Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Lisong Pan

dblp:340/1258 · DBLP profile ↗
← Back
3ranked-venue papers
0as first author
3since 2021 · last 2026
0009-0008-0720-2867ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 3 · 3 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
2 papers
Operating systems · 100%
Network and information security
1 paper
Systems and software security · 100%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Cloud and datacenter computing · 100%

Topics — the 10 heaviest of 10, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security › virtualization security
container security
0.812024
vKernel: Enhancing Container Isolation via Private Code and Data · IEEE Trans. Computers 2024
Systems and software security
operating system security
0.812024
vKernel: Enhancing Container Isolation via Private Code and Data · IEEE Trans. Computers 2024
Operating systems › system security › operating system security › protection mechanism › isolation
container isolation
0.812024
vKernel: Enhancing Container Isolation via Private Code and Data · IEEE Trans. Computers 2024
Operating systems
kernel customization
0.812024
vKernel: Enhancing Container Isolation via Private Code and Data · IEEE Trans. Computers 2024
Operating systems › system security › operating system security › protection mechanism › isolation
kernel isolation
0.812024
vKernel: Enhancing Container Isolation via Private Code and Data · IEEE Trans. Computers 2024
Operating systems › system security
operating system security
0.812024
vKernel: Enhancing Container Isolation via Private Code and Data · IEEE Trans. Computers 2024
Operating systems
virtualization
0.812024
vKernel: Enhancing Container Isolation via Private Code and Data · IEEE Trans. Computers 2024
Operating systems › resource management › process management
CPU scheduling
0.712023
Adapt Burstable Containers to Variable CPU Resources · IEEE Trans. Computers 2023
Cloud and datacenter computing
container management
0.712023
Adapt Burstable Containers to Variable CPU Resources · IEEE Trans. Computers 2023
Cloud and datacenter computing › virtualization
containerization
0.212023
Adapt Burstable Containers to Variable CPU Resources · IEEE Trans. Computers 2023

Methods — techniques the papers use, named apart from their topics

virtual kernel instance · 1.5inline hooks · 1.5virtual blocking · 1.3user-level adaptive scheduling · 1.3busy-waiting detection · 1.3
YearPublicationVenuePosition
2026 KPT-Fork: Enhancing User Data Isolation via Kernel Page Table Fork
abstract
Modern operating systems (OS) utilize a shared kernel address design, enabling the OS kernel to access physical memory addresses conveniently and efficiently. However, this design introduces vulnerabilities that attackers can exploit to arbitrarily read/write content from any kernel-space address, known as data-oriented attacks. Existing MMU-based isolation approaches face inherent challenges in scalability, compatibility, and context switch overhead. Inspired by the reference kernel page table, we propose to use user-private reference kernel page tables (UP-KPTs) as the foundation for data isolation in a shared kernel address space. A UP-KPT is a customized kernel page table tailored for a specific container, encompassing address mappings of private user data that are not visible to other containers. To protect sensitive system-wide data, an administrator can unmap such data from UP-KPTs and make it inaccessible to potentially malicious containers. UP-KPT provides strong data isolation while maintaining full compatibility with legacy applications and existing kernel components. We develop KPT-fork, a kernel isolation framework that enables the creation and management of UP-KPTs. KPT-fork entails two important designs: 1) a UP-KPT structure that enables data isolation while preserving the simplicity, convenience, and efficiency of a shared kernel page table; 2) a private memory allocator that efficiently transforms static and direct address mappings of private data in shared kernel addresses into dynamic user-private mappings. We demonstrate through three case studies that KPT-fork can be extended to protect various types of data. Our evaluation shows that KPT fork can defend against a wide range of data-oriented attacks while incurring negligible overhead.
Zixuan Wang 0030, Lisong Pan, Jia Rao, Hao Fan 0006, Song Wu 0001
IEEE Trans. Cloud Comput.2
2024 vKernel: Enhancing Container Isolation via Private Code and Data
abstract
Container technology is increasingly adopted in cloud environments. However, the lack of isolation in the shared kernel becomes a significant barrier to the wide adoption of containers. The challenges lie in how to simultaneously attain high performance and isolation. On the one hand, kernel-level isolation mechanisms, such asseccomp,capabilities, andapparmor, achieve good performance without much overhead, but lack the support for per-container customization. On the other hand, user-level and VM-based isolation offer superior security guarantees and allow for customization since a container is assigned a dedicated kernel, however, at the cost of high overhead. We presentvKernel, a kernel isolation framework. It maintains a minimal set of code and data that are either sensitive or are prone to interference in a virtual kernel instance (vKI). vKernel relies on inline hooks to intercept and redirect requests sent to the host kernel to a vKI, where container-specific security rules, functions, and data are implemented. Through case studies, we demonstrate that under vKernel user-defined data isolation and kernel customization can be supported with a reasonable engineering effort. An evaluation of vKernel with micro-benchmarks, cloud services, real-world applications show that vKernel achieves good security guarantees, but with much less overhead.
Hang Huang, Jia Rao, Song Wu 0001, Hao Fan 0006, Chen Yu 0003, Hai Jin 0001, Kun Suo, Lisong Pan
IEEE Trans. Computers9
2023 Adapt Burstable Containers to Variable CPU Resources
abstract
In the age of the cloud-native, container technology, referred as OS-level virtualization, is increasingly adopted to deploy cloud applications. Compared with virtual machines, containers are lightweight and flexible in resource management. An important quality-of-service (QoS) class in container management is burstable container, whose resource limits are higher than the actual requests allowing a container to expand whenever demands ramp up and additional resources become available. However, efficiently managing burstable containers is challenging, especially for CPU resources. On the one hand, burstable containers should maintain sufficient concurrency, in the form of threads, to utilize extendable CPU resources. On the other hand, the degree of concurrency necessary for utilizing peak CPU resources leads to suboptimal performance when a container's CPU allocation is constrained. In this paper, we recommend that the number of threads in burstable containers should always be set to the CPU limit to guarantee extensibility. However, modern operating systems (OSes) fall short of efficiently managing thread oversubscription. First, the OS CPU scheduler is inefficient for scheduling excessive threads and lacks container awareness. Second, the existing blocking synchronization supported by the OS kernel is inefficient in handling the sleep and wakeup of excessive threads. Finally, the non-blocking synchronization may waste CPUs performing busy waiting when more than one thread in the run queue. To this end, we present a user-level adaptive container scheduler and two OS mechanisms,virtual blockingandbusy-waiting detection, to avoid inefficiency in managing burstable containers without requiring program code changes. Experimental results show that our approaches can keep burstable containers efficient while allowing the applications in containers to take advantage of additional CPUs. The performance gain under high system load is up to 29.7×.
Hang Huang, Jia Rao, Song Wu 0001, Hai Jin 0001, Duoqiang Wang, Kun Suo, Lisong Pan
IEEE Trans. Computers8