VLDB 2026 Research / reviewers in the wild / expert
Anton Burtsev
dblp:28/7551
· DBLP profile ↗
24ranked-venue papers
7as first author
12since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 11 · 3 first-author · 6 since 2021Systems, architecture and hardware · 8 · 4 first-author · 2 since 2021Security and privacy · 4 · 4 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Beyond Driver Isolation - Triaging Threats against Driver IsolationabstractDevice driver isolation aims to protect kernels from faulty/malicious drivers, yet its security guarantees are not fully understood. Compartment Interface Vulnerabilities (CIVs), known in userspace applications, also impact driver isolation, but this area is underexplored. This paper surveys existing driver isolation frameworks, systematizes CIV classifications, and evaluates them in the driver isolation context. Our analysis reveals CIV prevalence under a baseline threat model, with large drivers exhibiting over 100 CIV instances and an average of 33 across the studied drivers. Enforcing additional security properties like CFI reduces average CIVs to approximately 28. This work offers insights into driver isolation security, CIV prevalence, and guidance for future systems. Yongzhe Huang, Kaiming Huang, Matthew Ennis, Vikram Narayanan, Anton Burtsev, Trent Jaeger, Gang Tan |
ACSAC | 5 |
| 2025 | Understanding the Security Impact of CHERI on the Operating System KernelabstractCapability Hardware Enhanced RISC Instructions (CHERI) is a set of hardware extensions that allow enforcement of spatial and temporal safety for unsafe programming languages like C. CHERI utilizes the concept of hardware capabilities to enforce bounds checks on all memory accesses and a hardware-assisted revocation scheme to enforce temporal safety. In theory, CHERI offers a surprising mix of practicality and strong security guarantees for traditionally unsafe environments like operating system kernels: capability extensions block a range of safety-related vulnerabilities common to low-level systems code while requiring only modest engineering effort. Our work takes a deep look at the potential impact of CHERI on the security of a commodity operating system kernel. We analyze a total of 439 kernel vulnerabilities in Linux and FreeBSD kernels. Our analysis shows that CHERI can block 61 % of kernel vulnerabilities if temporal safety is implemented in the kernel (35% if capability revocation is off). Enabling CHERI requires a modest effort, e.g., porting the FreeBSD kernel to support pure-capability mode of execution took 7 months. Finally, compared to Rust, which is able to mitigate 84% of kernel exploits, CHERI achieves the rate of 70% (38% if revocation is off). While CHERI is less effective, enabling it in the kernel requires a much lower development effort. Zhaofeng Li 0004, Jerry Zhang, Joshua Tlatelpa-Agustin, Anton Burtsev |
ACSAC | 5 |
| 2025 | Atmosphere: Practical Verified Kernels with Rust and VerusabstractRecent advances in programming languages and automated formal reasoning have changed the balance between the complexity and practicality of developing formally verified systems. Our work leverages Verus, a new verifier for Rust that combines ideas of linear types, permissioned reasoning, and automated verification based on satisfiability modulo theories (SMT), for the development of a formally verified microkernel, Atmosphere. Zhaofeng Li 0004, Jerry Zhang, Vikram Narayanan, Anton Burtsev |
SOSP | 5 |
| 2024 | Rust for Linux: Understanding the Security Impact of Rust in the Linux KernelabstractRust-for-Linux (RFL) is a new framework that allows development of Linux kernel extensions in Rust. At first glance, RFL is a huge step forward in terms of improving the security of the kernel: As a safe programming language, Rust can eliminate wide classes of low-level vulnerabilities. Yet, in practice, low-level driver code – complex driver interface, a combination of reference counting and manual memory management, arithmetic pointer and index operations, unsafe type casts, and numerous logical invariants about the data structures exchanged with the kernel might significantly limit the security impact of Rust.This work takes a careful look at how Rust can impact the security of driver code. Specifically, we ask the question: What classes (and what fraction) of vulnerabilities typically found in device driver code can be eliminated by reimplementing device drivers in Rust? We find that Rust can eliminate large classes of safety-related vulnerabilities, but naturally struggles to address protocol violations and semantic errors. Moreover, to be fully eliminated, many classes of flaws require careful programming discipline to avoid memory leaks and runtime panics (e.g., explicit checks for integer overflows and option types), careful implementation of Drop traits, as well as correct implementation of reference counting. Our analysis of 240 driver vulnerabilities that are present in device drivers in the last four years, shows that 82 could be automatically eliminated by Rust, 113 require specific programming idioms and developer’s involvement, and 45 remain unaffected by Rust. We hope that our work can improve the understanding of potential flaws in Rust drivers and result in more secure kernel code. Zhaofeng Li 0004, Vikram Narayanan, Jerry Zhang, Anton Burtsev |
ACSAC | 5 |
| 2024 | Limitations and Opportunities of Modern Hardware Isolation Mechanisms
Zhaofeng Li 0004, Tirth Jain, Vikram Narayanan, Anton Burtsev |
USENIX ATC | 5 |
| 2023 | Remote attestation of confidential VMs using ephemeral vTPMsabstractTrying to address the security challenges of a cloud-centric software deployment paradigm, silicon and cloud vendors are introducing confidential computing – an umbrella term aimed at providing hardware and software mechanisms for protecting cloud workloads from the cloud provider and its software stack. Today, Intel Software Guard Extensions (SGX), AMD secure encrypted virtualization (SEV), Intel trust domain extensions (TDX), etc., provide a way to shield cloud applications from the cloud provider through encryption of the application’s memory below the hardware boundary of the CPU, hence requiring trust only in the CPU vendor. Unfortunately, existing hardware mechanisms do not automatically enable the guarantee that a protected system was not tampered with during configuration and boot time. Such a guarantee relies on a hardware root of trust, i.e., an integrity-protected location that can store measurements in a trustworthy manner, extend them, and authenticate the measurement logs to the user (remote attestation). Vikram Narayanan, Cláudio Carvalho, Angelo Ruocco, Gheorghe Almási 0001, James Bottomley, Mengmei Ye, Tobin Feldman-Fitzthum, Daniele Buono, Hubertus Franke, Anton Burtsev |
ACSAC | 10 |
| 2023 | DRAMHiT: A Hash Table Architected for the Speed of DRAMabstractDespite decades of innovation, existing hash tables fail to achieve peak performance on modern hardware. Built around a relatively simple computation, i.e., a hash function, which in most cases takes only a handful of CPU cycles, hash tables should only be limited by the throughput of the memory subsystem. Unfortunately, due to the inherently random memory access pattern and the contention across multiple threads, existing hash tables spend most of their time waiting for the memory subsystem to serve cache misses and coherence requests. Vikram Narayanan, David Detweiler, Tianjiao Huang, Anton Burtsev |
EuroSys | 4 |
| 2023 | Evolving Operating System Kernels Towards Secure Kernel-Driver InterfacesabstractOur work explores the challenge of developing secure kernel-driver interfaces designed to protect the kernel from isolated kernel extensions. We first analyze a range of possible attack vectors that exist in current isolation frameworks. Then, we suggest a new approach to building secure isolation boundaries centered around ideas that originate in safe operating systems: isolation of heaps and single ownership. Anton Burtsev, Vikram Narayanan, Yongzhe Huang, Kaiming Huang, Gang Tan, Trent Jaeger |
HotOS | 1 |
| 2023 | Extending Rust with Support for Zero Copy CommunicationabstractIn contrast to hardware-based isolation solutions, language-based systems support crossing of isolation boundaries with an overhead of a function call. Moreover, the strong type system of a safe language provides support for secure communication in the face of complex, semantically-rich interfaces, i.e., support for fault isolation and end-to-end zero-copy communication through isolation of object spaces and controlled ownership on the shared exchange heap. If historically, safety was prohibitive due to overheads of a managed runtime, today, languages like Rust achieve the performance of unsafe C hence empowering language-based systems to support practical isolation with fine-grained boundaries and frequent communication. Arthur Lafrance, David Detweiler, Zhaofeng Li 0004, Vikram Narayanan, Anton Burtsev |
PLOS@SOSP | 6 |
| 2022 | KSplit: Automating Device Driver Isolation
Yongzhe Huang, Vikram Narayanan, David Detweiler, Kaiming Huang, Gang Tan, Trent Jaeger, Anton Burtsev |
OSDI | 7 |
| 2021 | Isolation in Rust: What is Missing?abstractRust is the first practical programming language that has the potential to provide fine-grained isolation of untrusted computations at the language level. A combination of zero-overhead safety, i.e., safety without a managed runtime and garbage collection, and a unique ownership discipline enable isolation in systems with tight performance budgets, e.g., databases, network processing frameworks, browsers, and even operating system kernels. Anton Burtsev, Dan Appel, David Detweiler, Tianjiao Huang, Zhaofeng Li 0004, Vikram Narayanan, Gerd Zellweger |
PLOS@SOSP | 1 |
| 2021 | Understanding the Overheads of Hardware and Language-Based IPC MechanismsabstractA recent surge of security attacks has triggered a renewed interest in hardware support for isolation. Extended page table switching with VMFUNC, memory protection keys (MPK), and memory tagging extensions (MTE) are just a few of the hardware isolation mechanisms that promise support for low-overhead isolation in recent CPUs. Along with the restored interest in lightweight hardware isolation mechanisms, safe programming languages like Rust has made a leap towards practical, zero-overhead safety implemented without garbage collection. Zhaofeng Li 0004, Tianjiao Huang, Vikram Narayanan, Anton Burtsev |
PLOS@SOSP | 4 |
| 2020 | Advances in Cryptography and Secure Hardware for Data OutsourcingabstractDespite extensive research, secure outsourcing remains an open challenge. This tutorial focuses on recent advances in secure cloud-based data outsourcing based on cryptographic (encryption, secret-sharing, and multi-party computation (MPC)) and hardware-based approaches. We highlight the strengths and weaknesses of state-of-the-art techniques, and conclude that, while no single approach is likely to emerge as a silver bullet. Thus, the key is to merge different hardware and software techniques to work in conjunction using partitioned computing wherein a computation is split across different cryptographic techniques carefully, so as not to compromise security. We highlight some recent work in that direction. Shantanu Sharma 0001, Anton Burtsev, Sharad Mehrotra |
ICDE | 2 |
| 2020 | RedLeaf: Isolation and Communication in a Safe Operating System
Vikram Narayanan, Tianjiao Huang, David Detweiler, Dan Appel, Zhaofeng Li 0004, Gerd Zellweger, Anton Burtsev |
OSDI | 7 |
| 2020 | Lightweight kernel isolation with virtualization and VM functionsabstractCommodity operating systems execute core kernel subsystems in a single address space along with hundreds of dynamically loaded extensions and device drivers. Lack of isolation within the kernel implies that a vulnerability in any of the kernel subsystems or device drivers opens a way to mount a successful attack on the entire kernel. Vikram Narayanan, Yongzhe Huang, Gang Tan, Trent Jaeger, Anton Burtsev |
VEE | 5 |
| 2019 | RedLeaf: Towards An Operating System for Safe and Verified FirmwareabstractRedLeaf is a new operating system being developed from scratch to utilize formal verification for implementing provably secure firmware. RedLeaf is developed in a safe language, Rust, and relies on automated reasoning using satisfiability modulo theories (SMT) solvers for formal verification. RedLeaf builds on two premises: (1) Rust's linear type system enables practical language safety even for systems with tightest performance and resource budgets (e.g., firmware), and (2) a combination of SMT-based reasoning and pointer discipline enforced by linear types provides a unique way to automate and simplify verification effort scaling it to the size of a small OS kernel. Vikram Narayanan, Marek S. Baranowski, Leonid Ryzhyk, Zvonimir Rakamaric, Anton Burtsev |
HotOS | 5 |
| 2019 | LXDs: Towards Isolation of Kernel Subsystems
Vikram Narayanan, Abhiram Balasubramanian, Charlie Jacobsen, Sarah Spall, Scotty Bauer, Michael Quigley, Aftab Hussain 0001, Abdullah Younis, Junjie Shen 0001, Moinak Bhattacharyya, Anton Burtsev |
USENIX ATC | 11 |
| 2017 | CapNet: security and least authority in a capability-enabled cloudabstractWe present CapNet, a capability-based network architecture designed to enable least authority and secure collaboration in the cloud. CapNet allows fine-grained management of rights, recursive delegation, hierarchical policies, and least privilege. To enable secure collaboration, CapNet extends a classical capability model with support for decentralized authority. We implement CapNet in the substrate of a software-defined network, integrate it with the OpenStack cloud, and develop protocols enabling secure multi-party collaboration. Anton Burtsev, David Johnson 0004, Josh Kunz, Eric Eide, Jacobus E. van der Merwe |
SoCC | 1 |
| 2017 | System Programming in Rust: Beyond SafetyabstractRust is a new system programming language that offers a practical and safe alternative to C. Rust is unique in that it enforces safety without runtime overhead, most importantly, without the overhead of garbage collection. While zero-cost safety is remarkable on its own, we argue that the superpowers of Rust go beyond safety. In particular, Rust's linear type system enables capabilities that cannot be implemented efficiently in traditional languages, both safe and unsafe, and that dramatically improve security and reliability of system software. We show three examples of such capabilities: zero-copy software fault isolation, efficient static information flow analysis, and automatic checkpointing. While these capabilities have been in the spotlight of systems research for a long time, their practical use is hindered by high cost and complexity. We argue that with the adoption of Rust these mechanisms will become commoditized. Abhiram Balasubramanian, Marek S. Baranowski, Anton Burtsev, Aurojit Panda, Zvonimir Rakamaric, Leonid Ryzhyk |
HotOS | 3 |
| 2016 | Abstractions for Practical Virtual Machine ReplayabstractEfficient deterministic replay of whole operating systems is feasible and useful, so why isn't replay a default part of the software stack? While implementing deterministic replay is hard, we argue that the main reason is the lack of general abstractions for understanding and addressing the significant engineering challenges involved in the development of a replay engine for a modern VMM. We present a design blueprint---a set of abstractions, general principles, and low-level implementation details---for efficient deterministic replay in a modern hypervisor. We build and evaluate our architecture in Xen, a full-featured hypervisor. Our architecture can be readily followed and adopted, enabling replay as a ubiquitous part of a modern virtualization stack. Anton Burtsev, David Johnson 0004, Mike Hibler, Eric Eide, John Regehr |
VEE | 1 |
| 2015 | Lightweight capability domains: towards decomposing the Linux kernelabstractDespite a number of radical changes in how computer systems are used, the design principles behind the very core of the systems stack---an operating system kernel---has remained unchanged for decades. We run monolithic kernels developed with a combination of an unsafe programming language, global sharing of data structures, opaque interfaces, and no explicit knowledge of kernel protocols. Today, the monolithic architecture of a kernel is the main factor undermining its security, and even worse, limiting its evolution towards a safer, more secure environment. Lack of isolation across kernel subsystems allows attackers to take control over the entire machine with a single kernel vulnerability. Furthermore, complex, semantically rich monolithic code with globally shared data structures and no explicit interfaces is not amenable to formal analysis and verification tools. Even after decades of work to make monolithic kernels more secure, over a hundred serious kernel vulnerabilities are still reported every year. Charles Jacobsen, Muktesh Khole, Sarah Spall, Scotty Bauer, Anton Burtsev |
PLOS@SOSP | 5 |
| 2013 | Weir: a streaming language for performance analysisabstractFor modern software systems, performance analysis can be a challenging task. The software stack can be a complex, multi-layer, multi-component, concurrent, and parallel environment with multiple contexts of execution and multiple sources of performance data. Although much performance data is available, because modern systems incorporate many mature data-collection mechanisms, analysis algorithms suffer from the lack of a unifying programming environment for processing the collected performance data, potentially from multiple sources, in a convenient and script-like manner. Anton Burtsev, Nikhil Mishrikoti, Eric Eide, Robert Ricci |
PLOS@SOSP | 1 |
| 2009 | Transparent checkpoints of closed distributed systems in EmulababstractEmulab is a testbed for networked and distributed systems experimentation. Two guiding principles of its design are realism and control of experimentation. There is an inherent tension between these goals, however, and in some aspects of the testbed's design, Emulab's implementers favored realism over control. Thus, Emulab provides wide-ranging control over an experiment's environment and initial conditions, but relatively little control over its execution--in particular, the ability to suspend, preempt, or replay the experiment. Anton Burtsev, Prashanth Radhakrishnan, Mike Hibler, Jay Lepreau |
EuroSys | 1 |
| 2009 | Fido: Fast Inter-Virtual-Machine Communication for Enterprise Appliances
Anton Burtsev, Kiran Srinivasan, Prashanth Radhakrishnan, Kaladhar Voruganti, Garth R. Goodson |
USENIX ATC | 1 |