Andrew Baumann

dblp:53/6957 · DBLP profile ↗
← Back
22ranked-venue papers
10as first author
2since 2021 · last 2024
0009-0002-2927-7233ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 14 · 6 first-author · 2 since 2021Systems, architecture and hardware · 9 · 4 first-author · 1 since 2021Computer networks · 1
YearPublicationVenuePosition
2024 Sharing is leaking: blocking transient-execution attacks with core-gapped confidential VMs
abstract
Confidential VMs on platforms such as Intel TDX, AMD SEV and Arm CCA promise greater security for cloud users against even a hypervisor-level attacker, but this promise has been shattered by repeated transient-execution vulnerabilities and CPU bugs. At the root of this problem lies the need to multiplex CPU cores with all their complex microarchitectural state among distrusting entities, with an untrusted hypervisor in control of the multiplexing.
Charly Castes, Andrew Baumann
ASPLOS (4)2
2023 Core slicing: closing the gap between leaky confidential VMs and bare-metal cloud
Ziqiao Zhou, Yizhou Shan, Weidong Cui, Xinyang Ge, Marcus Peinado, Andrew Baumann
OSDI6
2020 Autarky: closing controlled channels with self-paging enclaves
abstract
As the first widely-deployed secure enclave hardware, Intel SGX shows promise as a practical basis for confidential cloud computing. However, side channels remain SGX's greatest security weakness. Inparticular, the "controlled-channel attack" on enclave page faults exploits a longstanding architectural side channel and still lacks effective mitigation.
Meni Orenbach, Andrew Baumann, Mark Silberstein
EuroSys2
2019 A fork() in the road
abstract
The received wisdom suggests that Unix's unusual combination of fork() and exec() for process creation was an inspired design. In this paper, we argue that fork was a clever hack for machines and programs of the 1970s that has long outlived its usefulness and is now a liability. We catalog the ways in which fork is a terrible abstraction for the modern programmer to use, describe how it compromises OS implementations, and propose alternatives.
Andrew Baumann, Jonathan Appavoo, Orran Krieger, Timothy Roscoe
HotOS1
2019 Scaling symbolic evaluation for automated verification of systems code with Serval
abstract
This paper presents Serval, a framework for developing automated verifiers for systems software. Serval provides an extensible infrastructure for creating verifiers by lifting interpreters under symbolic evaluation, and a systematic approach to identifying and repairing verification performance bottlenecks using symbolic profiling and optimizations.
Luke Nelson, James Bornholt, Ronghui Gu, Andrew Baumann, Emina Torlak, Xi Wang 0005
SOSP4
2017 Hardware is the new Software
abstract
Moore's Law may be slowing, but, perhaps as a result, other measures of processor complexity are only accelerating. In recent years, Intel's architects have turned to an alphabet soup of instruction set extensions such as MPX, SGX, MPK, and CET as a way to sell CPUs through new security features. Unlike prior extensions, which mostly focused on accelerating user-mode data processing, these new features exhibit complex interactions and give system designers plenty to think about.
Andrew Baumann
HotOS1
2017 Komodo: Using verification to disentangle secure-enclave hardware from software
abstract
Intel SGX promises powerful security: an arbitrary number of user-mode enclaves protected against physical attacks and privileged software adversaries. However, to achieve this, Intel extended the x86 architecture with an isolation mechanism approaching the complexity of an OS microkernel, implemented by an inscrutable mix of silicon and microcode. While hardware-based security can offer performance and features that are difficult or impossible to achieve in pure software, hardware-only solutions are difficult to update, either to patch security flaws or introduce new features.
Andrew Ferraiuolo, Andrew Baumann, Chris Hawblitzel, Bryan Parno
SOSP2
2015 Tardigrade: Leveraging Lightweight Virtual Machines to Easily and Efficiently Construct Fault-Tolerant Services
Jacob R. Lorch, Andrew Baumann, Lisa Glendenning, Dutch T. Meyer, Andy Warfield
NSDI2
2015 Shielding Applications from an Untrusted Cloud with Haven
abstract
Today’s cloud computing infrastructure requires substantial trust. Cloud users rely on both the provider’s staff and its globally distributed software/hardware platform not to expose any of their private data. We introduce the notion of shielded execution, which protects the confidentiality and integrity of a program and its data from the platform on which it runs (i.e., the cloud operator’s OS, VM, and firmware). Our prototype, Haven, is the first system to achieve shielded execution of unmodified legacy applications, including SQL Server and Apache, on a commodity OS (Windows) and commodity hardware. Haven leverages the hardware protection of Intel SGX to defend against privileged code and physical attacks such as memory probes, and also addresses the dual challenges of executing unmodified legacy binaries and protecting them from a malicious host. This work motivated recent changes in the SGX specification.
Andrew Baumann, Marcus Peinado, Galen C. Hunt
ACM Trans. Comput. Syst.1
2014 Shielding Applications from an Untrusted Cloud with Haven
Andrew Baumann, Marcus Peinado, Galen C. Hunt
OSDI1
2013 Composing OS extensions safely and efficiently with Bascule
abstract
Library OS (LibOS) architectures implement the OS personality as a user-mode library, giving each application the flexibility to choose its LibOS. This approach is appealing for many reasons, not least the ability to extend or customise the LibOS. Recent work with Drawbridge [29] showed that an existing commodity OS (Windows 7) could be refactored to produce a LibOS while retaining application compatibility.
Andrew Baumann, Pedro Fonseca 0001, Lisa Glendenning, Jacob R. Lorch, Barry Bond, Reuben Olinsky, Galen C. Hunt
EuroSys1
2012 A Declarative Language Approach to Device Configuration
abstract
C remains the language of choice for hardware programming (device drivers, bus configuration, etc.): it is fast, allows low-level access, and is trusted by OS developers. However, the algorithms required to configure and reconfigure hardware devices and interconnects are becoming more complex and diverse, with the added burden of legacy support, “quirks,” and hardware bugs to work around. Even programming PCI bridges in a modern PC is a surprisingly complex problem, and is getting worse as new functionality such as hotplug appears. Existing approaches use relatively simple algorithms, hard-coded in C and closely coupled with low-level register access code, generally leading to suboptimal configurations. We investigate the merits and drawbacks of a new approach: separating hardware configuration logic (algorithms to determine configuration parameter values) from mechanism (programming device registers). The latter we keep in C, and the former we encode in a declarative programming language with constraint-satisfaction extensions. As a test case, we have implemented full PCI configuration, resource allocation, and interrupt assignment in the Barrelfish research operating system, using a concise expression of efficient algorithms in constraint logic programming. We show that the approach is tractable, and can successfully configure a wide range of PCs with competitive runtime cost. Moreover, it requires about half the code of the C-based approach in Linux while offering considerably more functionality. Additionally it easily accommodates adaptations such as hotplug, fixed regions, and “quirks.”
Adrian Schüpbach, Andrew Baumann, Timothy Roscoe, Simon Peter 0001
ACM Trans. Comput. Syst.2
2011 A declarative language approach to device configuration
abstract
C remains the language of choice for hardware programming (device drivers, bus configuration, etc.): it is fast, allows low-level access, and is trusted by OS developers. However, the algorithms required to configure and reconfigure hardware devices and interconnects are becoming more complex and diverse, with the added burden of legacy support, quirks, and hardware bugs to work around. Even programming PCI bridges in a modern PC is a surprisingly complex problem, and is getting worse as new functionality such as hotplug appears. Existing approaches use relatively simple algorithms, hard-coded in C and closely coupled with low-level register access code, generally leading to suboptimal configurations.
Adrian Schüpbach, Andrew Baumann, Timothy Roscoe, Simon Peter 0001
ASPLOS2
2011 Mind the Gap: Reconnecting Architecture and OS Research
Jeffrey C. Mogul, Andrew Baumann, Timothy Roscoe, Livio B. Soares
HotOS2
2009 Your computer is already a distributed system. Why isn't your OS?
Andrew Baumann, Simon Peter 0001, Adrian Schüpbach, Akhilesh Singhania, Timothy Roscoe, Paul Barham 0001, Rebecca Isaacs
HotOS1
2009 Rhizoma: A Runtime for Self-deploying, Self-managing Overlays
Qin Yin, Adrian Schüpbach, Justin Cappos, Andrew Baumann, Timothy Roscoe
Middleware4
2009 The multikernel: a new OS architecture for scalable multicore systems
abstract
Commodity computer systems contain more and more processor cores and exhibit increasingly diverse architectural tradeoffs, including memory hierarchies, interconnects, instruction sets and variants, and IO configurations. Previous high-performance computing systems have scaled in specific cases, but the dynamic nature of modern client and server workloads, coupled with the impossibility of statically optimizing an OS for all workloads and hardware variants pose serious challenges for operating system structures.
Andrew Baumann, Paul Barham 0001, Pierre-Évariste Dagand, Tim Harris 0001, Rebecca Isaacs, Simon Peter 0001, Timothy Roscoe, Adrian Schüpbach, Akhilesh Singhania
SOSP1
2009 Filet-o-Fish: practical and dependable domain-specific languages for OS development
abstract
We address a persistent problem with using domain-specific languages to write operating systems: the effort of implementing, checking, and debugging the DSL usually outweighs any of its benefits. Because these DSLs generate C by templated string concatenation, they are tedious to write, fragile, and incompatible with automated verification tools.
Pierre-Évariste Dagand, Andrew Baumann, Timothy Roscoe
PLOS@SOSP2
2008 30 seconds is not enough!: a study of operating system timer usage
abstract
The basic system timer facilities used by applications and OS kernels for scheduling timeouts and periodic activities have remained largely unchanged for decades, while hardware architectures and application loads have changed radically. This raises concerns with CPU overhead power management and application responsiveness.
Simon Peter 0001, Andrew Baumann, Timothy Roscoe, Paul Barham 0001, Rebecca Isaacs
EuroSys2
2007 Reboots Are for Hardware: Challenges and Solutions to Updating an Operating System on the Fly
Andrew Baumann, Jonathan Appavoo, Robert W. Wisniewski, Dilma Da Silva, Orran Krieger, Gernot Heiser
USENIX ATC1
2005 Improving dynamic update for operating systems
abstract
Modern operating systems are subject to a constant stream of patches and updates: to fix bugs, improve performance, or add features. Dynamic update offers significantly increased availability for operating systems, and enables administrators to avoid a difficult choice between the cost of down time and the risk of remaining unpatched. However, an operating system kernel is a unique environment for dynamic update; it is generally event-driven, multi-threaded, and involves a high degree of concurrency and asynchrony. It also provides a very restricted runtime environment. Existing dynamic update mechanisms are generally unsuited for use with operating-system code, either because they do not support concurrency [11, 13], require the system to be implemented in a specific language [1, 7, 9], or rely on a higher level of runtime support than is feasible within a traditional OS [5, 6].
Andrew Baumann, Jonathan Appavoo
SOSP1
2005 Providing Dynamic Update in an Operating System
Andrew Baumann, Gernot Heiser, Jonathan Appavoo, Dilma Da Silva, Orran Krieger, Robert W. Wisniewski, Jeremy Kerr
USENIX ATC, General Track1