VLDB 2026 Research / reviewers in the wild / expert
Andrew Baumann
dblp:53/6957
· DBLP profile ↗
22ranked-venue papers
10as first author
2since 2021 · last 2024
0009-0002-2927-7233ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 14 · 6 first-author · 2 since 2021Systems, architecture and hardware · 9 · 4 first-author · 1 since 2021Computer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Sharing is leaking: blocking transient-execution attacks with core-gapped confidential VMsabstractConfidential VMs on platforms such as Intel TDX, AMD SEV and Arm CCA promise greater security for cloud users against even a hypervisor-level attacker, but this promise has been shattered by repeated transient-execution vulnerabilities and CPU bugs. At the root of this problem lies the need to multiplex CPU cores with all their complex microarchitectural state among distrusting entities, with an untrusted hypervisor in control of the multiplexing. Charly Castes, Andrew Baumann |
ASPLOS (4) | 2 |
| 2023 | Core slicing: closing the gap between leaky confidential VMs and bare-metal cloud
Ziqiao Zhou, Yizhou Shan, Weidong Cui, Xinyang Ge, Marcus Peinado, Andrew Baumann |
OSDI | 6 |
| 2020 | Autarky: closing controlled channels with self-paging enclavesabstractAs the first widely-deployed secure enclave hardware, Intel SGX shows promise as a practical basis for confidential cloud computing. However, side channels remain SGX's greatest security weakness. Inparticular, the "controlled-channel attack" on enclave page faults exploits a longstanding architectural side channel and still lacks effective mitigation. Meni Orenbach, Andrew Baumann, Mark Silberstein |
EuroSys | 2 |
| 2019 | A fork() in the roadabstractThe received wisdom suggests that Unix's unusual combination of fork() and exec() for process creation was an inspired design. In this paper, we argue that fork was a clever hack for machines and programs of the 1970s that has long outlived its usefulness and is now a liability. We catalog the ways in which fork is a terrible abstraction for the modern programmer to use, describe how it compromises OS implementations, and propose alternatives. Andrew Baumann, Jonathan Appavoo, Orran Krieger, Timothy Roscoe |
HotOS | 1 |
| 2019 | Scaling symbolic evaluation for automated verification of systems code with ServalabstractThis paper presents Serval, a framework for developing automated verifiers for systems software. Serval provides an extensible infrastructure for creating verifiers by lifting interpreters under symbolic evaluation, and a systematic approach to identifying and repairing verification performance bottlenecks using symbolic profiling and optimizations. Luke Nelson, James Bornholt, Ronghui Gu, Andrew Baumann, Emina Torlak, Xi Wang 0005 |
SOSP | 4 |
| 2017 | Hardware is the new SoftwareabstractMoore's Law may be slowing, but, perhaps as a result, other measures of processor complexity are only accelerating. In recent years, Intel's architects have turned to an alphabet soup of instruction set extensions such as MPX, SGX, MPK, and CET as a way to sell CPUs through new security features. Unlike prior extensions, which mostly focused on accelerating user-mode data processing, these new features exhibit complex interactions and give system designers plenty to think about. Andrew Baumann |
HotOS | 1 |
| 2017 | Komodo: Using verification to disentangle secure-enclave hardware from softwareabstractIntel SGX promises powerful security: an arbitrary number of user-mode enclaves protected against physical attacks and privileged software adversaries. However, to achieve this, Intel extended the x86 architecture with an isolation mechanism approaching the complexity of an OS microkernel, implemented by an inscrutable mix of silicon and microcode. While hardware-based security can offer performance and features that are difficult or impossible to achieve in pure software, hardware-only solutions are difficult to update, either to patch security flaws or introduce new features. Andrew Ferraiuolo, Andrew Baumann, Chris Hawblitzel, Bryan Parno |
SOSP | 2 |
| 2015 | Tardigrade: Leveraging Lightweight Virtual Machines to Easily and Efficiently Construct Fault-Tolerant Services
Jacob R. Lorch, Andrew Baumann, Lisa Glendenning, Dutch T. Meyer, Andy Warfield |
NSDI | 2 |
| 2015 | Shielding Applications from an Untrusted Cloud with HavenabstractToday’s cloud computing infrastructure requires substantial trust. Cloud users rely on both the provider’s staff and its globally distributed software/hardware platform not to expose any of their private data. We introduce the notion of shielded execution, which protects the confidentiality and integrity of a program and its data from the platform on which it runs (i.e., the cloud operator’s OS, VM, and firmware). Our prototype, Haven, is the first system to achieve shielded execution of unmodified legacy applications, including SQL Server and Apache, on a commodity OS (Windows) and commodity hardware. Haven leverages the hardware protection of Intel SGX to defend against privileged code and physical attacks such as memory probes, and also addresses the dual challenges of executing unmodified legacy binaries and protecting them from a malicious host. This work motivated recent changes in the SGX specification. Andrew Baumann, Marcus Peinado, Galen C. Hunt |
ACM Trans. Comput. Syst. | 1 |
| 2014 | Shielding Applications from an Untrusted Cloud with Haven
Andrew Baumann, Marcus Peinado, Galen C. Hunt |
OSDI | 1 |
| 2013 | Composing OS extensions safely and efficiently with BasculeabstractLibrary OS (LibOS) architectures implement the OS personality as a user-mode library, giving each application the flexibility to choose its LibOS. This approach is appealing for many reasons, not least the ability to extend or customise the LibOS. Recent work with Drawbridge [29] showed that an existing commodity OS (Windows 7) could be refactored to produce a LibOS while retaining application compatibility. Andrew Baumann, Pedro Fonseca 0001, Lisa Glendenning, Jacob R. Lorch, Barry Bond, Reuben Olinsky, Galen C. Hunt |
EuroSys | 1 |
| 2012 | A Declarative Language Approach to Device ConfigurationabstractC remains the language of choice for hardware programming (device drivers, bus configuration, etc.): it is fast, allows low-level access, and is trusted by OS developers. However, the algorithms required to configure and reconfigure hardware devices and interconnects are becoming more complex and diverse, with the added burden of legacy support, “quirks,” and hardware bugs to work around. Even programming PCI bridges in a modern PC is a surprisingly complex problem, and is getting worse as new functionality such as hotplug appears. Existing approaches use relatively simple algorithms, hard-coded in C and closely coupled with low-level register access code, generally leading to suboptimal configurations. We investigate the merits and drawbacks of a new approach: separating hardware configuration logic (algorithms to determine configuration parameter values) from mechanism (programming device registers). The latter we keep in C, and the former we encode in a declarative programming language with constraint-satisfaction extensions. As a test case, we have implemented full PCI configuration, resource allocation, and interrupt assignment in the Barrelfish research operating system, using a concise expression of efficient algorithms in constraint logic programming. We show that the approach is tractable, and can successfully configure a wide range of PCs with competitive runtime cost. Moreover, it requires about half the code of the C-based approach in Linux while offering considerably more functionality. Additionally it easily accommodates adaptations such as hotplug, fixed regions, and “quirks.” Adrian Schüpbach, Andrew Baumann, Timothy Roscoe, Simon Peter 0001 |
ACM Trans. Comput. Syst. | 2 |
| 2011 | A declarative language approach to device configurationabstractC remains the language of choice for hardware programming (device drivers, bus configuration, etc.): it is fast, allows low-level access, and is trusted by OS developers. However, the algorithms required to configure and reconfigure hardware devices and interconnects are becoming more complex and diverse, with the added burden of legacy support, quirks, and hardware bugs to work around. Even programming PCI bridges in a modern PC is a surprisingly complex problem, and is getting worse as new functionality such as hotplug appears. Existing approaches use relatively simple algorithms, hard-coded in C and closely coupled with low-level register access code, generally leading to suboptimal configurations. Adrian Schüpbach, Andrew Baumann, Timothy Roscoe, Simon Peter 0001 |
ASPLOS | 2 |
| 2011 | Mind the Gap: Reconnecting Architecture and OS Research
Jeffrey C. Mogul, Andrew Baumann, Timothy Roscoe, Livio B. Soares |
HotOS | 2 |
| 2009 | Your computer is already a distributed system. Why isn't your OS?
Andrew Baumann, Simon Peter 0001, Adrian Schüpbach, Akhilesh Singhania, Timothy Roscoe, Paul Barham 0001, Rebecca Isaacs |
HotOS | 1 |
| 2009 | Rhizoma: A Runtime for Self-deploying, Self-managing Overlays
Qin Yin, Adrian Schüpbach, Justin Cappos, Andrew Baumann, Timothy Roscoe |
Middleware | 4 |
| 2009 | The multikernel: a new OS architecture for scalable multicore systemsabstractCommodity computer systems contain more and more processor cores and exhibit increasingly diverse architectural tradeoffs, including memory hierarchies, interconnects, instruction sets and variants, and IO configurations. Previous high-performance computing systems have scaled in specific cases, but the dynamic nature of modern client and server workloads, coupled with the impossibility of statically optimizing an OS for all workloads and hardware variants pose serious challenges for operating system structures. Andrew Baumann, Paul Barham 0001, Pierre-Évariste Dagand, Tim Harris 0001, Rebecca Isaacs, Simon Peter 0001, Timothy Roscoe, Adrian Schüpbach, Akhilesh Singhania |
SOSP | 1 |
| 2009 | Filet-o-Fish: practical and dependable domain-specific languages for OS developmentabstractWe address a persistent problem with using domain-specific languages to write operating systems: the effort of implementing, checking, and debugging the DSL usually outweighs any of its benefits. Because these DSLs generate C by templated string concatenation, they are tedious to write, fragile, and incompatible with automated verification tools. Pierre-Évariste Dagand, Andrew Baumann, Timothy Roscoe |
PLOS@SOSP | 2 |
| 2008 | 30 seconds is not enough!: a study of operating system timer usageabstractThe basic system timer facilities used by applications and OS kernels for scheduling timeouts and periodic activities have remained largely unchanged for decades, while hardware architectures and application loads have changed radically. This raises concerns with CPU overhead power management and application responsiveness. Simon Peter 0001, Andrew Baumann, Timothy Roscoe, Paul Barham 0001, Rebecca Isaacs |
EuroSys | 2 |
| 2007 | Reboots Are for Hardware: Challenges and Solutions to Updating an Operating System on the Fly
Andrew Baumann, Jonathan Appavoo, Robert W. Wisniewski, Dilma Da Silva, Orran Krieger, Gernot Heiser |
USENIX ATC | 1 |
| 2005 | Improving dynamic update for operating systemsabstractModern operating systems are subject to a constant stream of patches and updates: to fix bugs, improve performance, or add features. Dynamic update offers significantly increased availability for operating systems, and enables administrators to avoid a difficult choice between the cost of down time and the risk of remaining unpatched. However, an operating system kernel is a unique environment for dynamic update; it is generally event-driven, multi-threaded, and involves a high degree of concurrency and asynchrony. It also provides a very restricted runtime environment. Existing dynamic update mechanisms are generally unsuited for use with operating-system code, either because they do not support concurrency [11, 13], require the system to be implemented in a specific language [1, 7, 9], or rely on a higher level of runtime support than is feasible within a traditional OS [5, 6]. Andrew Baumann, Jonathan Appavoo |
SOSP | 1 |
| 2005 | Providing Dynamic Update in an Operating System
Andrew Baumann, Gernot Heiser, Jonathan Appavoo, Dilma Da Silva, Orran Krieger, Robert W. Wisniewski, Jeremy Kerr |
USENIX ATC, General Track | 1 |