Tal Garfinkel

dblp:55/1439 · DBLP profile ↗
← Back
24ranked-venue papers
7as first author
4since 2021 · last 2025
0000-0003-4213-4755ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 9 · 3 since 2021Security and privacy · 9 · 3 first-authorSoftware engineering, systems software and programming languages · 9 · 4 first-author · 3 since 2021Computer networks · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2025 Extended User Interrupts (xUI): Fast and Flexible Notification without Polling
abstract
Extended user interrupts (xUI) is a set of processor extensions that builds on Intel's UIPI model of user interrupts, for enhanced performance and flexibility. This paper deconstructs Intel's current UIPI design through analysis and measurement, and uses this to develop an accurate model of its timing. It then introduces four novel enhancements to user interrupts: tracked interrupts, hardware safepoints, a kernel bypass timer, and interrupt forwarding. xUI is modeled in gem5 simulation and evaluated on three use cases -- preemption in a high-performance user-level runtime, IO notification in a layer3 router using DPDK, and IO notification in a synthetic workload with a streaming accelerator modeled after Intel's Data Streaming Accelerator. This work shows that xUI offers the performance of shared memory polling with the efficiency of asynchronous notification.
Berk Aydogmus, Linsong Guo, Danial Zuberi, Tal Garfinkel, Dean M. Tullsen, Amy Ousterhout, Mohammadkazem Taram
ASPLOS (2)4
2025 Segue & ColorGuard: Optimizing SFI Performance and Scalability on Modern Architectures
abstract
Software-based fault isolation (SFI) enables in-process isolation through compiler instrumentation of memory accesses, and is a critical part of WebAssembly (Wasm). We present two optimizations that improve SFI performance and scalability: Segue uses x86-64 segmentation to reduce the cost of instrumentation on memory accesses, e.g., it eliminates 44.7% of Wasm's overhead on a Wasm-compatible subset of SPEC CPU 2006, and reduces overhead of Wasm-sandboxed font rendering in Firefox by 75%; ColorGuard leverages memory tagging (e.g., MPK), to enable up to a 15× increase in the number of Wasm instances that can run concurrently in a single address space, improving efficiency for high scale server-side workloads. We also explore the challenges of deploying these optimizations in three production toolchains: Wasm2c, WAMR and Wasmtime.
Shravan Narayan, Tal Garfinkel, Evan Johnson 0001, Zachary Yedidia, Yingchen Wang, Anjo Vahldiek-Oberwagner, Michael LeMay, Wenyong Huang, Xin Wang 0240, Mingqiu Sun, Dean M. Tullsen, Deian Stefan
ASPLOS (1)2
2025 The Benefits and Limitations of User Interrupts for Preemptive Userspace Scheduling
Linsong Guo, Danial Zuberi, Tal Garfinkel, Amy Ousterhout
NSDI3
2023 Going beyond the Limits of SFI: Flexible and Secure Hardware-Assisted In-Process Isolation with HFI
abstract
We introduce Hardware-assisted Fault Isolation (HFI), a simple extension to existing processors to support secure, flexible, and efficient in-process isolation. HFI addresses the limitations of existing software-based isolation (SFI) systems including: runtime overheads, limited scalability, vulnerability to Spectre attacks, and limited compatibility with existing code. HFI can seamlessly integrate with current SFI systems (e.g., WebAssembly), or directly sandbox unmodified native binaries. To ease adoption, HFI relies only on incremental changes to the data and control path of existing high-performance processors. We evaluate HFI for x86-64 using the gem5 simulator and compiler-based emulation on a mix of real and synthetic workloads.
Shravan Narayan, Tal Garfinkel, Mohammadkazem Taram, Joey Rudek, Daniel Moghimi, Evan Johnson 0001, Chris Fallin, Anjo Vahldiek-Oberwagner, Michael LeMay, Ravi Sahita, Dean M. Tullsen, Deian Stefan
ASPLOS (3)2
2020 Retrofitting Fine Grain Isolation in the Firefox Renderer
Shravan Narayan, Craig Disselkoen, Tal Garfinkel, Nathan Froyd, Eric Rahm, Sorin Lerner, Hovav Shacham, Deian Stefan
USENIX Security Symposium3
2017 Towards Practical Default-On Multi-Core Record/Replay
abstract
We present Castor, a record/replay system for multi-core applications that provides consistently low and predictable overheads. With Castor, developers can leave record and replay on by default, making it practical to record and reproduce production bugs, or employ fault tolerance to recover from hardware failures.
Ali José Mashtizadeh, Tal Garfinkel, David Terei, David Mazières, Mendel Rosenblum
ASPLOS2
2014 XvMotion: Unified Virtual Machine Migration over Long Distance
Ali José Mashtizadeh, Min Cai, Gabriel Tarasuk-Levin, Ricardo Koller, Tal Garfinkel, Sreekanth Setty
USENIX ATC5
2011 The Design and Evolution of Live Storage Migration in VMware ESX
Ali José Mashtizadeh, Emré Celebi, Tal Garfinkel, Min Cai
USENIX ATC3
2010 Multi-stage replay with crosscut
abstract
Deterministic record-replay has many useful applications, ranging from fault tolerance and forensics to reproducing and diagnosing bugs. When choosing a record-replay solution, the system admin-istrator must choose a priori how comprehensively to record the execution and at what abstraction level to record it. Unfortunately, these choices may not match well with how the recording is eventu-ally used. A recording may contain too little information to support the end use of replay, or it may contain more sensitive information than is allowed to be shown to the end user of replay. Similarly, fixing the abstraction level at the time of recording often leads to a semantic mismatch with the end use of replay. This paper describes how to remedy these problems by adding customizable replay stages to create special-purpose logs for the end users of replay. Our system, called Crosscut, allows replay logs to be “sliced ” along time and abstraction boundaries. Using this approach, users can create slices that include only the processes, applications, or components of interest, excluding parts that handle sensitive data. Users can also retarget the abstraction level of the replay log to higher-level platforms, such as Perl or Valgrind. Exe-cution can then be augmented with additional analysis code at re-play time, without disturbing the replayed components in the slice. Crosscut thus uses replay itself to transform logs into a more effi-cient, secure, and usable form for replay-based applications. Our current Crosscut prototype builds on VMware Worksta-tion’s record-replay capabilities, and supports a variety of differ-ent replay environments. We show how Crosscut can create slices of only the parts of the computation of interest and thereby avoid leaking sensitive information, and we show how to retarget the ab-straction level of the log to enable more convenient use during re-play debugging.
Jim Chow, Dominic G. Lucchetti, Tal Garfinkel, Geoffrey Lefebvre, Ryan Gardner, Joshua Mason, Sam Small, Peter M. Chen
VEE3
2008 Overshadow: a virtualization-based approach to retrofitting protection in commodity operating systems
abstract
Commodity operating systems entrusted with securing sensitive data are remarkably large and complex, and consequently, frequently prone to compromise. To address this limitation, we introduce a virtual-machine-based system called Overshadow that protects the privacy and integrity of application data, even in the event of a total OScompromise. Overshadow presents an application with a normal view of its resources, but the OS with an encrypted view. This allows the operating system to carry out the complex task of managing an application's resources, without allowing it to read or modify them. Thus, Overshadow offers a last line of defense for application data.Overshadow builds on multi-shadowing, a novel mechanism that presents different views of physical memory, depending on the context performing the access. This primitive offers an additional dimension of protection beyond the hierarchical protection domains implemented by traditional operating systems and processor architectures.We present the design and implementation of Overshadow and show how its new protection semantics can be integrated with existing systems. Our design has been fully implemented and used to protect a wide range of unmodified legacy applications running on an unmodified Linux operating system. We evaluate the performance of our implementation, demonstrating that this approach is practical.
Tal Garfinkel, E. Christopher Lewis, Pratap Subrahmanyam, Carl A. Waldspurger, Dan Boneh, Jeffrey S. Dwoskin, Dan R. K. Ports
ASPLOS2
2008 VMwareDecoupling Dynamic Program Analysis from Execution in Virtual Environments
Jim Chow, Tal Garfinkel, Peter M. Chen
USENIX ATC2
2008 Towards Application Security on Untrusted Operating Systems
Dan R. K. Ports, Tal Garfinkel
HotSec2
2007 Compatibility Is Not Transparency: VMM Detection Myths and Realities
Tal Garfinkel, Keith Adams, Andy Warfield, Jason Franklin
HotOS1
2007 Reducing shoulder-surfing by using gaze-based password entry
abstract
Shoulder-surfing -- using direct observation techniques, such as looking over someone's shoulder, to get passwords, PINs and other sensitive personal information -- is a problem that has been difficult to overcome. When a user enters information using a keyboard, mouse, touch screen or any traditional input device, a malicious observer may be able to acquire the user's password credentials. We present EyePassword, a system that mitigates the issues of shoulder surfing via a novel approach to user input.
Manu Kumar, Tal Garfinkel, Dan Boneh, Terry Winograd
SOUPS2
2006 Virtualization Aware File Systems: Getting Beyond the Limitations of Virtual Disks
Ben Pfaff, Tal Garfinkel, Mendel Rosenblum
NSDI2
2006 SANE: A Protection Architecture for Enterprise Networks
Martín Casado, Tal Garfinkel, Aditya Akella, Michael J. Freedman, Dan Boneh, Nick McKeown
USENIX Security Symposium2
2005 When Virtual Is Harder than Real: Security Challenges in Virtual Machine Based Computing Environments
Tal Garfinkel, Mendel Rosenblum
HotOS1
2005 Shredding Your Garbage: Reducing Data Lifetime Through Secure Deallocation
Jim Chow, Ben Pfaff, Tal Garfinkel, Mendel Rosenblum
USENIX Security Symposium3
2004 Ostia: A Delegating Architecture for Secure System Call Interposition
Tal Garfinkel, Ben Pfaff, Mendel Rosenblum
NDSS1
2004 Understanding Data Lifetime via Whole System Simulation (Awarded Best Paper!)
Jim Chow, Ben Pfaff, Tal Garfinkel, Kevin Christopher, Mendel Rosenblum
USENIX Security Symposium3
2003 Flexible OS Support and Applications for Trusted Computing
Tal Garfinkel, Mendel Rosenblum, Dan Boneh
HotOS1
2003 Traps and Pitfalls: Practical Problems in System Call Interposition Based Security Tools
Tal Garfinkel
NDSS1
2003 A Virtual Machine Introspection Based Architecture for Intrusion Detection
Tal Garfinkel, Mendel Rosenblum
NDSS1
2003 Terra: a virtual machine-based platform for trusted computing
abstract
We present a flexible architecture for trusted computing, called Terra, that allows applications with a wide range of security requirements to run simultaneously on commodity hardware. Applications on Terra enjoy the semantics of running on a separate, dedicated, tamper-resistant hardware platform, while retaining the ability to run side-by-side with normal applications on a general-purpose computing platform. Terra achieves this synthesis by use of a trusted virtual machine monitor (TVMM) that partitions a tamper-resistant hardware platform into multiple, isolated virtual machines (VM), providing the appearance of multiple boxes on a single, general-purpose platform. To each VM, the TVMM provides the semantics of either an "open box," i.e. a general-purpose hardware platform like today's PCs and workstations, or a "closed box," an opaque special-purpose platform that protects the privacy and integrity of its contents like today's game consoles and cellular phones. The software stack in each VM can be tailored from the hardware interface up to meet the security requirements of its application(s). The hardware and TVMM can act as a trusted party to allow closed-box VMs to cryptographically identify the software they run, i.e. what is in the box, to remote parties. We explore the strengths and limitations of this architecture by describing our prototype implementation and several applications that we developed for it.
Tal Garfinkel, Ben Pfaff, Jim Chow, Mendel Rosenblum, Dan Boneh
SOSP1