VLDB 2026 Research / reviewers in the wild / expert
Chip Killian
dblp:65/438 · also Charles E. Killian, Charles Edwin Killian Jr., Charles Killian
· DBLP profile ↗
22ranked-venue papers
5as first author
1since 2021 · last 2021
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 7 · 1 first-authorComputer networks · 7 · 2 first-author · 1 since 2021Security and privacy · 4Software engineering, systems software and programming languages · 4 · 2 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Computer architecture, parallel and distributed computing, and storage systems
12 papers |
Distributed systems · 55% Cloud and datacenter computing · 14% Parallel and multicore computing · 11% | |
| Computer networks
7 papers |
Network management and operations · 33% Software-defined and programmable networks · 30% Routing and switching · 15% | |
| Software engineering, system software, and programming languages
3 papers |
Program analysis · 35% Programming languages and type systems · 35% Program verification · 18% |
Topics — the 30 heaviest of 39, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Software-defined and programmable networks
SDN control plane |
0.5 | 1 | 2021 | Orion: Google's Software-Defined Networking Control Plane · NSDI 2021 |
Distributed systems
fault tolerance |
0.4 | 3 | 2012 | Composable Reliability for Asynchronous Systems · USENIX ATC 2012 Gatling: Automatic Attack Discovery in Large-Scale Distributed Systems · NDSS 2012 Finding latent performance bugs in systems implementations · SIGSOFT FSE 2010 |
Network management and operations
network verification |
0.2 | 1 | 2016 | Automated Adversarial Testing of Unmodified Wireless Routing Implementations · IEEE/ACM Trans. Netw. 2016 |
Cloud and datacenter computing
datacenter network |
0.1 | 1 | 2021 | Orion: Google's Software-Defined Networking Control Plane · NSDI 2021 |
Cloud and datacenter computing › datacenter network
software-defined networking |
0.1 | 1 | 2021 | Orion: Google's Software-Defined Networking Control Plane · NSDI 2021 |
Distributed systems › peer-to-peer systems
overlay networks |
0.1 | 3 | 2008 | High-bandwidth data dissemination for large-scale distributed systems · ACM Trans. Comput. Syst. 2008 MACEDON: Methodology for Automatically Creating, Evaluating, and Designing Overlay Networks · NSDI 2004 Brief announcement: the overlay network content distribution problem · PODC 2005 |
Network management and operations › fault management
fault diagnosis |
0.1 | 1 | 2012 | Structured Comparative Analysis of Systems Logs to Diagnose Performance Problems · NSDI 2012 |
Network management and operations › performance management
performance diagnosis |
0.1 | 1 | 2012 | Structured Comparative Analysis of Systems Logs to Diagnose Performance Problems · NSDI 2012 |
Embedded and real-time systems › embedded system security
attack detection |
0.1 | 1 | 2012 | Gatling: Automatic Attack Discovery in Large-Scale Distributed Systems · NDSS 2012 |
Distributed systems
distributed debugging |
0.1 | 3 | 2007 | Pip: Detecting the Unexpected in Distributed Systems · NSDI 2006 Experiences with Pip: finding unexpected behavior in distributed systems · SOSP 2005 Mace: language support for building distributed systems · PLDI 2007 |
Parallel and multicore computing › parallel programming models
declarative parallelism |
0.1 | 1 | 2011 | InContext: simple parallelism for distributed applications · HPDC 2011 |
Distributed systems
distributed application development |
0.1 | 1 | 2011 | InContext: simple parallelism for distributed applications · HPDC 2011 |
Parallel and multicore computing
parallel programming models |
0.1 | 1 | 2011 | InContext: simple parallelism for distributed applications · HPDC 2011 |
Performance modeling and evaluation › performance diagnosis
performance anomaly detection |
0.1 | 1 | 2010 | Finding latent performance bugs in systems implementations · SIGSOFT FSE 2010 |
Distributed systems › distributed communication
data dissemination |
0.1 | 1 | 2008 | High-bandwidth data dissemination for large-scale distributed systems · ACM Trans. Comput. Syst. 2008 |
Distributed systems
peer-to-peer systems |
0.1 | 1 | 2008 | High-bandwidth data dissemination for large-scale distributed systems · ACM Trans. Comput. Syst. 2008 |
Programming languages and type systems
domain-specific languages |
0.1 | 1 | 2007 | Mace: language support for building distributed systems · PLDI 2007 |
Program analysis
static analysis |
0.1 | 1 | 2007 | Life, Death, and the Critical Transition: Finding Liveness Bugs in Systems Code (Awarded Best Paper) · NSDI 2007 |
Distributed systems
programming language support |
0.1 | 1 | 2007 | Mace: language support for building distributed systems · PLDI 2007 |
Distributed systems
anomaly detection |
0.1 | 1 | 2006 | Pip: Detecting the Unexpected in Distributed Systems · NSDI 2006 |
Electronic design automation › hardware verification and test
fault detection |
0.1 | 1 | 2006 | Pip: Detecting the Unexpected in Distributed Systems · NSDI 2006 |
Wireless networking › channel assignment › wireless resource management
bandwidth adaptation |
0.1 | 1 | 2005 | Maintaining High-Bandwidth Under Dynamic Network Conditions · USENIX ATC, General Track 2005 |
Content delivery and video streaming
overlay multicast |
0.1 | 1 | 2005 | Brief announcement: the overlay network content distribution problem · PODC 2005 |
Transport protocols and congestion control
transport protocols |
0.1 | 1 | 2005 | Maintaining High-Bandwidth Under Dynamic Network Conditions · USENIX ATC, General Track 2005 |
Internet architecture and protocols
network topology |
0.0 | 1 | 2004 | MACEDON: Methodology for Automatically Creating, Evaluating, and Designing Overlay Networks · NSDI 2004 |
Internet architecture and protocols › overlay networks
overlay construction |
0.0 | 1 | 2004 | MACEDON: Methodology for Automatically Creating, Evaluating, and Designing Overlay Networks · NSDI 2004 |
Distributed systems › peer-to-peer systems › overlay networks
overlay network design |
0.0 | 1 | 2004 | MACEDON: Methodology for Automatically Creating, Evaluating, and Designing Overlay Networks · NSDI 2004 |
Systems and software security
distributed system security |
0.0 | 1 | 2012 | Gatling: Automatic Attack Discovery in Large-Scale Distributed Systems · NDSS 2012 |
Distributed systems
asynchronous systems |
0.0 | 1 | 2012 | Composable Reliability for Asynchronous Systems · USENIX ATC 2012 |
Performance modeling and evaluation
system logs |
0.0 | 1 | 2012 | Structured Comparative Analysis of Systems Logs to Diagnose Performance Problems · NSDI 2012 |
Methods — techniques the papers use, named apart from their topics
model checking · 0.8virtualization · 0.2network emulation · 0.2state space exploration · 0.2random simulation · 0.2measurement · 0.2deployment · 0.2source-to-source compilation · 0.1statistical modeling · 0.1expectation inference · 0.1interactive visualization · 0.1expectation checking · 0.1simulation · 0.0optimization · 0.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2021 | Orion: Google's Software-Defined Networking Control Plane
Andrew D. Ferguson, Steve D. Gribble, Chi-Yao Hong, Chip Killian, Waqar Mohsin, Henrik Mühe, Joon Ong, Leonid B. Poutievski, Lorenzo Vicisano, Richard Alimi, Shawn Shuoshuo Chen, Mike Conley, Subhasree Mandal, Karthik Nagaraj, Kondapa Naidu Bollineni, Amr Sabaa, Shidong Zhang, Amin Vahdat |
NSDI | 4 |
| 2016 | Automated Adversarial Testing of Unmodified Wireless Routing ImplementationsabstractNumerous routing protocols have been designed and subjected to model checking and simulations. However, model checking the design or testing the simulator-based prototype of a protocol does not guarantee that the implementation is free of bugs and vulnerabilities. Testing implementations beyond their basic functionality (also known as adversarial testing) can increase protocol robustness. We focus on automated adversarial testing of real-world implementations of wireless routing protocols. In our previous work we created Turret, a platform that uses a network emulator and virtualization to test unmodified binaries of general distributed systems. Based on Turret, we create Turret-W designed specifically for wireless routing protocols. Turret-W includes new functionalities such as differentiating routing messages from data messages to enable evaluation of attacks on the control plane and the data plane separately, support for several additional protocols (e.g., those that use homogeneous/heterogenous packet formats, those that run on geographic forwarding (not just IP), those that operate at the data link layer instead of the network layer), support for several additional attacks (e.g., replay attacks) and for establishment of adversarial side-channels that allow for collusion. Turret-W can test not only general routing attacks, but also wireless specific attacks such as wormhole. Using Turret-W on publicly available implementations of five representative routing protocols, we (re-)discovered 37 attacks and 3 bugs. All these bugs and 5 of the total attacks were not previously reported to the best of our knowledge. Md. Endadul Hoque, Hyojeong Lee Seibert, Rahul Potharaju, Chip Killian, Cristina Nita-Rotaru |
IEEE/ACM Trans. Netw. | 4 |
| 2015 | Gatling: Automatic Performance Attack Discovery in Large-Scale Distributed SystemsabstractIn this article, we propose Gatling, a framework that automatically finds performance attacks caused by insider attackers in large-scale message-passing distributed systems. In performance attacks, malicious nodes deviate from the protocol when sending or creating messages, with the goal of degrading system performance. We identify a representative set of basic malicious message delivery and lying actions and design a greedy search algorithm that finds effective attacks consisting of a subset of these actions. Although lying malicious actions are protocol dependent, requiring the format and meaning of messages, Gatling captures them without needing to modify the target system by using a type-aware compiler. We have implemented and used Gatling on nine systems, a virtual coordinate system, a distributed hash table lookup service and application, two multicast systems and one file sharing application, and three secure systems designed specifically to tolerate insiders, two based on virtual coordinates and one using Outlier Detection, one invariant derived from physical laws, and the last one a Byzantine resilient replication system. We found a total of 48 attacks, with the time needed to find each attack ranging from a few minutes to a few hours. Hyojeong Lee Seibert, Jeff Seibert, Dylan Fistrovic, Chip Killian, Cristina Nita-Rotaru |
ACM Trans. Inf. Syst. Secur. | 4 |
| 2014 | Turret: A Platform for Automated Attack Finding in Unmodified Distributed System ImplementationsabstractSecurity and performance are critical goals for distributed systems. The increased design complexity, incomplete expertise of developers, and limited functionality of existing testing tools often result in bugs and vulnerabilities that prevent implementations from achieving their design goals in practice. Many of these bugs, vulnerabilities, and misconfigurations manifest after the code has already been deployed making the debugging process difficult and costly. In this paper, we present Turret, a platform for automatically finding performance attacks in unmodified implementations of distributed systems. Turret does not require the user to provide any information about vulnerabilities and runs the implementation in the same operating system setup as the deployment, with an emulated network. Turret uses a new attack finding algorithm and several optimizations that allow it to find attacks in a matter of minutes. We ran Turret on 5 different distributed system implementations specifically designed to tolerate insider attacks, and found 30 performance attacks, 24 of which were not previously reported to the best of our knowledge. Hyojeong Lee Seibert, Jeff Seibert, Md. Endadul Hoque, Chip Killian, Cristina Nita-Rotaru |
ICDCS | 4 |
| 2013 | EventWave: programming model and runtime support for tightly-coupled elastic cloud applicationsabstractAn attractive approach to leveraging the ability of cloud-computing platforms to provide resources on demand is to build elastic applications, which can dynamically scale up or down based on resource requirements. To ease the development of elastic applications, it is useful for programmers to write applications with simple sequential semantics, without considering elasticity, and rely on runtime support to provide that elasticity. While this approach has been useful in restricted domains, such as MapReduce, existing programming models for general distributed applications do not expose enough information about their inherent organization of state and computation to provide such transparent elasticity. Wei-Chiu Chuang, Bo Sang, Sunghwan Yoo, Milind Kulkarni 0001, Chip Killian |
SoCC | 6 |
| 2013 | Adversarial testing of wireless routing implementationsabstractWe focus on automated adversarial testing of real-world implementations of wireless routing protocols. We extend an existing platform, Turret, designed for general distributed systems, to address the specifics of wireless routing protocols. Specifically, we add functionality to differentiate routing messages from data messages and support wireless specific attacks such as blackhole and wormhole, or routing attacks such as replay attacks. The extended platform, Turret-W, uses a network emulator to create reproducible network conditions and virtualization to run unmodified binaries of wireless protocol implementations. Using the platform on publicly available implementations of two representative routing protocols we (re-)discovered 14 attacks and 3 bugs. Md. Endadul Hoque, Hyojeong Lee Seibert, Rahul Potharaju, Chip Killian, Cristina Nita-Rotaru |
WISEC | 4 |
| 2012 | Gatling: Automatic Attack Discovery in Large-Scale Distributed Systems
Hyojeong Lee Seibert, Jeff Seibert, Chip Killian, Cristina Nita-Rotaru |
NDSS | 3 |
| 2012 | Structured Comparative Analysis of Systems Logs to Diagnose Performance Problems
Karthik Nagaraj, Chip Killian, Jennifer Neville |
NSDI | 2 |
| 2012 | Composable Reliability for Asynchronous Systems
Sunghwan Yoo, Chip Killian, Terence Kelly, Hyoun Kyu Cho, Steven Plite |
USENIX ATC | 2 |
| 2011 | InContext: simple parallelism for distributed applicationsabstractAs networking services, such as DHTs, provide increasingly complex functionality, providing acceptable performance will require parallelizing their operations on individual nodes. Unfortunately, the event-driven style in which these applications have traditionally been written makes it difficult to reason about parallelism, and providing safe, efficient parallel implementations of distributed systems remains a challenge. In this paper, we introduce a declarative programming model based on contexts, which allows programmers to specify the sharing behavior of event handlers. Programs that adhere to the programming model can be safely parallelized according to an abstract execution model, with parallel behavior that is well-defined with respect to the expected sequential behavior. The declarative nature of the programming model allows conformance to be captured as a safety property that can be verified using a model checker. Sunghwan Yoo, Hyojeong Lee Seibert, Chip Killian, Milind Kulkarni 0001 |
HPDC | 3 |
| 2011 | Removing the blinders: Using information to mitigate adversaries in adaptive overlaysabstractThe proliferation of peer-to-peer systems has led to the increasing deployment of dynamic, adaptive overlay networks that are designed to preserve application performance goals. While such networks provide increased performance and resiliency to benign faults, they are susceptible to attacks conducted by compromised overlay nodes, especially those targeting the adaptation mechanisms. In this work, we propose a lightweight, general solution to increase the resiliency of adaptive overlay networks. By locally aggregating and correlating network topology with system performance metrics such as latency and bandwidth, each node can check the consistency of the reported information and constrain the attacker's ability to lie about system metrics. As a result, each node can make better adaptation decisions. We demonstrate the susceptibility of adaptation mechanisms to malicious attacks and the utility of our solution through real-life deployments of mature, adaptive overlay-based systems. David Zage, Chip Killian, Cristina Nita-Rotaru |
NSS | 2 |
| 2010 | Finding latent performance bugs in systems implementationsabstractRobust distributed systems commonly employ high-level recovery mechanisms enabling the system to recover from a wide variety of problematic environmental conditions such as node failures, packet drops and link disconnections. Unfortunately, these recovery mechanisms also effectively mask additional serious design and implementation errors, disguising them as latent performance bugs that severely degrade end-to-end system performance. These bugs typically go unnoticed due to the challenge of distinguishing between a bug and an intermittent environmental condition that must be tolerated by the system. We present techniques that can automatically pinpoint latent performance bugs in systems implementations, in the spirit of recent advances in model checking by systematic state space exploration. The techniques proceed by automating the process of conducting random simulations, identifying performance anomalies, and analyzing anomalous executions to pinpoint the circumstances leading to performance degradation. Chip Killian, Karthik Nagaraj, Salman Pervez, Ryan Braud, James W. Anderson, Ranjit Jhala |
SIGSOFT FSE | 1 |
| 2009 | Live Debugging of Distributed Systems
Darren Dao, Jeannie R. Albrecht, Chip Killian, Amin Vahdat |
CC | 3 |
| 2009 | Building Distributed Systems Using MaceabstractMace, MaceMC andMacePCwork together to make it easier to build correct, high performance distributed systems implementations. Mace developers find that it now takes them a fraction of the time previously needed to go from design to implementation of a new distributed system. Together with ModelNet and Plush, the whole toolkit is among the best in the world for implementing, testing, evaluating, and deploying distributed and peer-to-peer systems. Mace represents six years of development work and has been publicly available for five years. In addition to the Mace research contributions, the Mace distribution also represents many of the best-quality publicly-available implementations of the included services, and by itself represents a practical contribution that users worldwide recognize and utilize. Chip Killian, James W. Anderson, Ryan Braud, Ranjit Jhala, Amin Vahdat |
Peer-to-Peer Computing | 1 |
| 2008 | High-bandwidth data dissemination for large-scale distributed systemsabstractThis article focuses on the multireceiver data dissemination problem. Initially, IP multicast formed the basis for efficiently supporting such distribution. More recently, overlay networks have emerged to support point-to-multipoint communication. Both techniques focus on constructing trees rooted at the source to distribute content among all interested receivers. We argue, however, that trees have two fundamental limitations for data dissemination. First, since all data comes from a single parent, participants must often continuously probe in search of a parent with an acceptable level of bandwidth. Second, due to packet losses and failures, available bandwidth is monotonically decreasing down the tree. To address these limitations, we present Bullet, a data dissemination mesh that takes advantage of the computational and storage capabilities of end hosts to create a distribution structure where a node receives data in parallel from multiple peers. For the mesh to deliver improved bandwidth and reliability, we need to solve several key problems: (i) disseminating disjoint data over the mesh, (ii) locating missing content, (iii) finding who to peer with (peering strategy), (iv) retrieving data at the right rate from all peers (flow control), and (v) recovering from failures and adapting to dynamically changing network conditions. Additionally, the system should be self-adjusting and should have few user-adjustable parameter settings. We describe our approach to addressing all of these problems in a working, deployed system across the Internet. Bullet outperforms state-of-the-art systems, including BitTorrent, by 25-70% and exhibits strong performance and reliability in a range of deployment settings. In addition, we find that, relative to tree-based solutions, Bullet reduces the need to perform expensive bandwidth probing. Dejan Kostic, Alex C. Snoeren, Amin Vahdat, Ryan Braud, Chip Killian, James W. Anderson, Jeannie R. Albrecht, Adolfo Rodriguez, Erik Vandekieft |
ACM Trans. Comput. Syst. | 5 |
| 2007 | Life, Death, and the Critical Transition: Finding Liveness Bugs in Systems Code (Awarded Best Paper)
Chip Killian, James W. Anderson, Ranjit Jhala, Amin Vahdat |
NSDI | 1 |
| 2007 | Mace: language support for building distributed systemsabstractBuilding distributed systems is particularly difficult because of the asynchronous, heterogeneous, and failure-prone environment where these systemsmust run. Tools for building distributed systems must strike a compromise between reducing programmer effort and increasing system efficiency. We present Mace, a C++ language extension and source-to-source compiler that translates a concise but expressive distributed system specification into a C++ implementation. Mace overcomes the limitations of low-level languages by providing a unified framework for networking and event handling, and the limitations of high-level languages by allowing programmers to write program components in a controlled and structured manner in C++. By imposing structure and restrictions on how applications can be written, Mace supports debugging at a higher level, including support for efficient model checking and causal-path debugging. Because Mace programs compile to C++, programmers can use existing C++ tools, including optimizers, profilers, and debuggers to analyze their systems. Chip Killian, James W. Anderson, Ryan Braud, Ranjit Jhala, Amin Vahdat |
PLDI | 1 |
| 2006 | Pip: Detecting the Unexpected in Distributed Systems
Patrick Reynolds, Chip Killian, Janet L. Wiener, Jeffrey C. Mogul, Mehul A. Shah, Amin Vahdat |
NSDI | 2 |
| 2005 | Brief announcement: the overlay network content distribution problemabstractMany overlay multicast protocols have been designed and deployed across the Internet to support content distribution. To our knowledge, however, none have provided a rigorous analysis of the problem or the effectiveness of their proposed solutions. We define the Overlay Network Content Distribution (OCD) problem to allow such analyses. Chip Killian, Michael Vrable, Alex C. Snoeren, Amin Vahdat, Joseph Pasquale |
PODC | 1 |
| 2005 | Experiences with Pip: finding unexpected behavior in distributed systemsabstractBugs in complex distributed systems are often hard to find. Many bugs reflect discrepancies between a system's behavior and the programmer's assumptions about that behavior. Differences may be in correctness, in performance characteristics, or both. Our debugging framework, Pip, compares actual behavior with expected behavior and visualizes both. Pip consists of two tools to help reconcile assumptions and actual behavior: an automatic expectations checker and an interactive behavior-explorer GUI. Patrick Reynolds, Janet L. Wiener, Jeffrey C. Mogul, Mehul A. Shah, Chip Killian, Amin Vahdat |
SOSP | 5 |
| 2005 | Maintaining High-Bandwidth Under Dynamic Network Conditions
Dejan Kostic, Ryan Braud, Chip Killian, Erik Vandekieft, James W. Anderson, Alex C. Snoeren, Amin Vahdat |
USENIX ATC, General Track | 3 |
| 2004 | MACEDON: Methodology for Automatically Creating, Evaluating, and Designing Overlay Networks
Adolfo Rodriguez, Chip Killian, Sooraj Bhat, Dejan Kostic, Amin Vahdat |
NSDI | 2 |