VLDB 2026 Research / reviewers in the wild / expert
Lisong Pan
dblp:340/1258
· DBLP profile ↗
3ranked-venue papers
0as first author
3since 2021 · last 2026
0009-0008-0720-2867ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 3 · 3 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
2 papers |
Operating systems · 100% | |
| Network and information security
1 paper |
Systems and software security · 100% | |
| Computer architecture, parallel and distributed computing, and storage systems
1 paper |
Cloud and datacenter computing · 100% |
Topics — the 10 heaviest of 10, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security › virtualization security
container security |
0.8 | 1 | 2024 | vKernel: Enhancing Container Isolation via Private Code and Data · IEEE Trans. Computers 2024 |
Systems and software security
operating system security |
0.8 | 1 | 2024 | vKernel: Enhancing Container Isolation via Private Code and Data · IEEE Trans. Computers 2024 |
Operating systems › system security › operating system security › protection mechanism › isolation
container isolation |
0.8 | 1 | 2024 | vKernel: Enhancing Container Isolation via Private Code and Data · IEEE Trans. Computers 2024 |
Operating systems
kernel customization |
0.8 | 1 | 2024 | vKernel: Enhancing Container Isolation via Private Code and Data · IEEE Trans. Computers 2024 |
Operating systems › system security › operating system security › protection mechanism › isolation
kernel isolation |
0.8 | 1 | 2024 | vKernel: Enhancing Container Isolation via Private Code and Data · IEEE Trans. Computers 2024 |
Operating systems › system security
operating system security |
0.8 | 1 | 2024 | vKernel: Enhancing Container Isolation via Private Code and Data · IEEE Trans. Computers 2024 |
Operating systems
virtualization |
0.8 | 1 | 2024 | vKernel: Enhancing Container Isolation via Private Code and Data · IEEE Trans. Computers 2024 |
Operating systems › resource management › process management
CPU scheduling |
0.7 | 1 | 2023 | Adapt Burstable Containers to Variable CPU Resources · IEEE Trans. Computers 2023 |
Cloud and datacenter computing
container management |
0.7 | 1 | 2023 | Adapt Burstable Containers to Variable CPU Resources · IEEE Trans. Computers 2023 |
Cloud and datacenter computing › virtualization
containerization |
0.2 | 1 | 2023 | Adapt Burstable Containers to Variable CPU Resources · IEEE Trans. Computers 2023 |
Methods — techniques the papers use, named apart from their topics
virtual kernel instance · 1.5inline hooks · 1.5virtual blocking · 1.3user-level adaptive scheduling · 1.3busy-waiting detection · 1.3
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | KPT-Fork: Enhancing User Data Isolation via Kernel Page Table ForkabstractModern operating systems (OS) utilize a shared kernel address design, enabling the OS kernel to access physical memory addresses conveniently and efficiently. However, this design introduces vulnerabilities that attackers can exploit to arbitrarily read/write content from any kernel-space address, known as data-oriented attacks. Existing MMU-based isolation approaches face inherent challenges in scalability, compatibility, and context switch overhead. Inspired by the reference kernel page table, we propose to use user-private reference kernel page tables (UP-KPTs) as the foundation for data isolation in a shared kernel address space. A UP-KPT is a customized kernel page table tailored for a specific container, encompassing address mappings of private user data that are not visible to other containers. To protect sensitive system-wide data, an administrator can unmap such data from UP-KPTs and make it inaccessible to potentially malicious containers. UP-KPT provides strong data isolation while maintaining full compatibility with legacy applications and existing kernel components. We develop KPT-fork, a kernel isolation framework that enables the creation and management of UP-KPTs. KPT-fork entails two important designs: 1) a UP-KPT structure that enables data isolation while preserving the simplicity, convenience, and efficiency of a shared kernel page table; 2) a private memory allocator that efficiently transforms static and direct address mappings of private data in shared kernel addresses into dynamic user-private mappings. We demonstrate through three case studies that KPT-fork can be extended to protect various types of data. Our evaluation shows that KPT fork can defend against a wide range of data-oriented attacks while incurring negligible overhead. Zixuan Wang 0030, Lisong Pan, Jia Rao, Hao Fan 0006, Song Wu 0001 |
IEEE Trans. Cloud Comput. | 2 |
| 2024 | vKernel: Enhancing Container Isolation via Private Code and DataabstractContainer technology is increasingly adopted in cloud environments. However, the lack of isolation in the shared kernel becomes a significant barrier to the wide adoption of containers. The challenges lie in how to simultaneously attain high performance and isolation. On the one hand, kernel-level isolation mechanisms, such asseccomp,capabilities, andapparmor, achieve good performance without much overhead, but lack the support for per-container customization. On the other hand, user-level and VM-based isolation offer superior security guarantees and allow for customization since a container is assigned a dedicated kernel, however, at the cost of high overhead. We presentvKernel, a kernel isolation framework. It maintains a minimal set of code and data that are either sensitive or are prone to interference in a virtual kernel instance (vKI). vKernel relies on inline hooks to intercept and redirect requests sent to the host kernel to a vKI, where container-specific security rules, functions, and data are implemented. Through case studies, we demonstrate that under vKernel user-defined data isolation and kernel customization can be supported with a reasonable engineering effort. An evaluation of vKernel with micro-benchmarks, cloud services, real-world applications show that vKernel achieves good security guarantees, but with much less overhead. Hang Huang, Jia Rao, Song Wu 0001, Hao Fan 0006, Chen Yu 0003, Hai Jin 0001, Kun Suo, Lisong Pan |
IEEE Trans. Computers | 9 |
| 2023 | Adapt Burstable Containers to Variable CPU ResourcesabstractIn the age of the cloud-native, container technology, referred as OS-level virtualization, is increasingly adopted to deploy cloud applications. Compared with virtual machines, containers are lightweight and flexible in resource management. An important quality-of-service (QoS) class in container management is burstable container, whose resource limits are higher than the actual requests allowing a container to expand whenever demands ramp up and additional resources become available. However, efficiently managing burstable containers is challenging, especially for CPU resources. On the one hand, burstable containers should maintain sufficient concurrency, in the form of threads, to utilize extendable CPU resources. On the other hand, the degree of concurrency necessary for utilizing peak CPU resources leads to suboptimal performance when a container's CPU allocation is constrained. In this paper, we recommend that the number of threads in burstable containers should always be set to the CPU limit to guarantee extensibility. However, modern operating systems (OSes) fall short of efficiently managing thread oversubscription. First, the OS CPU scheduler is inefficient for scheduling excessive threads and lacks container awareness. Second, the existing blocking synchronization supported by the OS kernel is inefficient in handling the sleep and wakeup of excessive threads. Finally, the non-blocking synchronization may waste CPUs performing busy waiting when more than one thread in the run queue. To this end, we present a user-level adaptive container scheduler and two OS mechanisms,virtual blockingandbusy-waiting detection, to avoid inefficiency in managing burstable containers without requiring program code changes. Experimental results show that our approaches can keep burstable containers efficient while allowing the applications in containers to take advantage of additional CPUs. The performance gain under high system load is up to 29.7×. Hang Huang, Jia Rao, Song Wu 0001, Hai Jin 0001, Duoqiang Wang, Kun Suo, Lisong Pan |
IEEE Trans. Computers | 8 |