VLDB 2026 Research / reviewers in the wild / expert
Kelly Kaoudis
dblp:203/6456
· DBLP profile ↗
4ranked-venue papers
0as first author
3since 2021 · last 2024
0009-0009-1479-7069ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 2 since 2021Computer networks · 1Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | PolyTracker: Whole-Input Dynamic Information Flow TracingabstractWe present PolyTracker, a whole-program, whole-input dynamic information flow tracing (DIFT) framework. Given an LLVM compatible codebase or a binary that has been lifted to LLVM intermediate representation (IR), PolyTracker compiles it, adding static instrumentation. The instrumented program will run normally with modest performance overhead, but will additionally output a runtime trace artifact in the co-designed TDAG (Tainted Directed Acyclic Graph) format. TDAGs can be post-processed for a variety of analyses, including tracing every input byte through program execution. TDAGs can be generated either by running the program over a corpus of inputs or by employing a randomized input generator such as a fuzzer. PolyTracker traces (TDAGs) are useful not only for very localized, targeted dynamic program analysis as with smaller-scale DIFT: TDAGs are primarily intended for whole-program runtime exploration and bug finding, granular information-flow diffing between program runs, and comparisons of implementations of the same input specification without any need to emulate and instrument the entire running environment. For user-friendliness and reproducibility, the software repository provides a number of examples of PolyTracker-instrumented builds of popular open-source software projects. We also provide an analysis library and REPL written in Python that are designed to assist users with operating over TDAGs. Evan Sultanik, Marek Surovic, Henrik Brodin, Kelly Kaoudis, Facundo Tuesca, Carson Harmon, Lisa Overall, Joseph Sweeney, Bradford Larsen |
ISSTA | 4 |
| 2024 | Endokernel: A Thread Safe Monitor for Lightweight Subprocess Isolation
Fangfei Yang, Bumjin Im, Weijie Huang 0001, Kelly Kaoudis, Anjo Vahldiek-Oberwagner, Chia-Che Tsai, Nathan Dautenhahn |
USENIX Security Symposium | 4 |
| 2023 | Endoprocess: Programmable and Extensible Subprocess IsolationabstractModern applications combine multiple components into single processes, leading to complex tradeoffs between isolation, performance, and programmability. We present the Endoprocess, a unique, microkernel-based approach for protection within process spaces. An endoprocess safely multiplexes process resources by exporting a low-level abstraction, the subprocess, that is transparently overlaid on existing process interfaces (like mmap, mprotect, etc), and provides extensibility and programmability through custom application-layer modules. We report experimental results of an initial prototype and highlight several application domains. Overall, the endoprocess presents a path for protection within processes while remaining compatible with existing OS abstractions and multiplexing them in a secure and extensible way. Fangfei Yang, Weijie Huang 0001, Kelly Kaoudis, Anjo Vahldiek-Oberwagner, Nathan Dautenhahn |
NSPW | 3 |
| 2017 | Augmenting cloud architectures to support decentralized applicationsabstractDespite the benefits of decentralized applications in terms of resilience and privacy, the overwhelming majority of applications with mainstream adoption are provided in a centralized manner. We argue that this is due to the direct benefits to the developer that centralization provides in terms of performance, monetization, and deployability. In this paper we introduce a new model, untrusted delegation, which joins the simplified deployment model of centralization with the benefits of decentralization. In this model, we decouple administrative ownership from administrative management, and leverage the existence of either a private cloud infrastructure, or a public cloud provider that acts as a neutral third party, that is augmented to support decentralization. Our initial prototype integrates with the Digital Ocean API and as a proof-of-concept, we can deploy Tor relay nodes with users only needing to sign up for a Digital Ocean account. Michael Coughlin, Kelly Kaoudis, Eric Keller |
IM | 2 |