VLDB 2026 Research / reviewers in the wild / expert
Tal Garfinkel
dblp:55/1439
· DBLP profile ↗
24ranked-venue papers
7as first author
4since 2021 · last 2025
0000-0003-4213-4755ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 9 · 3 since 2021Security and privacy · 9 · 3 first-authorSoftware engineering, systems software and programming languages · 9 · 4 first-author · 3 since 2021Computer networks · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Extended User Interrupts (xUI): Fast and Flexible Notification without PollingabstractExtended user interrupts (xUI) is a set of processor extensions that builds on Intel's UIPI model of user interrupts, for enhanced performance and flexibility. This paper deconstructs Intel's current UIPI design through analysis and measurement, and uses this to develop an accurate model of its timing. It then introduces four novel enhancements to user interrupts: tracked interrupts, hardware safepoints, a kernel bypass timer, and interrupt forwarding. xUI is modeled in gem5 simulation and evaluated on three use cases -- preemption in a high-performance user-level runtime, IO notification in a layer3 router using DPDK, and IO notification in a synthetic workload with a streaming accelerator modeled after Intel's Data Streaming Accelerator. This work shows that xUI offers the performance of shared memory polling with the efficiency of asynchronous notification. Berk Aydogmus, Linsong Guo, Danial Zuberi, Tal Garfinkel, Dean M. Tullsen, Amy Ousterhout, Mohammadkazem Taram |
ASPLOS (2) | 4 |
| 2025 | Segue & ColorGuard: Optimizing SFI Performance and Scalability on Modern ArchitecturesabstractSoftware-based fault isolation (SFI) enables in-process isolation through compiler instrumentation of memory accesses, and is a critical part of WebAssembly (Wasm). We present two optimizations that improve SFI performance and scalability: Segue uses x86-64 segmentation to reduce the cost of instrumentation on memory accesses, e.g., it eliminates 44.7% of Wasm's overhead on a Wasm-compatible subset of SPEC CPU 2006, and reduces overhead of Wasm-sandboxed font rendering in Firefox by 75%; ColorGuard leverages memory tagging (e.g., MPK), to enable up to a 15× increase in the number of Wasm instances that can run concurrently in a single address space, improving efficiency for high scale server-side workloads. We also explore the challenges of deploying these optimizations in three production toolchains: Wasm2c, WAMR and Wasmtime. Shravan Narayan, Tal Garfinkel, Evan Johnson 0001, Zachary Yedidia, Yingchen Wang, Anjo Vahldiek-Oberwagner, Michael LeMay, Wenyong Huang, Xin Wang 0240, Mingqiu Sun, Dean M. Tullsen, Deian Stefan |
ASPLOS (1) | 2 |
| 2025 | The Benefits and Limitations of User Interrupts for Preemptive Userspace Scheduling
Linsong Guo, Danial Zuberi, Tal Garfinkel, Amy Ousterhout |
NSDI | 3 |
| 2023 | Going beyond the Limits of SFI: Flexible and Secure Hardware-Assisted In-Process Isolation with HFIabstractWe introduce Hardware-assisted Fault Isolation (HFI), a simple extension to existing processors to support secure, flexible, and efficient in-process isolation. HFI addresses the limitations of existing software-based isolation (SFI) systems including: runtime overheads, limited scalability, vulnerability to Spectre attacks, and limited compatibility with existing code. HFI can seamlessly integrate with current SFI systems (e.g., WebAssembly), or directly sandbox unmodified native binaries. To ease adoption, HFI relies only on incremental changes to the data and control path of existing high-performance processors. We evaluate HFI for x86-64 using the gem5 simulator and compiler-based emulation on a mix of real and synthetic workloads. Shravan Narayan, Tal Garfinkel, Mohammadkazem Taram, Joey Rudek, Daniel Moghimi, Evan Johnson 0001, Chris Fallin, Anjo Vahldiek-Oberwagner, Michael LeMay, Ravi Sahita, Dean M. Tullsen, Deian Stefan |
ASPLOS (3) | 2 |
| 2020 | Retrofitting Fine Grain Isolation in the Firefox Renderer
Shravan Narayan, Craig Disselkoen, Tal Garfinkel, Nathan Froyd, Eric Rahm, Sorin Lerner, Hovav Shacham, Deian Stefan |
USENIX Security Symposium | 3 |
| 2017 | Towards Practical Default-On Multi-Core Record/ReplayabstractWe present Castor, a record/replay system for multi-core applications that provides consistently low and predictable overheads. With Castor, developers can leave record and replay on by default, making it practical to record and reproduce production bugs, or employ fault tolerance to recover from hardware failures. Ali José Mashtizadeh, Tal Garfinkel, David Terei, David Mazières, Mendel Rosenblum |
ASPLOS | 2 |
| 2014 | XvMotion: Unified Virtual Machine Migration over Long Distance
Ali José Mashtizadeh, Min Cai, Gabriel Tarasuk-Levin, Ricardo Koller, Tal Garfinkel, Sreekanth Setty |
USENIX ATC | 5 |
| 2011 | The Design and Evolution of Live Storage Migration in VMware ESX
Ali José Mashtizadeh, Emré Celebi, Tal Garfinkel, Min Cai |
USENIX ATC | 3 |
| 2010 | Multi-stage replay with crosscutabstractDeterministic record-replay has many useful applications, ranging from fault tolerance and forensics to reproducing and diagnosing bugs. When choosing a record-replay solution, the system admin-istrator must choose a priori how comprehensively to record the execution and at what abstraction level to record it. Unfortunately, these choices may not match well with how the recording is eventu-ally used. A recording may contain too little information to support the end use of replay, or it may contain more sensitive information than is allowed to be shown to the end user of replay. Similarly, fixing the abstraction level at the time of recording often leads to a semantic mismatch with the end use of replay. This paper describes how to remedy these problems by adding customizable replay stages to create special-purpose logs for the end users of replay. Our system, called Crosscut, allows replay logs to be “sliced ” along time and abstraction boundaries. Using this approach, users can create slices that include only the processes, applications, or components of interest, excluding parts that handle sensitive data. Users can also retarget the abstraction level of the replay log to higher-level platforms, such as Perl or Valgrind. Exe-cution can then be augmented with additional analysis code at re-play time, without disturbing the replayed components in the slice. Crosscut thus uses replay itself to transform logs into a more effi-cient, secure, and usable form for replay-based applications. Our current Crosscut prototype builds on VMware Worksta-tion’s record-replay capabilities, and supports a variety of differ-ent replay environments. We show how Crosscut can create slices of only the parts of the computation of interest and thereby avoid leaking sensitive information, and we show how to retarget the ab-straction level of the log to enable more convenient use during re-play debugging. Jim Chow, Dominic G. Lucchetti, Tal Garfinkel, Geoffrey Lefebvre, Ryan Gardner, Joshua Mason, Sam Small, Peter M. Chen |
VEE | 3 |
| 2008 | Overshadow: a virtualization-based approach to retrofitting protection in commodity operating systemsabstractCommodity operating systems entrusted with securing sensitive data are remarkably large and complex, and consequently, frequently prone to compromise. To address this limitation, we introduce a virtual-machine-based system called Overshadow that protects the privacy and integrity of application data, even in the event of a total OScompromise. Overshadow presents an application with a normal view of its resources, but the OS with an encrypted view. This allows the operating system to carry out the complex task of managing an application's resources, without allowing it to read or modify them. Thus, Overshadow offers a last line of defense for application data.Overshadow builds on multi-shadowing, a novel mechanism that presents different views of physical memory, depending on the context performing the access. This primitive offers an additional dimension of protection beyond the hierarchical protection domains implemented by traditional operating systems and processor architectures.We present the design and implementation of Overshadow and show how its new protection semantics can be integrated with existing systems. Our design has been fully implemented and used to protect a wide range of unmodified legacy applications running on an unmodified Linux operating system. We evaluate the performance of our implementation, demonstrating that this approach is practical. Tal Garfinkel, E. Christopher Lewis, Pratap Subrahmanyam, Carl A. Waldspurger, Dan Boneh, Jeffrey S. Dwoskin, Dan R. K. Ports |
ASPLOS | 2 |
| 2008 | VMwareDecoupling Dynamic Program Analysis from Execution in Virtual Environments
Jim Chow, Tal Garfinkel, Peter M. Chen |
USENIX ATC | 2 |
| 2008 | Towards Application Security on Untrusted Operating Systems
Dan R. K. Ports, Tal Garfinkel |
HotSec | 2 |
| 2007 | Compatibility Is Not Transparency: VMM Detection Myths and Realities
Tal Garfinkel, Keith Adams, Andy Warfield, Jason Franklin |
HotOS | 1 |
| 2007 | Reducing shoulder-surfing by using gaze-based password entryabstractShoulder-surfing -- using direct observation techniques, such as looking over someone's shoulder, to get passwords, PINs and other sensitive personal information -- is a problem that has been difficult to overcome. When a user enters information using a keyboard, mouse, touch screen or any traditional input device, a malicious observer may be able to acquire the user's password credentials. We present EyePassword, a system that mitigates the issues of shoulder surfing via a novel approach to user input. Manu Kumar, Tal Garfinkel, Dan Boneh, Terry Winograd |
SOUPS | 2 |
| 2006 | Virtualization Aware File Systems: Getting Beyond the Limitations of Virtual Disks
Ben Pfaff, Tal Garfinkel, Mendel Rosenblum |
NSDI | 2 |
| 2006 | SANE: A Protection Architecture for Enterprise Networks
Martín Casado, Tal Garfinkel, Aditya Akella, Michael J. Freedman, Dan Boneh, Nick McKeown |
USENIX Security Symposium | 2 |
| 2005 | When Virtual Is Harder than Real: Security Challenges in Virtual Machine Based Computing Environments
Tal Garfinkel, Mendel Rosenblum |
HotOS | 1 |
| 2005 | Shredding Your Garbage: Reducing Data Lifetime Through Secure Deallocation
Jim Chow, Ben Pfaff, Tal Garfinkel, Mendel Rosenblum |
USENIX Security Symposium | 3 |
| 2004 | Ostia: A Delegating Architecture for Secure System Call Interposition
Tal Garfinkel, Ben Pfaff, Mendel Rosenblum |
NDSS | 1 |
| 2004 | Understanding Data Lifetime via Whole System Simulation (Awarded Best Paper!)
Jim Chow, Ben Pfaff, Tal Garfinkel, Kevin Christopher, Mendel Rosenblum |
USENIX Security Symposium | 3 |
| 2003 | Flexible OS Support and Applications for Trusted Computing
Tal Garfinkel, Mendel Rosenblum, Dan Boneh |
HotOS | 1 |
| 2003 | Traps and Pitfalls: Practical Problems in System Call Interposition Based Security Tools
Tal Garfinkel |
NDSS | 1 |
| 2003 | A Virtual Machine Introspection Based Architecture for Intrusion Detection
Tal Garfinkel, Mendel Rosenblum |
NDSS | 1 |
| 2003 | Terra: a virtual machine-based platform for trusted computingabstractWe present a flexible architecture for trusted computing, called Terra, that allows applications with a wide range of security requirements to run simultaneously on commodity hardware. Applications on Terra enjoy the semantics of running on a separate, dedicated, tamper-resistant hardware platform, while retaining the ability to run side-by-side with normal applications on a general-purpose computing platform. Terra achieves this synthesis by use of a trusted virtual machine monitor (TVMM) that partitions a tamper-resistant hardware platform into multiple, isolated virtual machines (VM), providing the appearance of multiple boxes on a single, general-purpose platform. To each VM, the TVMM provides the semantics of either an "open box," i.e. a general-purpose hardware platform like today's PCs and workstations, or a "closed box," an opaque special-purpose platform that protects the privacy and integrity of its contents like today's game consoles and cellular phones. The software stack in each VM can be tailored from the hardware interface up to meet the security requirements of its application(s). The hardware and TVMM can act as a trusted party to allow closed-box VMs to cryptographically identify the software they run, i.e. what is in the box, to remote parties. We explore the strengths and limitations of this architecture by describing our prototype implementation and several applications that we developed for it. Tal Garfinkel, Ben Pfaff, Jim Chow, Mendel Rosenblum, Dan Boneh |
SOSP | 1 |