VLDB 2026 Research / reviewers in the wild / expert
Nayeem Islam
dblp:38/3967
· DBLP profile ↗
18ranked-venue papers
6as first author
0since 2021 · last 2007
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 6 · 5 first-authorSoftware engineering, systems software and programming languages · 6Security and privacy · 3Applied, interdisciplinary, general and emerging computing · 2Databases, data management, data science and information retrieval · 1Theory of computation · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
5 papers |
Program verification · 53% Program analysis · 21% Programming languages and type systems · 21% | |
| Computer architecture, parallel and distributed computing, and storage systems
3 papers |
Distributed systems · 55% Memory systems · 20% Cloud and datacenter computing · 14% | |
| Network and information security
2 papers |
Web and mobile security · 78% Systems and software security · 22% | |
| Computer networks
1 paper |
Wireless networking · 100% |
Topics — the 19 heaviest of 21, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Web and mobile security
browser security |
0.1 | 1 | 2007 | JavaScript instrumentation for browser security · POPL 2007 |
Program analysis
dynamic analysis |
0.1 | 1 | 2007 | JavaScript instrumentation for browser security · POPL 2007 |
Program verification › program logic
hoare logic |
0.1 | 1 | 2007 | Enforcing resource bounds via static verification of dynamic checks · ACM Trans. Program. Lang. Syst. 2007 |
Programming languages and type systems
language semantics |
0.1 | 1 | 2007 | JavaScript instrumentation for browser security · POPL 2007 |
Programming languages and type systems › language semantics › formal semantics
operational semantics |
0.1 | 1 | 2007 | JavaScript instrumentation for browser security · POPL 2007 |
Program analysis
program rewriting |
0.1 | 1 | 2007 | JavaScript instrumentation for browser security · POPL 2007 |
Program verification › quantitative verification
resource bound verification |
0.1 | 1 | 2007 | Enforcing resource bounds via static verification of dynamic checks · ACM Trans. Program. Lang. Syst. 2007 |
Program verification › quantitative verification
resource verification |
0.1 | 1 | 2007 | Enforcing resource bounds via static verification of dynamic checks · ACM Trans. Program. Lang. Syst. 2007 |
Program verification
static verification |
0.1 | 1 | 2007 | Enforcing resource bounds via static verification of dynamic checks · ACM Trans. Program. Lang. Syst. 2007 |
Program verification › code-level verification
java verification |
0.1 | 1 | 2005 | JVer: A Java Verifier · CAV 2005 |
Distributed systems
replication |
0.0 | 1 | 2004 | Flexible on-device service object replication with replets · WWW 2004 |
Program verification
dynamic verification |
0.0 | 1 | 2007 | Enforcing resource bounds via static verification of dynamic checks · ACM Trans. Program. Lang. Syst. 2007 |
Systems and software security
operating system security |
0.0 | 1 | 1998 | Operating System Protection for Fine-Grained Programs · USENIX Security Symposium 1998 |
Memory systems
cache |
0.0 | 1 | 1998 | High-Performance Caching With The Lava Hit-Server · USENIX ATC 1998 |
Wireless networking › mobile computing
disconnected operation |
0.0 | 1 | 2004 | Flexible on-device service object replication with replets · WWW 2004 |
Wireless networking
mobile computing |
0.0 | 1 | 2004 | Flexible on-device service object replication with replets · WWW 2004 |
Cloud and datacenter computing
virtualization |
0.0 | 1 | 2004 | Flexible on-device service object replication with replets · WWW 2004 |
Distributed systems › operating system support › interprocess communication
message-passing systems |
0.0 | 1 | 1992 | Design Considerations for Shared Memory Multiprocessor Message Systems · IEEE Trans. Parallel Distributed Syst. 1992 |
Parallel and multicore computing › multiprocessor system
shared-memory multiprocessor |
0.0 | 1 | 1992 | Design Considerations for Shared Memory Multiprocessor Message Systems · IEEE Trans. Parallel Distributed Syst. 1992 |
Methods — techniques the papers use, named apart from their topics
rewriting · 0.1program instrumentation · 0.1replication · 0.1caching · 0.1static analysis · 0.1linear inequalities · 0.1hoare logic · 0.1comparative measurement · 0.0benchmarking · 0.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2007 | JavaScript instrumentation for browser securityabstractIt is well recognized that JavaScript can be exploited to launch browser-based security attacks. We propose to battle such attacks using program instrumentation. Untrusted JavaScript code goes through a rewriting process which identifies relevant operations, modifies questionable behaviors, and prompts the user (a web page viewer) for decisions on how to proceed when appropriate. Our solution is parametric with respect to the security policy-the policy is implemented separately from the rewriting, and the same rewriting process is carried out regardless of which policy is in use. Be-sides providing a rigorous account of the correctness of our solution, we also discuss practical issues including policy management and prototype experiments. A useful by-product of our work is an operational semantics of a core subset of JavaScript, where code embedded in (HTML) documents may generate further document pieces (with new code embedded) at runtime, yielding a form of self-modifying code. Dachuan Yu, Ajay Chander, Nayeem Islam, Igor Serikov |
POPL | 3 |
| 2007 | Enforcing resource bounds via static verification of dynamic checksabstractWe show how to limit a program's resource usage in an efficient way, using a novel combination of dynamic checks and static analysis. Usually, dynamic checking is inefficient due to the overhead of checks, while static analysis is difficult and rejects many safe programs. We propose a hybrid approach that solves these problems. We split each resource-consuming operation into two parts. The first is a dynamic check, called reserve. The second is the actual operation, called consume, which does not perform any dynamic checks. The programmer is then free to hoist and combine reserve operations. Combining reserve operations reduces their overhead, while hoisting reserve operations ensures that the program does not run out of resources at an inconvenient time. A static verifier ensures that the program reserves resources before it consumes them. This verification is both easier and more flexible than an a priori static verification of resource usage. We present a sound and efficient static verifier based on Hoare logic and linear inequalities. As an example, we present a version of tar written in Java. Ajay Chander, David Espinosa, Nayeem Islam, Peter Lee 0001, George C. Necula |
ACM Trans. Program. Lang. Syst. | 3 |
| 2006 | A Typed Assembly Language for Confidentiality
Dachuan Yu, Nayeem Islam |
ESOP | 2 |
| 2005 | JVer: A Java Verifier
Ajay Chander, David Espinosa, Nayeem Islam, Peter Lee 0001, George C. Necula |
CAV | 3 |
| 2005 | HAIL: a language for easy and correct device accessabstractIt is difficult to write device drivers. One factor is that writing low-level code for accessing devices and manipulating their registers is tedious and error-prone. For many system-on-chip based systems, buggy hardware, imprecise documentation, and code reuse worsen the situation further. This paper presents HAIL (Hardware Access Interface Language), a language-based approach to simplify device access programming and generate error checking code against bugs in software, hardware, and documentation. HAIL is a domain-specific language that specifies all aspects of a device's programming interface and the access methods in a particular system and OS. A compiler automatically checks the specification and translates it into C code for device access, with optional debugging code. The generated code can be included directly into device driver code. In the paper, we argue that HAIL lowers development effort, incurs minimal runtime overhead, and reduces device access related bugs. We also show that the HAIL specification can be reused for different operating systems, thereby reducing porting costs. Jun Sun 0002, Wanghong Yuan, Mahesh Kallahalla, Nayeem Islam |
EMSOFT | 4 |
| 2005 | Enforcing Resource Bounds via Static Verification of Dynamic Checks
Ajay Chander, David Espinosa, Nayeem Islam, Peter Lee 0001, George C. Necula |
ESOP | 3 |
| 2004 | Dynamically Programmable and Reconfigurable Middleware Services
Manuel Román, Nayeem Islam |
Middleware | 2 |
| 2004 | Flexible on-device service object replication with repletsabstractAn increasingly large amount of Web applications employ service objects such as Servlets to generate dynamic and personalized content. Existing caching infrastructures are not well suited for caching such content in mobile environments because of disconnection and weak connection. One possible approach to this problem is to replicate Web-related application logic to client devices. The challenges to this approach are to deal with client devices that exhibit huge divergence in resource availabilities, to support applications that have different data sharing and coherency requirements, and to accommodate the same application under different deployment environments. Nayeem Islam, Ali Ismael |
WWW | 2 |
| 1999 | Flexible Control of Downloaded Executable ContentabstractWe present a security architecture that enables system and application a ccess control requirements to be enforced on applications composed from downloaded executable content. Downloaded executable content consists of messages downloaded from remote hosts that contain executables that run, upon receipt, on the downloading principal's machine. Unless restricted, this content can perform malicious actions, including accessing its downloading principal's private data and sending messages on this principal's behalf. Current security architectures for controlling downloaded executable content (e.g., JDK 1.2) enable specification of access control requirements for content based on its provider and identity. Since these access control requirements must cover every legal use of the class, they may include rights that are not necessary for a particular application of content. Therefore, using these systems, an application composed from downloaded executable content cannot enforce its access control requirements without the addition of application-specific security mechanisms. In this paper, we define an access control model with the following properties: (1) system administrators can define system access control requirements on applications and (2) application developers can use the same model to enforce application access control requirements without the need for ad hoc security mechanisms. This access control model uses features of role-based access control models to enable (1) specification of a single role that applies to multiple application instances; (2) selection of a content's access rights based on the content's application and role in the application; (3) consistency maintained between application state and content access rights; and (4) control of role administration. We detail a system architecture that uses this access control model to implement secure collaborative applications. Lastly, we describe an implementation of this architecture, called the Lava security architecture. Trent Jaeger, Atul Prakash 0001, Jochen Liedtke, Nayeem Islam |
ACM Trans. Inf. Syst. Secur. | 4 |
| 1998 | High-Performance Caching With The Lava Hit-Server
Jochen Liedtke, Vsevolod Panteleenko, Trent Jaeger, Nayeem Islam |
USENIX ATC | 4 |
| 1998 | Operating System Protection for Fine-Grained Programs
Trent Jaeger, Jochen Liedtke, Nayeem Islam |
USENIX Security Symposium | 3 |
| 1997 | Extensible Resource Management for Cluster ComputingabstractAdvanced general purpose parallel systems should be able to support diverse applications with different resource requirements without compromising effectiveness and efficiency. We present a resource management model for cluster computing that allows multiple scheduling policies to co-exist dynamically. In particular, we have built Octopus, an extensible and distributed hierarchical scheduler that implements new space sharing, gang scheduling and load sharing strategies. A series of experiments performed on an IBM SP2 suggest that Octopus can effectively match application requirements to available resources, and improve the performance of a variety of parallel applications within a cluster. Nayeem Islam, Andreas L. Prodromidis, Mark S. Squillante, Ajei S. Gopal, Liana L. Fong |
ICDCS | 1 |
| 1997 | A Flexible Security Model for Using Internet ContentabstractJava applets, Netscape plug-ins and ActiveX controls have led to the popularization of a new paradigm: extensive downloading of executable code into applications to enhance the functionality of the desktop. One of the problems with this paradigm is the need to control the access rights of the downloaded content. In this paper, we describe a system for downloading content from the Internet and controlling its actions on a client machine. Our system generates a protection domain for the downloaded content dynamically rising the content's requested domain and a policy database that describes the user's trust in the content's manufacturer and type. Our system ensures that this protection domain is enforced throughout the execution of the content. We have modified the Java Virtual Machine to implement our security model. Our implementation, called Flexxguard, is freely available at http://www.alphaworks.ibm.com. Rangachari Anand, Nayeem Islam, Trent Jaeger, Josyula R. Rao |
SRDS | 2 |
| 1997 | Customized Message Passing
Nayeem Islam |
J. Parallel Distributed Comput. | 1 |
| 1996 | Communication Compilation for Unreliable NetworksabstractParallel programs running on top of generic protocols (e.g. TCP) in a cluster of workstations often do not perform or scale as well as one would expect. One reason for this is that both the performance and scalability of parallel applications are highly dependent on the speed of communication, yet the generic protocols used to guarantee reliable message delivery add unnecessary overhead which degrades the performance of the parallel application. The main thesis we explore in this paper is that it is possible to use knowledge of application behavior to design protocols that are more efficient. In particular, we investigate automatic techniques for generating optimized application-specific network protocols for parallel applications running on unreliable networks. Our algorithms assume that the application communication can be represented by a context free grammar. Such algorithms form the basis for a communication compiler. Nayeem Islam, Amitabh Dave, Roy H. Campbell |
ICDCS | 1 |
| 1996 | Dynamic Partitioning in Different Distributed-Memory Environments
Nayeem Islam, Andreas L. Prodromidis, Mark S. Squillante |
JSSPP | 1 |
| 1995 | Techniques for Global Optimization of Message Passing Communication on Unreliable NetworksabstractIn this paper, we present techniques to improve the performance of parallel and distributed applications running on distributed systems built with unreliable local-area networks. The optimizations tailor the message passing system used by the application to the communication pattern exhibited by the application. The optimizations are global and application dependent since communication patterns vary from application to application. The techniques improve both the execution times and scalability of many parallel applications as well as distributed system services. Nayeem Islam, Roy H. Campbell |
ICDCS | 1 |
| 1992 | Design Considerations for Shared Memory Multiprocessor Message SystemsabstractThe comparative performance is studied of different message passing system designs experimentally on a shared memory Encore Multimax multiprocessor. The systems are measured both by benchmarks and by running example parallel applications. To act as a control, the shared memory machine results are compared with the performance of the benchmarks and applications on the Intel iPSC/2 running the NX/2 operating system. The design alternatives considered are buffering, buffer organization, reference and value semantics, synchronization, coordination strategy and the location of the system in user or kernel space. The results include measurements of the effects of the design alternatives, memory caching, message sizes and copying.> Nayeem Islam, Roy H. Campbell |
IEEE Trans. Parallel Distributed Syst. | 1 |