one of the challenges for the cloud service provider is to launch the application quickly when requested by any client. Techniques like VM snapshots can be used to improve the application launch time as shown in many existing research works. In this paper, we argue that GUI applications are different from snapshot-optimized cloud services like FaaS because the GUI applications are stateful and require specialized techniques for snapshot management. To manage application snapshots in a memory-efficient manner, the proposed KalpaVriksh framework maintains a single snapshot to launch multiple GUI applications from different end users. Furthermore, the unified snapshot framework does not impact the application launch time by using intelligent snapshot creation procedures. The experimental analysis shows that KalpaVriksh snapshot techniques apart from being memory- efficient, reach the farthest feasible point of snapshot capture (i.e., first external communication) during application execution, faster than a normal application launch (by 4.9x).
Sumaiya Shaikh, Saurabh Kumar 0007, Debadatta Mishra
CCGrid3
2022 LDT: Lightweight Dirty Tracking of Memory Pages for x86 Systems
abstract
Incremental memory checkpointing is a crucial primitive required by applications such as live migration, cloning, debugging etc. In many implementations of incremental check-pointing, the memory modifications are tracked by restricting write access to memory pages using the support provided in the memory management unit (MMU) hardware. Disabling write access impacts the performance of applications because of the page faults induced in the form of permission violation on memory store operations by the applications.In this paper, we propose LDT, a light-weight memory write monitoring mechanism to support efficient incremental check-pointing. LDT is designed to work in systems with MMU support for page dirty indicators (such as dirty-bit in x86 systems) by enabling polymorphic use of the indicators such that no other subsystem is impacted because of LDT. We design and implement LDT in the Linux kernel as an alternate to the existing write-restriction based technique. We establish the correctness and comparative efficiency of LDT through extensive experimental analysis. The results show that under write-heavy workloads, LDT outperforms write-restriction based technique by a factor of 2x in execution time. For real-world workload benchmarks such as Redis, LDT results in 2% to 8% throughput improvement compared to the state-of-the-art dirty tracking technique.
K. P. Arun 0002, Debadatta Mishra
HIPC3
2022 MicroBlind: Flexible and Secure File System Middleware for Application Sandboxes
abstract
Virtual machine (VM) based application sandboxes leverage strong isolation guarantees of virtualization techniques to address several security issues through effective containment of malware. Specifically, in end-user physical hosts, potentially vulnerable applications can be isolated from each other (and the host) using VM based sandboxes. However, sharing data across applications executing within different sandboxes is a non-trivial requirement for end-user systems because at the end of the day, all applications are used by the end-user owning the device. Existing file sharing techniques compromise the security or efficiency, especially considering lack of technical expertise of many end-users in the contemporary times. In this paper, we propose MicroBlind, a security hardened file sharing framework for virtualized sandboxes to support efficient data sharing across different application sandboxes. MicroBlind enables a simple file sharing management API for end users where the end user can orchestrate file sharing across different VM sandboxes in a secure manner. To demonstrate the efficacy of MicroBlind, we perform comprehensive empirical analysis against existing data sharing techniques (augmented for the sandboxing setup) and show that MicroBlind provides improved security and efficiency.
Saketh Maddamsetty, Ayush Tharwani, Debadatta Mishra
IC2E3
2022 SniP: An Efficient Stack Tracing Framework for Multi-threaded Programs
abstract
Usage of the execution stack at run-time captures the dynamic state of programs and can be used to derive useful insights into the program behaviour. The stack usage information can be used to identify and debug performance and security aspects of applications. Binary run-time instrumentation techniques are well known to capture the memory access traces during program execution. Tracing the program in entirety and filtering out stack specific accesses is a commonly used technique for stack related analysis. However, applying vanilla tracing techniques (using tools like Intel Pin) for multi-threaded programs has challenges such as identifying the stack areas to perform efficient run-time tracing.
K. P. Arun 0002, Saurabh Kumar 0007, Debadatta Mishra, Biswabandan Panda
MSR3
2022 AndroOBFS: Time-tagged Obfuscated Android Malware Dataset with Family Information
abstract
With the large-scale adaptation of Android OS and ever-increasing contributions in the Android application space, Android has become the number one target of malware writers. In recent years, a large number of automatic malware detection and classification systems have evolved to tackle the dynamic nature of malware growth using either static or dynamic analysis techniques. Performance of static malware detection methods degrade due to the obfuscation attacks. Although many benchmark datasets are available to measure the performance of malware detection and classification systems, only a single obfuscated malware dataset (PRAGuard) is available to showcase the efficacy of the existing malware detection systems against the obfuscation attacks. PRAGuard contains outdated samples till March 2013 and does not represent the latest application categories. Moreover, PRAGuard does not provide the family information for malware because of which PRAGuard can not be used to evaluate the efficacy of the malware family classification systems.
Saurabh Kumar 0007, Debadatta Mishra, Biswabandan Panda, Sandeep K. Shukla
MSR2
2022 Portkey: hypervisor-assisted container migration in nested cloud environments
abstract
Derivative cloud service providers use nesting to provision virtual computational entities (VCE) within VCEs, e.g., containers runtimes within virtual machines. As part of resource management and ensuring application performance, migration of nested containers is an important and useful mechanism. Checkpoint Restore In Userspace (CRIU) is the dominant method for migration, used by Docker and other container technologies. While CRIU works well for container migration from host to host, it suffers from significant increase in resource requirements in nested setups. The overheads are primarily due to the high network virtualization overhead in nested environments. While techniques such as SR-IOV can mitigate the overheads, they require additional hardware features and tight coupling of network endpoints. Based on our insights of network virtualization being the main bottleneck, we present Portkey - a software-based solution for efficient nested container migration that significantly reduces CPU utilization at both the source and destination hosts. Our solution relies on interposing a layer that directly coordinates network IO from within a virtual machine with the hypervisor. A new set of hypercalls provide this interfacing along with a control loop that minimizes the hypercall path usage. Extensive evaluation of our solution shows that Portkey reduces CPU usage by up to 75% and 82% at the source and destination hosts, respectively.
Debadatta Mishra, Purushottam Kulkarni, Umesh Bellur
VEE2
2021 Empirical Analysis of Architectural Primitives for NVRAM Consistency
abstract
Non-volatile memory (NVM) provides persistent memory semantics with access latencies comparable to volatile DRAM. The persistent nature of NVM requires the application developers to design data consistency mechanisms for failure recovery, without which application may end up with inconsistent memory state after a power failure or a system crash. Most commonly employed methods use architectural support for cache line flushing and memory fencing to enforce ordering of writes to NVM. In this paper, we study the performance overhead of different hardware primitives used to achieve NVM consistency on Intel x86-64 and Arm64 systems using micro-benchmarks. Further, we also empirically analyze the impact of working set size and memory access characteristics (read-to-write ratio) of applications on different data consistency techniques. Logging based mechanisms (e.g., redo and undo logging), commonly used for NVM consistency, also use underlying architectural primitives like cache flushing. We comparatively study the overheads of redo and undo logging with different architectural primitives. The analysis presented in this paper can be useful to improve the software/hardware architecture, develop efficient applications and perform better capacity planning in NVM systems.
K. P. Arun 0002, Debadatta Mishra, Biswabandan Panda
HiPC2
2021 DeepDetect: A Practical On-device Android Malware Detector
abstract
Over the past few years, Android has become one of the most popular operating systems for smartphones as it is open-source and provides extensive support for wide variety of applications. This has led to an increase in the number of malware targeting Android devices. The lack of robust security enforcement in Play Store along with the rapid increase in the number of new Android malware presents a scope for a variety of diverse malicious applications to spread across devices. Further-more, Android allows installation of an application from unver-ified sources (e.g., third-party market and sideloading), which opens up other ways for mal ware to infect the smartphones. This paper presents DeepDetect that enables on-device malware detection by employing a machine learning based model on static features. With effective feature engineering, DeepDetect can be used on-device. To classify an Android application as malware, it takes ~5.32 seconds, which is 2.23X faster than API based malware detector, while consuming 0.45 % (for 50 applications) of total device energy. DeepDetect provides a malware detection rate of 99.9% for known malware with a 0.01 % false-positive rate. For unseen/new samples, it detects more than 97 % mal ware with a false-positive rate of 1.73%. Further, in the presence of obfuscated malware, DeepDetect correctly detects 95.57 % of malware samples. We have also evaluated our model against the Pegasus malware sample and with a new dataset after removing the potential biases across space and time.
Saurabh Kumar 0007, Debadatta Mishra, Biswabandan Panda, Sandeep K. Shukla
QRS2
2021 Android Malware Family Classification: What Works - API Calls, Permissions or API Packages?
abstract
With the increased popularity and wide adoption of Android as a mobile OS platform, it has been a major target for malware authors. Due to unprecedented rapid growth in the number, variants, and diversity of malware, detecting malware on the Android platform has become challenging. Beyond the detection of a malware, classifying the family the malware belongs to, helps security analysts to reuse malware removal techniques that is known to work for that family of malware. It takes manual analysis if a malware belongs to an unknown family. Therefore, classifying malware into exact family is important. This paper presents a technique and tool named MAPFam that applies machine learning on static features from the Manifest file and API packages to classify an Android malware into its family. This work is premised on a starting hypothesis that features extracted from API packages rather than on API calls lead to more precise classification. Our experiments indeed shows that API package based models provides ∼1.63X more accurate classification compared to an API call based method. Our machine learning based malware family classification system uses API packages, requested permissions, and other features from the Manifest files. The proposed family classification system achieves accuracy and average precision above 97% for the top 60 malware families by using only 81 features with 97.55% of model reliability rate (Kappa score). The experimental results also shows that MAPFam can perfectly identity 36 malware families.
Saurabh Kumar 0007, Debadatta Mishra, Sandeep K. Shukla
SIN2
2021 Analysis of NVMe-SSD to passthrough GPU data transfer in virtualized systems
abstract
Non-volatile storage (NVM) technologies provide faster data access compared to traditional hard disk drives and can benefit applications executing on accelerators like general purpose graphics processing units (GPGPUs). Many contemporary GPU-friendly applications process huge volumes of data residing in the secondary storage. Several research work propose techniques to optimize data transfer overheads between devices connected to the same bus e.g., peer-to-peer data transfer between NVMe-SSD and GPU connected to a PCI bus. The applicability of these techniques, extent of their benefit and associated costs in virtualized systems is the scope of this paper.
Arunkumar Vediappan, Debadatta Mishra
VEE2
2020 STDNeut: Neutralizing Sensor, Telephony System and Device State Information on Emulated Android Environments
Saurabh Kumar 0007, Debadatta Mishra, Biswabandan Panda, Sandeep K. Shukla
CANS2
2019 Synergy: A Hypervisor Managed Holistic Caching System
abstract
Efficient system-wide memory management is an important challenge for over-commitment based hosting in virtualized systems. Due to the limitation of memory domains considered for sharing, current deduplication solutions simply cannot achieve system-wide deduplication. Popular memory management techniques like sharing and ballooning enable important memory usage optimizations individually. However, they do not complement each other and, in fact, may degrade individual benefits when combined. We propose $\mathsf{Synergy}$Synergy, a hypervisor managed caching system to improve memory efficiency in over-commitment scenarios. $\mathsf{Synergy}$Synergy builds on an exclusive caching framework to achieve, for the first time, system-wide memory deduplication. $\mathsf{Synergy}$Synergy also enables the co-existence of the mutually agnostic ballooning and sharing techniques within hypervisor managed systems. Finally, $\mathsf{Synergy}$Synergy implements a novel file-level eviction policy that prevents hypervisor caching benefits from being squandered away due to partial cache hits. $\mathsf{Synergy}$Synergy's cache is flexible with configuration knobs for cache sizing and data storage options, and a utility-based cache partitioning scheme. Our evaluation shows that $\mathsf{Synergy}$Synergy consistently uses 10 to 75 percent lesser memory by exploiting system-wide deduplication as compared to inclusive caching techniques and achieves application speedup of 2x to 23x. We also demonstrate the capabilities of $\mathsf{Synergy}$Synergy to increase VM packing density and support for dynamic reconfiguration of cache partitioning policies.
Debadatta Mishra, Purushottam Kulkarni, Raju Rangaswami
IEEE Trans. Cloud Comput.1
2017 DoubleDecker: a cooperative disk caching framework for derivative clouds
abstract
Derivative clouds, light weight application containers provisioned in virtual machines, are becoming viable and cost-effective options for infrastructure and software-based services. Ubiquitous dynamic memory management techniques in virtualized systems are centralized at the hypervisor and are ineffective in nested derivative cloud setups. In this paper, we highlight the challenges in management of memory resources in derivative cloud systems. Hypervisor caching, an enabler of centralized disk cache management, provides flexible memory or non-volatile memory management at the hypervisor to improve the resource usage efficiency and performance of applications. Existing hypervisor caching solutions have limited effectiveness in nested setups due to their nesting agnostic design, centralized management model and lack of holistic view of memory management. We propose DoubleDecker, a decentralized disk caching framework, realized through guest OS and hypervisor cooperation, with support for efficient memory management in derivative clouds. The DoubleDecker hypervisor caching framework, an integral part of our proposed solution, provides interfaces for differentiated cache partitioning and management in nested setups and is equipped to handle both memory and SSD based caching stores. We demonstrate the flexibility of DoubleDecker to handle dynamic and changing memory provisioning requirements and its capability to simultaneously provision memory across multiple levels. Such multi-level configurations cannot be explored by centralized designs and are a key feature of DoubleDecker. Our experimentation with DoubleDecker demonstrates that application performance can be consistently improved due to the flexible policy framework for disk caching. With our setup, we report an average performance improvement of 4x and a maximum of 11x.
Debadatta Mishra, Prashanth, Purushottam Kulkarni
Middleware1
2017 Catalyst: GPU-assisted rapid memory deduplication in virtualization environments
abstract
Content based page sharing techniques improve memory efficiency in virtualized systems by identifying and merging identical pages. Kernel Same-page Merging (KSM), a Linux kernel utility for page sharing, sequentially scans memory pages of virtual machines to deduplicate pages. Sequential scanning of pages has several undesirable side effects---wasted CPU cycles when no sharing opportunities exist, and rate of discovery of sharing being dependent on the scanning rate and corresponding CPU availability. In this work, we exploit presence of GPUs on modern systems to enable rapid memory sharing through targeted scanning of pages. Our solution, Catalyst, works in two phases, the first where pages of virtual machines are processed by the GPU to identify likely pages for sharing and a second phase that performs page-level similarity checks on a targeted set of shareable pages. Opportunistic usage of the GPU to produce sharing hints enables rapid and low-overhead duplicate detection, and sharing of memory pages in virtualization environments. We evaluate Catalyst against various benchmarks and workloads to demonstrate that Catalyst can achieve higher memory sharing in lesser time compared to different scan rate configurations of KSM, at lower or comparable compute costs.
Anshuj Garg, Debadatta Mishra, Purushottam Kulkarni
VEE2
2014 Vagabond: Dynamic Network Endpoint Reconfiguration in Virtualized Environments
abstract
One of the biggest challenges of virtualization today is to efficiently share and manage network devices among different virtual machines (VMs). Software-based network virtualization solutions like device emulation and split driver device models have advantages of resource sharing and fine grained hypervisor resource control. However, software based approaches have performance and scalability impediments due to the software interventions for every I/O activity. Recent hardware advancements in network devices allow in-device partitioning and assignment of network functions to different guest operating systems. The nature of the assignment is static which gives rise to inflexibility in efficient network resource management. Additionally, fine grained hypervisor control on the network device is compromised because of the direct hardware assignment to the guest virtual machine.
Kallol Dey, Debadatta Mishra, Purushottam Kulkarni
SoCC2
2014 Comparative Analysis of Page Cache Provisioning in Virtualized Environments
abstract
Efficient management of system memory plays a critical role in provisioning virtual machines, as it impacts levels of over-commitment and associated application performance. Typically, file accesses from a virtual machine traverse through different levels of page caches, which consume memory. Different configurations of page cache provisioning are possible, each providing different levels of memory utilization and performance levels. In this work, we study different page cache provisioning options with the KVM (Kernel Virtual Machine) virtual machine monitor solution. Our goal is to systematically understand possible provisioning use cases to compare their cost-benefit tradeoffs. Towards this we implement and evaluate tmem, an exclusive caching model (based on the transcendent memory model) for file blocks. Together with the tmem-caching model and existing page cache provisioning options, we present an empirical analysis of all cases. Our evaluation focuses on identifying actual caching needs, overheads and benefits for different combinations and identifies the relative benefits of each. We find that there is up-to 10x increase in disk read throughput with tmem-based caching and the CPU overheads for this technique are proportional to the gain in throughput.
Debadatta Mishra, Purushottam Kulkarni
MASCOTS1
2013 Share-o-meter: An empirical analysis of KSM based memory sharing in virtualized systems
abstract
Content based memory sharing in virtualized environments has proven to be a useful technique for over-commitment based placement of virtual machines. Kernel-based Virtual Machine (KVM) on Linux uses Kernel SamePage Merging (KSM) to identify and exploit sharing opportunities. In this paper, we present an analysis of page sharing across virtual machines by comparing page sharing achieved by KSM to total sharing opportunities presented by virtual machines. We study the impact of different KSM configurations, system resources, and workload characteristics on page sharing achieved by KSM. We also study the cost of sharing in terms of CPU utilization overhead from Copy-On-Write page breaks that occur on KSM shared pages. Our analysis is aimed at exploring the KSM configuration space towards obtaining desired sharing levels with minimal overheads for a given amount of system resources and workload characteristics. Our empirical analysis shows that for workloads exhibiting different memory usage patterns, different KSM configuration parameters are required to achieve maximum savings. We quantify the levels of savings and associated costs for several (individual and combinations) of workloads, exhibiting different sharing opportunities and memory usage characteristics. Further, we demonstrate the need for adaptive configuration of KSM's aggressiveness based on changes in total memory available for sharing and change in memory usage characteristics.
Shashank Rachamalla, Debadatta Mishra, Purushottam Kulkarni
HiPC2