David M. Eyers

dblp:55/684 · also David Michael Eyers · DBLP profile ↗
← Back
52ranked-venue papers
3as first author
10since 2021 · last 2026
0000-0002-7284-8006ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 17 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 9 · 3 since 2021Security and privacy · 5Computer networks · 4 · 1 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 VulnBench: A Comprehensive Benchmark for Transformer-Based Vulnerability Detection
abstract
Reproducible benchmarking of tools that automatically detect vulnerabilities in source code remains challenging due to inconsistent implementations, varying data preprocessing, and methodological flaws that compromise fair model comparison. In a recent study, 9 in 10 vulnerability detection studies were found to use inappropriate evaluation approaches, with models achieving high scores through spurious correlations rather than actual vulnerability detection. We present VulnBench, an extensible, open-source benchmarking tool that enables fair comparison across models and datasets. Our systematic evaluation of CodeBERT, GraphCodeBERT, CodeT5 (encoder-only and full), and NatGen across eight mostly C/C++ source code datasets reveals that proper threshold optimization can improve F1-scores by up to 54%, as well as wide variation in F1-scores showing the large gap in the difficulty of the vulnerability dataset field. By standardising evaluation protocols, VulnBench enables researchers to distinguish between genuine model improvements and methodological artifacts as well as reducing wasteful duplication of effort spent on reproducing results.
Jake Norton, David M. Eyers, Veronica Liesaputra
AAAI2
2024 SUSS: Improving TCP Performance by Speeding Up Slow-Start
abstract
The traditional slow-start mechanism in TCP can result in slow ramping-up of the data delivery rate, inefficient bandwidth utilization, and prolonged completion time for small-size flows, especially in networks with a large bandwidth-delay product (BDP). Existing solutions either only work in specific situations, or require network assistance, making them challenging (if even possible) to deploy. This paper presents SUSS (Speeding Up Slow Start): a lightweight, sender-side add-on to the traditional slow-start mechanism, that aims to safely expedite the growth of the congestion window when a flow is significantly below its optimal fair share of the available bandwidth. SUSS achieves this by accelerating the growth in cwnd when exponential growth is predicted to continue in the next round. SUSS employs a novel combination of ACK clocking and packet pacing to effectively mitigate traffic burstiness caused by accelerated increases in cwnd. We have implemented SUSS in the Linux kernel, integrated into the CUBIC congestion control algorithm. Our real-world experiments span many device types and Internet locations, demonstrating that SUSS consistently outperforms traditional slow-start with no measured negative impacts. SUSS achieves over 20% improvement in flow completion time in all experiments with flow sizes less than 5MB and RTT larger than 50 ms.
Mahdi Arghavani, Haibo Zhang 0001, David M. Eyers, Abbas Arghavani
SIGCOMM3
2024 Preface for the special issue on tool papers of the 17th International Federated Conference on Distributed Computing Techniques, DisCoTec 2022
Ferruccio Damiani, David M. Eyers, Anna Philippou
Sci. Comput. Program.2
2023 ORC: Increasing Cloud Memory Density via Object Reuse with Capabilities
Vasily A. Sartakov, Lluís Vilanova, Munir Geden, David M. Eyers, Takahiro Shinagawa, Peter R. Pietzuch
OSDI4
2022 Reproducibility and Automation of the Appraisal Taxonomy
abstract
There is a lack of reproducibility in results from experiments that apply the Appraisal taxonomy. Appraisal is widely used by linguists to study how people judge things or people. Automating Appraisal could be beneficial for use cases such as moderating online comments. Past work in Appraisal annotation has been descriptive in nature and, the lack of publicly available data sets hinders the progress of automation. In this work, we are interested in two things; first, measuring the performance of automated approaches to Appraisal classification in the publicly available Australasian Language Technology Association (ALTA) Shared Task Challenge data set. Second, we are interested in reproducing the annotation of the ALTA data set. Four additional annotators, each with a different linguistics background, were employed to re-annotate the data set. Our results show a poor level of agreement at more detailed Appraisal categories (Fleiss Kappa = 0.059) and a fair level of agreement (Kappa = 0.372) at coarse-level categories. We find similar results when using automated approaches that are available publicly. Our empirical evidence suggests that at present, automating classification is practical only when considering coarse-level categories of the taxonomy.
Pradeesh Parameswaran, Andrew Trotman, Veronica Liesaputra, David M. Eyers
COLING4
2022 PACED: Provenance-based Automated Container Escape Detection
abstract
The security of container-based microservices relies heavily on the isolation of operating system resources that is provided by namespaces. However, vulnerabilities exist in the isolation of containers that may be exploited by attackers to gain access to the host. These are commonly referred to as container escape attacks. While prior work has identified vulnerabilities in namespace isolation, no general container escape detection and warning system has been presented. We present Paced, a novel, realtime system to detect container-escape attacks. We define what constitutes a cross-namespace event and how such events can be used to detect a container escape attack. We develop a provenance-based approach to isolate cross-namespace events and propose a rule—privileged_flow—to detect attacks on Docker and Kubernetes environments. We evaluate our detection method on a suite of contemporary CVEs with container escape exploits, bad container configurations, and benchmarks. Paced achieves near-perfect accuracy with no false negatives. We release our implementation and datasets as free, open-source software.
Mashal Abbas, Shahpar Khan, Abdul Monum, Fareed Zaffar, Rashid Tahir, David M. Eyers, Hassaan Irshad, Ashish Gehani, Vinod Yegneswaran, Thomas Pasquier
IC2E6
2022 CAP-VMs: Capability-Based Isolation and Sharing in the Cloud
Vasily A. Sartakov, Lluís Vilanova, David M. Eyers, Takahiro Shinagawa, Peter R. Pietzuch
OSDI3
2021 Spons & Shields: practical isolation for trusted execution
abstract
Trusted execution environments (TEEs) promise a cost-effective, “lift-and-shift” solution for deploying security-sensitive applications in untrusted clouds. For this, they must support rich, multi-component applications, but a large trusted computing base (TCB) inside the TEE risks that attackers can compromise application security. Fine-grained compartmentalisation can increase security through defense-in-depth, but current solutions either run all software components unprotected in the same TEE, lack efficient shared memory support, or isolate application processes using separate TEEs, impacting performance and compatibility.
Vasily A. Sartakov, Dan O'Keeffe, David M. Eyers, Lluís Vilanova, Peter R. Pietzuch
VEE3
2021 I-Scheduler: Iterative scheduling for distributed stream processing systems
Leila Eskandari, Jason Mair, Zhiyi Huang 0001, David M. Eyers
Future Gener. Comput. Syst.4
2021 Detecting the target of sarcasm is hard: Really??
Pradeesh Parameswaran, Andrew Trotman, Veronica Liesaputra, David M. Eyers
Inf. Process. Manag.4
2020 Facilitating plausible deniability for cloud providers regarding tenants' activities using trusted execution
abstract
A cloud provider that can technically determine tenants' operations may be compelled to disclose such activities by law enforcement agencies (LEAs). The situation gets even more complex when multiple LEAs across different jurisdictions are involved, e.g., because of the distributed locations of cloud servers and data storage. Yet cloud providers typically do not need or want to know about their tenants' activities, other than measuring how such activities incur expenses for using cloud resources. Thus mechanisms should be developed for cloud providers to have sufficient plausible deniability with regards to the processing being carried out by tenants on their platform, in jurisdictions that permit cloud providers to avoid liabilities in this way. Symmetrically, such mechanisms could protect tenants from legal over-reach, for example, when the country in which the cloud provider is incorporated could force disclosure of the processing carried out by cloud tenants. But to what extent can cloud providers acquire plausible deniability? Current discussions regarding risk have focused on data confidentiality and integrity. We argue that processing operations can equally reveal sensitive information-such as trade secrets and business processes-and that for some classes of application both data protection and algorithm protection are necessary. In this paper, we examine the legal and technical motivations for achieving plausible deniability in cloud interactions. We demonstrate the likely performance overhead of using containers secured with technologies such as Intel SGX. Further, we examine the current limitations of our proposed plausible deniability mechanisms, and outline a potential approach for enabling lawful access to enclaves subject to appropriate judicial oversight.
Dan O'Keeffe, Asma Vranaki, Thomas Pasquier, David M. Eyers
IC2E4
2020 StopEG: Detecting when to stop exponential growth in TCP slow-start
abstract
TCP slow-start grows the congestion window exponentially, aims to quickly probe the throughput of the network path. Stopping this growth at the wrong time can affect the overall network performance. In this paper, we introduce StopEG, an efficient mechanism to accurately and quickly detect when to stop this exponential growth. StopEG reacts to the changes on congestion window size rather than traditional congestion signals such as packet loss. We show that theoretically the number of inflight packets in the forward path is no more than 56.8% of all the inflight packets when the bottleneck link is unsaturated, and use this value as the threshold to stop the exponential growth. StopEG is evaluated through simulations in ns-3 by incorporating it into Google's BBR congestion control algorithm. Simulation results demonstrate its effectiveness in BBR, with a reduction of ≈68% in the length of the bottleneck queue when new connections are initiated.
Mahdi Arghavani, Haibo Zhang 0001, David M. Eyers, Abbas Arghavani
LCN3
2019 TrustZone for Supervised Asymmetric Multiprocessing Systems
abstract
Many modern forms of asymmetric multiprocessing (AMP) architecture use hypervisors to increase software security by isolating the system software in virtual machines. However, efficient virtualisation depends on hardware support that is not available across all products. Within modern ARM architectures, the aforementioned software isolation can also be implemented using ARM TrustZone technology. This paper presents a TrustZone-based AMP architecture (TZ-AMP) that can consolidate multiple system software environments securely on devices that lack hardware virtualisation support. We evaluate our prototype on the ARMv7-A architecture, and demonstrate TrustZone-based context-switching performance in the order of microseconds, confirming that TZ-AMP maintains high performance while also achieving hardware-backed software security.
Mahdi Amiri-Kordestani, David M. Eyers, Zhiyi Huang 0001, Morteza Biglari-Abhari
PDCAT2
2019 Introduction to the Special Issue on Integrating Process-oriented and Event-based Systems
David M. Eyers, Avigdor Gal, Hans-Arno Jacobsen, Matthias Weidlich 0001
Inf. Syst.1
2019 Manila: Using a densely populated PMC-space for power modelling within large-scale systems
Jason Mair, Zhiyi Huang 0001, David M. Eyers
Parallel Comput.3
2018 Runtime Analysis of Whole-System Provenance
abstract
Identifying the root cause and impact of a system intrusion remains a foundational challenge in computer security. Digital provenance provides a detailed history of the flow of information within a computing system, connecting suspicious events to their root causes. Although existing provenance-based auditing techniques provide value in forensic analysis, they assume that such analysis takes place only retrospectively. Such post-hoc analysis is insufficient for realtime security applications; moreover, even for forensic tasks, prior provenance collection systems exhibited poor performance and scalability, jeopardizing the timeliness of query responses. We present CamQuery, which provides inline, realtime provenance analysis, making it suitable for implementing security applications. CamQuery is a Linux Security Module that offers support for both userspace and in-kernel execution of analysis applications. We demonstrate the applicability of CamQuery to a variety of runtime security applications including data loss prevention, intrusion detection, and regulatory compliance. In evaluation, we demonstrate that CamQuery reduces the latency of realtime query mechanisms, while imposing minimal overheads on system execution. CamQuery thus enables the further deployment of provenance-based technologies to address central challenges in computer security.
Thomas Pasquier, Xueyuan Han, Thomas Moyer, Adam Bates 0001, Olivier Hermant, David M. Eyers, Jean Bacon, Margo I. Seltzer
CCS6
2018 LibSEAL: revealing service integrity violations using trusted execution
abstract
Users of online services such as messaging, code hosting and collaborative document editing expect the services to uphold the integrity of their data. Despite providers' best efforts, data corruption still occurs, but at present service integrity violations are excluded from SLAs. For providers to include such violations as part of SLAs, the competing requirements of clients and providers must be satisfied. Clients need the ability to independently identify and prove service integrity violations to claim compensation. At the same time, providers must be able to refute spurious claims.
Pierre-Louis Aublin, Florian Kelbert, Dan O'Keeffe, Divya Muthukumaran, Christian Priebe, Joshua Lind, Robert Krahn, Christof Fetzer, David M. Eyers, Peter R. Pietzuch
EuroSys9
2018 T3-Scheduler: A topology and Traffic aware two-level Scheduler for stream processing systems in a heterogeneous cluster
Leila Eskandari, Jason Mair, Zhiyi Huang 0001, David M. Eyers
Future Gener. Comput. Syst.4
2018 Distributed sparse bundle adjustment algorithm based on three-dimensional point partition and asynchronous communication
abstract
Sparse bundle adjustment (SBA) is a key but time- and memory-consuming step in three-dimensional (3D) reconstruction. In this paper, we propose a 3D point-based distributed SBA algorithm (DSBA) to improve the speed and scalability of SBA. The algorithm uses an asynchronously distributed sparse bundle adjustment (A-DSBA) to overlap data communication with equation computation. Compared with the synchronous DSBA mechanism (SDSBA), A-DSBA reduces the running time by 46%. The experimental results on several 3D reconstruction datasets reveal that our distributed algorithm running on eight nodes is up to five times faster than that of the stand-alone parallel SBA. Furthermore, the speedup of the proposed algorithm (running on eight nodes with 48 cores) is up to 41 times that of the serial SBA (running on a single node).
Xiaolong Shen, Yong Dou, Steven Mills, David M. Eyers, Huan Feng, Zhiyi Huang 0001
Frontiers Inf. Technol. Electron. Eng.4
2018 Data provenance to audit compliance with privacy policy in the Internet of Things
Thomas Pasquier, Jatinder Singh, Julia E. Powles, David M. Eyers, Margo I. Seltzer, Jean Bacon
Pers. Ubiquitous Comput.4
2018 Principal Component Analysis Based Filtering for Scalable, High Precision k-NN Search
abstract
Approximate$k$Nearest Neighbours (A$k$NN) search is widely used in domains such as computer vision and machine learning. However, A$k$NN search in high-dimensional datasets does not scale well on multicore platforms, due to its large memory footprint. Parallel A$k$NN search using space subdivision for filtering helps reduce the memory footprint, but its loss of precision is unstable. In this paper, we propose a new data filtering method—PCAF—for parallel A$k$NN search based on principal component analysis. PCAF improves on previous methods, demonstrating sustained, high scalability for a wide range of high-dimensional datasets on both Intel and AMD multicore platforms. Moreover, PCAF maintains highly precise A$k$NN search results.
Huan Feng, David M. Eyers, Steven Mills, Yongwei Wu 0001, Zhiyi Huang 0001
IEEE Trans. Computers2
2017 Practical whole-system provenance capture
abstract
Data provenance describes how data came to be in its present form. It includes data sources and the transformations that have been applied to them. Data provenance has many uses, from forensics and security to aiding the reproducibility of scientific experiments. We present CamFlow, a whole-system provenance capture mechanism that integrates easily into a PaaS offering. While there have been several prior whole-system provenance systems that captured a comprehensive, systemic and ubiquitous record of a system's behavior, none have been widely adopted. They either A) impose too much overhead, B) are designed for long-outdated kernel releases and are hard to port to current systems, C) generate too much data, or D) are designed for a single system. CamFlow addresses these shortcoming by: 1) leveraging the latest kernel design advances to achieve efficiency; 2) using a self-contained, easily maintainable implementation relying on a Linux Security Module, NetFilter, and other existing kernel facilities; 3) providing a mechanism to tailor the captured provenance data to the needs of the application; and 4) making it easy to integrate provenance across distributed systems. The provenance we capture is streamed and consumed by tenant-built auditor applications. We illustrate the usability of our implementation by describing three such applications: demonstrating compliance with data regulations; performing fault/intrusion detection; and implementing data loss prevention. We also show how CamFlow can be leveraged to capture meaningful provenance without modifying existing applications.
Thomas Pasquier, Xueyuan Han, Mark Goldstein, Thomas Moyer, David M. Eyers, Margo I. Seltzer, Jean Bacon
SoCC5
2017 PHP2Uni: Building Unikernels Using Scripting Language Transpilation
abstract
Unikernels are a rapidly emerging technology in the world of cloud computing. Unikernels build on research into library operating systems to deliver smaller, faster and more secure virtual machines, specifically optimised for a single application service. These features are especially useful in cost or resource constrained environments. However, as with any new technology, early adopters need to master many technical details, and understand many aspects of the mechanisms used to build and deploy unikernels. Both of these factors may slow adoption rates. In this paper, we present our initial experiments into the use of an approach for building unikernels that is accessible to those whose technical expertise is focused on web development. We present PHP2Uni: a tool chain that takes a website built from PHP files-PHP remains the most widely used web language-and builds a resource-efficient unikernel image from them, while requiring little knowledge of the underlying operating system software complexity.
Thomas Pasquier, David M. Eyers, Jean Bacon
IC2E2
2017 TrustCEP: Adopting a Trust-Based Approach for Distributed Complex Event Processing
abstract
The advent of the Internet of Things (IoT), with modern sensors and sensor-based devices, will significantly stimulate the development of context-aware applications. An effective means to extract higher-level contextual information from sensor data is distributed complex event processing (CEP), which facilitates the analysis of real-time data streams coming from heterogeneous and distributed sources. Considering that user context is inherently sensitive information, the preservation of privacy is critical once the processing of user context takes place over several (possibly malicious) devices, especially in collaborative scenarios. In this paper, we tackle this issue by introducing a trust-based approach for the placement and execution of CEP operators in a distributed environment. We propose a trust management model based on communication interactions among the users. Furthermore, we incorporate trust recommendations using a cosine-based similarity check in order to overcome collusion and on-off attacks. We developed a smartphone-based distributed CEP system called TrustCEP to evaluate our approach for trust management. Based on the evaluation of TrustCEP, we observe that our approach induces a minimal increase in average battery consumption compared to privacy-negligent approaches.
Rahul Chini Dwarakanath, Boris Koldehofe, Yashas Bharadwaj, The An Binh Nguyen, David M. Eyers, Ralf Steinmetz
MDM5
2017 Glamdring: Automatic Application Partitioning for Intel SGX
Joshua Lind, Christian Priebe, Divya Muthukumaran, Dan O'Keeffe, Pierre-Louis Aublin, Florian Kelbert, Tobias Reiher, David Goltzsche, David M. Eyers, Rüdiger Kapitza, Christof Fetzer, Peter R. Pietzuch
USENIX ATC9
2017 Camflow: Managed Data-Sharing for Cloud Services
abstract
A model of cloud services is emerging whereby a few trusted providers manage the underlying hardware and communications whereas many companies build on this infrastructure to offer higher level, cloud-hosted PaaS services and/or SaaS applications. From the start, strong isolation between cloud tenants was seen to be of paramount importance, provided first by virtual machines (VM) and later by containers, which share the operating system (OS) kernel. Increasingly it is the case that applications also require facilities to effect isolation and protection of data managed bythose applications. They also require flexible data sharingwith other applications, often across the traditional cloud-isolation boundaries; for example, when government, consisting of different departments, provides services to its citizens through a common platform. These concerns relate to the management of data. Traditional access control is application and principal/role specific, applied at policy enforcement points, after which there is no subsequent control over where data flows;a crucial issue once data has left its owner's control by cloud-hosted applications andwithin cloud-services. Information Flow Control (IFC), in addition, offers system-wide, end-to-end, flow control based on the properties of the data. We discuss the potential of clouddeployed IFC for enforcingowners' data flow policy with regard to protection and sharing, aswell as safeguarding against malicious or buggy software. In addition, the audit log associated with IFC provides transparency and offers system-wide visibility over data flows. This helps those responsible to meet their data management obligations, providing evidence of compliance, and aids in the identification ofpolicy errors and misconfigurations. We present our IFC model and describe and evaluate our IFC architecture and implementation (CamFlow). This comprises an OS level implementation of IFC with support for application management, together with an IFC-enabled middleware.
Thomas Pasquier, Jatinder Singh, David M. Eyers, Jean Bacon
IEEE Trans. Cloud Comput.3
2016 Information Flow Audit for PaaS Clouds
abstract
With the rapid increase in uptake of cloud services, issues of data management are becoming increasingly prominent. There is a clear, outstanding need for the ability for specified policy to control and track data as it flows throughout cloud infrastructure, to ensure that those responsible for data are meeting their obligations. This paper introduces Information Flow Audit, an approach for tracking information flows within cloud infrastructure. This builds upon CamFlow (Cambridge Flow Control Architecture), a prototype implementation of our model for data-centric security in PaaS clouds. CamFlow enforces Information Flow Control policy both intra-machine at the kernel-level, and inter-machine, on message exchange. Here we demonstrate how CamFlow can be extended to provide data-centric audit logs akin to provenance metadata in a format in which analyses can easily be automated through the use of standard graph processing tools. This allows detailed understanding of the overall system. Combining a continuously enforced data-centric security mechanism with meaningful audit empowers tenants and providers to both meet and demonstrate compliance with their data management obligations.
Thomas Pasquier, Jatinder Singh, Jean Bacon, David M. Eyers
IC2E4
2016 PCAF: Scalable, High Precision k-NN Search Using Principal Component Analysis Based Filtering
abstract
Approximate k Nearest Neighbours (AkNN) search is widely used in domains such as computer vision and machine learning. However, AkNN search in high dimensional datasets does not work well on multicore platforms. It scales poorly due to its large memory footprint. Current parallel AkNN search using space subdivision for filtering helps reduce the memory footprint, but leads to loss of precision. We propose a new data filtering method -- PCAF -- for parallel AkNN search based on principal components analysis. PCAF improves on previous methods by demonstrating sustained, high scalability for a wide range of high dimensional datasets on both Intel and AMD multicore platforms. Moreover, PCAF maintains high precision in terms of the AkNN search results.
Huan Feng, David M. Eyers, Steven Mills, Yongwei Wu 0001, Zhiyi Huang 0001
ICPP2
2016 Big ideas paper: Policy-driven middleware for a legally-compliant Internet of Things
Jatinder Singh, Thomas Pasquier, Jean Bacon, Julia E. Powles, Raluca Diaconu, David M. Eyers
Middleware6
2016 SCONE: Secure Linux Containers with Intel SGX
Sergei Arnautov, Bohdan Trach, Franz Gregor, Thomas Knauth, André Martin, Christian Priebe, Joshua Lind, Divya Muthukumaran, Dan O'Keeffe, Mark Stillwell, David Goltzsche, David M. Eyers, Rüdiger Kapitza, Peter R. Pietzuch, Christof Fetzer
OSDI12
2016 Data-Centric Access Control for Cloud Computing
abstract
The usual approach to security for cloud-hosted applications is strong separation. However, it is often the case that the same data is used by different applications, particularly given the increase in data-driven (`big data' and IoT) applications. We argue that access control for the cloud should no longer be application-specific but should be data-centric, associated with the data that can flow between applications. Indeed, the data may originate outside cloud services from diverse sources such as medical monitoring, environmental sensing etc. Information Flow Control (IFC) potentially offers data-centric, system-wide data access control. It has been shown that IFC can be provided at operating system level as part of a PaaS offering, with an acceptable overhead.
Thomas Pasquier, Jean Bacon, Jatinder Singh, David M. Eyers
SACMAT4
2016 Twenty Security Considerations for Cloud-Supported Internet of Things
abstract
To realize the broad vision of pervasive computing, underpinned by the “Internet of Things” (IoT), it is essential to break down application and technology-based silos and support broad connectivity and data sharing; the cloud being a natural enabler. Work in IoT tends toward the subsystem, often focusing on particular technical concerns or application domains, before offloading data to the cloud. As such, there has been little regard given to the security, privacy, and personal safety risks that arise beyond these subsystems; i.e., from the wide-scale, cross-platform openness that cloud services bring to IoT. In this paper, we focus on security considerations for IoT from the perspectives of cloud tenants, end-users, and cloud providers, in the context of wide-scale IoT proliferation, working across the range of IoT technologies (be they things or entire IoT subsystems). Our contribution is to analyze the current state of cloud-supported IoT to make explicit the security considerations that require further work.
Jatinder Singh, Thomas Pasquier, Jean Bacon, Hajoon Ko, David M. Eyers
IEEE Internet Things J.5
2015 Quantifying the Energy Efficiency Challenges of Achieving Exascale Computing
abstract
Power and performance are two potentially opposing objectives in the design of a supercomputer, where increases in performance often come at the cost of increased power consumption and vice versa. The task of simultaneously maximising both objectives is becoming an increasingly prominent challenge in the development of future exascale supercomputers. To gain some perspective on the scale of the challenge, we analyse the power and performance trends for the Top500 and Green500 supercomputer lists. We then present the PαPW metric, which we use to evaluate the scalability of power efficiency, projecting the development of an exascale system. From this analysis, we found that when both power and performance are considered, the projected date of achieving an exascale system falls far beyond the current target of 2020.
Jason Mair, Zhiyi Huang 0001, David M. Eyers, Yawen Chen 0001
CCGRID3
2015 FlowWatcher: Defending against Data Disclosure Vulnerabilities in Web Applications
abstract
Bugs in the authorisation logic of web applications can expose the data of one user to another. Such data disclosure vulnerabilities are common---they can be caused by a single omitted access control check in the application. We make the observation that, while the implementation of the authorisation logic is complex and therefore error-prone, most web applications only use simple access control models, in which each piece of data is accessible by a user or a group of users. This makes it possible to validate the correct operation of the authorisation logic externally, based on the observed data in HTTP traffic to and from an application.
Divya Muthukumaran, Dan O'Keeffe, Christian Priebe, David M. Eyers, Brian Shand, Peter R. Pietzuch
CCS4
2015 Integrating Messaging Middleware and Information Flow Control
abstract
Security is an ongoing challenge in cloud computing. Currently, cloud consumers have few mechanisms for managing their data within the cloud provider's infrastructure. Information Flow Control (IFC) involves attaching labels to data, to govern its flow throughout a system. We have worked on kernel-level IFC enforcement to protect data flows within a virtual machine (VM). This paper makes the case for, and demonstrates the feasibility of an IFC-enabled messaging middleware, to enforce IFC within and across applications, containers, VMs, and hosts. We detail how such middleware can integrate with local (kernel) enforcement mechanisms, and highlight the benefits of separating data management policy from application/service-logic.
Jatinder Singh, Thomas Pasquier, Jean Bacon, David M. Eyers
IC2E4
2015 Efficient Selection Algorithm for Fast k-NN Search on GPUs
abstract
k Nearest Neighbours (k-NN) search is a fundamental problem in many computer vision and machine learning tasks. These tasks frequently involve a large number of high-dimensional vectors, which require intensive computations. Recent research work has shown that the Graphics Processing Unit (GPU) is a promising platform for solving k-NN search. However, these search algorithms often meet a serious bottleneck on GPUs due to a selection procedure, called k-selection, which is the final stage of k-NN and significantly affects the overall performance. In this paper, we propose new data structures and optimization techniques to accelerate k-selection on GPUs. Three key techniques are proposed: Merge Queue, Buffered Search and Hierarchical Partition. Compared with previous works, the proposed techniques can significantly improve the computing efficiency of k-selection on GPUs. Experimental results show that our techniques can achieve an up to 4:2× performance improvement over the state-of-the-art methods.
Xiaoxin Tang, Zhiyi Huang 0001, David M. Eyers, Steven Mills, Minyi Guo
IPDPS3
2015 Scalable Multicore k-NN Search via Subspace Clustering for Filtering
abstract
k Nearest Neighbors (k-NN) search is a widely used category of algorithms with applications in domains such as computer vision and machine learning. Despite the desire to process increasing amounts of high-dimensional data within these domains, k-NN algorithms scale poorly on multicore systems because they hit a memory wall. In this paper, we propose a novel data filtering strategy for k-NN search algorithms on multicore platforms. By excluding unlikely features during the k-NN search process, this strategy can reduce the amount of computation required as well as the memory footprint. It is complementary to the data selection strategies used in other state-of-the-art k-NN algorithms. A Subspace Clustering for Filtering (SCF) method is proposed to implement the data filtering strategy. Experimental results on four k-NN algorithms show that SCF can significantly improve their performance on three modern multicore platforms with only a small loss of search precision.
Xiaoxin Tang, Zhiyi Huang 0001, David M. Eyers, Steven Mills, Minyi Guo
IEEE Trans. Parallel Distributed Syst.3
2014 FlowK: Information Flow Control for the Cloud
abstract
Security concerns are widely seen as an obstacle to the adoption of cloud computing solutions and although a wealth of law and regulation has emerged, the technical basis for enforcing and demonstrating compliance lags behind. Our Cloud Safety Net project aims to show that Information Flow Control (IFC) can augment existing security mechanisms and provide continuous enforcement of extended. Finer-grained application-level security policy in the cloud. We present FlowK, a loadable kernel module for Linux, as part of a proof of concept that IFC can be provided for cloud computing. Following the principle of policy-mechanism separation, IFC policy is assumed to be expressed at application level and FlowK provides mechanisms to enforce IFC policy at runtime. FlowK's design minimises the changes required to existing software when IFC is provided. To show how FlowK can be integrated with cloud software we have designed and evaluated a framework for deploying IFC-aware web applications, suitable for use in a PaaS cloud.
Thomas Pasquier, Jean Bacon, David M. Eyers
CloudCom3
2014 Data filtering for scalable high-dimensional k-NN search on multicore systems
abstract
K Nearest Neighbors (k-NN) search is a widely used category of algorithms with applications in domains such as computer vision and machine learning. With the rapidly increasing amount of data available, and their high dimensionality, k-NN algorithms scale poorly on multicore systems because they hit a memory wall. In this paper, we propose a novel data filtering strategy, named Subspace Clustering for Filtering (SCF), for k-NN search algorithms on multicore platforms. By excluding unlikely features in k-NN search, this strategy can reduce memory footprint as well as computation. Experimental results on four k-NN algorithms show that SCF can improve their performance on two modern multicore platforms with insignificant loss of search precision.
Xiaoxin Tang, Steven Mills, David M. Eyers, Kai-Cheung Leung, Zhiyi Huang 0001, Minyi Guo
HPDC3
2014 Information Flow Control for Secure Cloud Computing
abstract
Security concerns are widely seen as an obstacle to the adoption of cloud computing solutions. Information Flow Control (IFC) is a well understood Mandatory Access Control methodology. The earliest IFC models targeted security in a centralised environment, but decentralised forms of IFC have been designed and implemented, often within academic research projects. As a result, there is potential for decentralised IFC to achieve better cloud security than is available today. In this paper we describe the properties of cloud computing-Platform-as-a-Service clouds in particular-and review a range of IFC models and implementations to identify opportunities for using IFC within a cloud computing context. Since IFC security is linked to the data that it protects, both tenants and providers of cloud services can agree on security policy, in a manner that does not require them to understand and rely on the particulars of the cloud software stack in order to effect enforcement.
Jean Bacon, David M. Eyers, Thomas Pasquier, Jatinder Singh, Ioannis Papagiannis, Peter R. Pietzuch
IEEE Trans. Netw. Serv. Manag.2
2013 Toward Unified and Flexible Security Policies Enforceable within the Cloud
David M. Eyers, Giovanni Russello
DAIS1
2013 Performance Tuning on Multicore Systems for Feature Matching within Image Collections
abstract
Parallel programming is the mainstream for today's HPC applications. Programmers need to parallelize their programs to achieve better performance on multicore systems. However, due to a lack of good understanding of parallelism in algorithms, scheduling policy in runtime systems, and multicore architectures, programmers usually find it very hard to write high-performance, scalable programs on these parallel platforms. Although using a parallelized library written by experts can reduce the amount of work for coding, it does not automatically guarantee good performance according to our study. A better understanding of parallelism in algorithms, the OS/runtime systems, and hardware architectures is necessary if programmers wish to further improve performance. In this paper, we use SIFT-based feature matching within large-scale image collections to show the importance of three factors-the level of parallelism, scheduling policy, and memory architecture-that affect the performance of large-scale feature matching on multicore systems. We demonstrate experimental results using programs based on OpenCV and OpenMP, which are executed on both 16-core and 64-core machines. From our experimental results, we find that images with a large number of features achieve poor scalability on the 64-core machine due to a poor cache utilization. To address this issue of cache performance, we propose a Divide-and-Merge algorithm that divides the feature space into several small sub-spaces so that they fit within the cache. Our experiments show that the performance tuning addressing all of the three factors improves the speedup of feature matching from 10.6× to 21.5× on the 64-core machine. While the speedup is improved by 103%, the scalability of the feature matching algorithm is improved by up to 6.45 times on the 64-core machine with our performance tuning. Our study indicates that performance tuning on multicore systems is very challenging even for a simple image processing algorithm.
Xiaoxin Tang, Steven Mills, David M. Eyers, Zhiyi Huang 0001, Kai-Cheung Leung, Minyi Guo
ICPP3
2011 IO Tetris: Deep Storage Consolidation for the Cloud via Fine-Grained Workload Analysis
abstract
Intelligent workload consolidation in storage systems leads to better Return On Investment (ROI), in terms of more efficient use of data center resources, better Quality of Service (QoS), and lower power consumption. This is particularly significant yet challenging in a cloud environment, in which a large set of different workloads multiplex on a shared, heterogeneous infrastructure. However, the increasing availability of fine grained workload logging facilities allows better insights to be gained from workload profiles. As a consequence, consolidation can be done more deeply, according to a detailed understanding of how well given workloads mix. We describe IO Tetris, which takes a first look at fine-grained consolidation in large-scale storage systems by leveraging temporal patterns found in real-world I/O traces gathered from enterprise storage environments. The core functionality of IO Tetris consists of two stages. A grouping stage performs hierarchical grouping of storage workloads to find complementary groupings that consolidate well together over time and conflicting ones that do not. After that, a migration stage examines the discovered groupings to determine how to maximize resource utilization efficiency while minimizing migration costs. Experiments based on customer I/O traces from a high-end enterprise class IBM storage controller show that a non-trivial number of IO Tetris groupings exist in real-world storage workloads, and that these groupings can be leveraged to achieve better storage consolidation in a cloud setting.
Ramani Routray, David M. Eyers, David D. Chambliss, Prasenjit Sarkar, Douglas Willcocks, Peter R. Pietzuch
IEEE CLOUD3
2011 SafeWeb: A Middleware for Securing Ruby-Based Web Applications
Petr Hosek 0001, Matteo Migliavacca, Ioannis Papagiannis, David M. Eyers, David Evans 0002, Brian Shand, Jean Bacon, Peter R. Pietzuch
Middleware4
2011 Handover Delay in Mobile WiMAX: A Simulation Study
abstract
Worldwide Interoperability for Microwave Access (WiMAX) deployment is growing at a rapid pace. Since Mobile WiMAX has the key advantage of serving large coverage areas per base station, it has become a popular emerging technology for handling mobile clients. However, serving a large number of Mobile Stations (MS) in practice requires an efficient handover scheme. Currently, mobile WiMAX has a long handover delay that contributes to the overall end-to-end communication delay. Recent research is focusing on increasing the efficiency of hand over schemes. In this paper, we analyse the performance of the two standardised handover schemes, namely the Mobile IP and the ASN-based Network Mobility (ABNM), in mobile WiMAX using simulation. Our results clearly indicate that ABNM is more efficient for handover in terms of handover delay and throughput.
Bhaskar Ashoka, David M. Eyers, Zhiyi Huang 0001
PDCAT2
2011 Configuring large-scale storage using a middleware with machine learning
abstract
SUMMARY The proliferation of cloud services and other forms of service‐oriented computing continues to accelerate. Alongside this development is an ever‐increasing need for storage within the data centres that host these services. Management applications used by cloud providers to configure their infrastructure should ideally operate in terms of high‐level policy goals, and not burden administrators with the details presented by particular instances of storage systems. One common technology used by cloud providers is the Storage Area Network (SAN). Support for seamless scalability is engineered into SAN devices. However, SAN infrastructure has a very large parameter space: their optimal deployment is a difficult challenge, and subsequent management in cloud storage continues to be difficult. parindent = 10pt In this article, we discuss our work in SAN configuration middleware, which aims to provide users of large‐scale storage infrastructure such as cloud providers with tools to assist them in their management and evolution of heterogeneous SAN environments. We propose a middleware rather than a stand‐alone tool so that the middleware can be a proxy for interacting with, and informing, a central repository of SAN configurations. Storage system users can have their SAN configurations validated against a knowledge base of best practices that are contained within the central repository. Desensitized information is exported from local management applications to the repository, and the local middleware can subscribe to updates that proactively notify storage users should particular configurations be updated to be considered as sub‐optimal, or unsafe. Copyright © 2011 John Wiley & Sons, Ltd.
David M. Eyers, Ramani Routray, Douglas Willcocks, Peter R. Pietzuch
Concurr. Comput. Pract. Exp.1
2010 Enforcing End-to-End Application Security in the Cloud - (Big Ideas Paper)
Jean Bacon, David Evans 0002, David M. Eyers, Matteo Migliavacca, Peter R. Pietzuch, Brian Shand
Middleware3
2010 Distributed Middleware Enforcement of Event Flow Security Policy
Matteo Migliavacca, Ioannis Papagiannis, David M. Eyers, Brian Shand, Jean Bacon, Peter R. Pietzuch
Middleware3
2010 DEFCON: High-Performance Event Processing with Information Security
Matteo Migliavacca, Ioannis Papagiannis, David M. Eyers, Brian Shand, Jean Bacon, Peter R. Pietzuch
USENIX ATC3
2005 Securing Publish/Subscribe for Multi-domain Systems
Jean Bacon, David M. Eyers, Ken Moody, Lauri I. W. Pesonen
Middleware2
2004 Using trust and risk in role-based access control policies
abstract
Emerging trust and risk management systems provide a framework for principals to determine whether they will exchange resources, without requiring a complete definition of their credentials and intentions. Most distributed access control architectures have far more rigid policy rules, yet in many respects aim to solve a similar problem. This paper elucidates the similarities between trust management and distributed access control systems by demonstrating how the OASIS access control system and its role-based policy language can be extended to make decisions on the basis of trust and risk analyses rather than on the basis of credentials alone. We apply our new model to the prototypical example of a file storage and publication service for the Grid, and test it using our Prolog-based OASIS implementation.
Nathan Dimmock, András Belokosztolszki, David M. Eyers, Jean Bacon, Ken Moody
SACMAT3
2002 Shielding RBAC Infrastructures from Cyberterrorism
András Belokosztolszki, David M. Eyers
DBSec2