Greg O'Shea

dblp:82/5545 · DBLP profile ↗
← Back
21ranked-venue papers
3as first author
1since 2021 · last 2025
0009-0001-3952-1909ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 8Systems, architecture and hardware · 6 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-authorSoftware engineering, systems software and programming languages · 2Security and privacy · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer architecture, parallel and distributed computing, and storage systems
10 papers
Storage systems · 45% Cloud and datacenter computing · 33% Interconnection networks and networks-on-chip · 14%
Computer networks
11 papers
Software-defined and programmable networks · 22% Datacenter networks · 18% Internet architecture and protocols · 17%

Topics — the 30 heaviest of 44, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Cloud and datacenter computing
cloud storage
0.912025
Holographic Storage for the Cloud: advances and challenges · ACM Trans. Storage 2025
Storage systems › optical storage
holographic memory
0.912025
Holographic Storage for the Cloud: advances and challenges · ACM Trans. Storage 2025
Interconnection networks and networks-on-chip
spatial multiplexing
0.912025
Holographic Storage for the Cloud: advances and challenges · ACM Trans. Storage 2025
Storage systems › storage device technology
storage density
0.912025
Holographic Storage for the Cloud: advances and challenges · ACM Trans. Storage 2025
Storage systems › i/o architecture › i/o subsystem
i/o stack
0.522017
Treating the Storage Stack Like a Network · ACM Trans. Storage 2017
sRoute: Treating the Storage Stack Like a Network · FAST 2016
Cloud and datacenter computing
datacenter storage
0.522017
Treating the Storage Stack Like a Network · ACM Trans. Storage 2017
IOFlow: a software-defined storage architecture · SOSP 2013
Storage systems › storage architecture
software-defined storage
0.312017
Treating the Storage Stack Like a Network · ACM Trans. Storage 2017
Energy-efficient computing
storage energy efficiency
0.312025
Holographic Storage for the Cloud: advances and challenges · ACM Trans. Storage 2025
Storage systems › networked storage
storage networking
0.212016
sRoute: Treating the Storage Stack Like a Network · FAST 2016
Software-defined and programmable networks
programmable data plane
0.212015
Enabling End-Host Network Functions · SIGCOMM 2015
Cloud and datacenter computing
performance isolation
0.212014
End-to-end Performance Isolation Through Virtual Datacenters · OSDI 2014
Edge and fog computing
infostation
0.212013
Measurement-Based Design of Roadside Content Delivery Systems · IEEE Trans. Mob. Comput. 2013
Internet architecture and protocols
network topology
0.212013
CamCubeOS: a key-based network stack for 3D torus cluster topologies · HPDC 2013
Wireless networking
WLAN
0.212013
Measurement-Based Design of Roadside Content Delivery Systems · IEEE Trans. Mob. Comput. 2013
High-performance computing
cluster computing
0.212013
CamCubeOS: a key-based network stack for 3D torus cluster topologies · HPDC 2013
Cloud and datacenter computing
datacenter network
0.212013
Chatty Tenants and the Cloud Network Sharing Problem · NSDI 2013
Cloud and datacenter computing › datacenter network
network sharing
0.212013
Chatty Tenants and the Cloud Network Sharing Problem · NSDI 2013
Vehicular, aerial and satellite networks
vehicular networks
0.122013
Feasibility of content dissemination between devices in moving vehicles · CoNEXT 2009
Measurement-Based Design of Roadside Content Delivery Systems · IEEE Trans. Mob. Comput. 2013
Distributed systems › data aggregation
in-network aggregation
0.112012
Camdoop: Exploiting In-network Aggregation for Big Data Applications · NSDI 2012
Datacenter networks
data center network topology
0.112010
Symbiotic routing in future data centers · SIGCOMM 2010
Routing and switching
routing protocol
0.112010
Symbiotic routing in future data centers · SIGCOMM 2010
Vehicular, aerial and satellite networks › data delivery
vehicular content distribution
0.112009
Feasibility of content dissemination between devices in moving vehicles · CoNEXT 2009
Software-defined and programmable networks
control plane
0.112017
Treating the Storage Stack Like a Network · ACM Trans. Storage 2017
Internet architecture and protocols › network architecture design › layered architecture › protocol layering
network stack
0.112016
sRoute: Treating the Storage Stack Like a Network · FAST 2016
Internet architecture and protocols › overlay networks › peer-to-peer routing
DHT-based routing
0.112006
Virtual ring routing: network routing inspired by DHTs · SIGCOMM 2006
Internet architecture and protocols
network coding
0.112006
Network coding with traffic engineering · CoNEXT 2006
Routing and switching
routing
0.112006
Virtual ring routing: network routing inspired by DHTs · SIGCOMM 2006
Routing and switching
wireless routing
0.112006
Virtual ring routing: network routing inspired by DHTs · SIGCOMM 2006
Cloud and datacenter computing
virtualization
0.112014
End-to-end Performance Isolation Through Virtual Datacenters · OSDI 2014
Cloud and datacenter computing › datacenter architecture
virtualized datacenter
0.112014
End-to-end Performance Isolation Through Virtual Datacenters · OSDI 2014

Methods — techniques the papers use, named apart from their topics

workload-driven optimization · 0.9physics modeling · 0.9machine learning · 0.9forwarding rules · 0.6data plane switches · 0.6programmable NIC · 0.4kernel bypass · 0.4measurement study · 0.2device-to-device data scavenging · 0.2virtual rings · 0.1network coding · 0.1distributed hash table · 0.1
YearPublicationVenuePosition
2025 Holographic Storage for the Cloud: advances and challenges
abstract
Holographic Storage is an old idea that has always promised high density and fast random access, but has never been commercially competitive with Hard Disk Drives (HDDs) and Solid State Devices (SSDs). In Project HSD at Microsoft Research we asked the question: “Does holographic storage finally make sense for cloud storage?” This article describes our journey toward answering this question. We achieved 1.8× higher density than the previous state-of-the-art, using commodity components available today and leveraging machine learning to compensate for the noise and distortions introduced by commodity components. This uncovered two new challenges which are the focus of this article: achieving high end-to-end energy efficiency without sacrificing capacity, and spatial multiplexing without mechanical movement. Improving end-to-end energy efficiency requires joint optimization across low-level media parameters and higher-level system parameters that govern background maintenance operations such as read refresh and garbage collection. We developed new physics models of the media; analytic and simulation models of the media access and background media maintenance; and workload-driven optimization to find optimal parameter combinations. These techniques resulted in a 14× improvement over the previous approach for typical workloads without sacrificing capacity. We also designed the first scalable and mechanical movement free spatial multiplexing system for holographic storage. Despite these advances, we conclude that currently, holographic storage is still far from the combination of density, capacity scaling, and energy efficiency needed to compete with the incumbent technologies. We need fundamental advances in the physical media that improve energy efficiency by another 1–2 orders of magnitude without reducing data density. Further advances in optics are also required to achieve spatial multiplexing that is simultaneously scalable, low-loss, and high-density.
Nathanael Cheriere, Jiaqi Chu, Grace Brennan, Pashmina Cameron, Pedro Da Costa, Jannes Gladrow, Guilherme Ilunga, Douglas J. Kelly, Joowon Lim, Giorgio Maltese, Tony Mason, Greg O'Shea, Soujanya Ponnapalli, Michael Rudow, Alan Sanders, Theano Stavrinos, Xingbo Wu, Mengyang Yang, Dushyanth Narayanan, Benn C. Thomsen, Antony I. T. Rowstron
ACM Trans. Storage13
2018 DC-DRF: Adaptive Multi-Resource Sharing at Public Cloud Scale
abstract
Public cloud datacenters implement a distributed computing environment built for economy at scale, with hundreds of thousands of compute and storage servers and a large population of predominantly small customers often densely packed to a compute server. Several recent contributions have investigated how equitable sharing and differentiated services can be achieved in this multi-resource environment, using the Extended Dominant Resource Fairness (EDRF) algorithm. However, we find that EDRF requires prohibitive execution time when employed at datacenter scale due to its iterative nature and polynomial time complexity; its closed-form expression does not alter its asymptotic complexity.
Ian A. Kash, Greg O'Shea, Stavros Volos
SoCC2
2017 Treating the Storage Stack Like a Network
abstract
In a data center, an IO from an application to distributed storage traverses not only the network but also several software stages with diverse functionality. This set of ordered stages is known as the storage or IO stack. Stages include caches, hypervisors, IO schedulers, file systems, and device drivers. Indeed, in a typical data center, the number of these stages is often larger than the number of network hops to the destination. Yet, while packet routing is fundamental to networks, no notion of IO routing exists on the storage stack. The path of an IO to an endpoint is predetermined and hard coded. This forces IO with different needs (e.g., requiring different caching or replica selection) to flow through a one-size-fits-all IO stack structure, resulting in an ossified IO stack. This article proposes sRoute, an architecture that provides a routing abstraction for the storage stack. sRoute comprises a centralized control plane and “sSwitches” on the data plane. The control plane sets the forwarding rules in each sSwitch to route IO requests at runtime based on application-specific policies. A key strength of our architecture is that it works with unmodified applications and Virtual Machines (VMs). This article shows significant benefits of customized IO routing to data center tenants: for example, a factor of 10 for tail IO latency, more than 60% better throughput for a customized replication protocol, a factor of 2 in throughput for customized caching, and enabling live performance debugging in a running system.
Ioan A. Stefanovici, Bianca Schroeder, Greg O'Shea, Eno Thereska
ACM Trans. Storage3
2016 sRoute: Treating the Storage Stack Like a Network
Ioan A. Stefanovici, Bianca Schroeder, Greg O'Shea, Eno Thereska
FAST3
2015 Software-defined caching: managing caches in multi-tenant data centers
abstract
In data centers, caches work both to provide low IO latencies and to reduce the load on the back-end network and storage. But they are not designed for multi-tenancy; system-level caches today cannot be configured to match tenant or provider objectives. Exacerbating the problem is the increasing number of un-coordinated caches on the IO data plane. The lack of global visibility on the control plane to coordinate this distributed set of caches leads to inefficiencies, increasing cloud provider cost.
Ioan A. Stefanovici, Eno Thereska, Greg O'Shea, Bianca Schroeder, Hitesh Ballani, Thomas Karagiannis, Antony I. T. Rowstron, Tom Talpey
SoCC3
2015 Enabling End-Host Network Functions
abstract
Many network functions executed in modern datacenters, e.g., load balancing, application-level QoS, and congestion control, exhibit three common properties at the data-plane: they need to access and modify state, to perform computations, and to access application semantics -- this is critical since many network functions are best expressed in terms of application-level messages. In this paper, we argue that the end hosts are a natural enforcement point for these functions and we present Eden, an architecture for implementing network functions at datacenter end hosts with minimal network support. Eden comprises three components, a centralized controller, an enclave at each end host, and Eden-compliant applications called stages. To implement network functions, the controller configures stages to classify their data into messages and the enclaves to apply action functions based on a packet's class. Our Eden prototype includes enclaves implemented both in the OS kernel and on programmable NICs. Through case studies, we show how application-level classification and the ability to run actual programs on the data-path allows Eden to efficiently support a broad range of network functions at the network's edge.
Hitesh Ballani, Paolo Costa, Christos Gkantsidis, Matthew P. Grosvenor, Thomas Karagiannis, Lazaros Koromilas, Greg O'Shea
SIGCOMM7
2014 End-to-end Performance Isolation Through Virtual Datacenters
Sebastian Angel, Hitesh Ballani, Thomas Karagiannis, Greg O'Shea, Eno Thereska
OSDI4
2013 CamCubeOS: a key-based network stack for 3D torus cluster topologies
Paolo Costa, Austin Donnelly, Greg O'Shea, Antony I. T. Rowstron
HPDC3
2013 Chatty Tenants and the Cloud Network Sharing Problem
Hitesh Ballani, Keon Jang, Thomas Karagiannis, Changhoon Kim, Dinan Gunawardena, Greg O'Shea
NSDI6
2013 IOFlow: a software-defined storage architecture
abstract
In data centers, the IO path to storage is long and complex. It comprises many layers or "stages" with opaque interfaces between them. This makes it hard to enforce end-to-end policies that dictate a storage IO flow's performance (e.g., guarantee a tenant's IO bandwidth) and routing (e.g., route an untrusted VM's traffic through a sanitization middlebox). These policies require IO differentiation along the flow path and global visibility at the control plane. We design IOFlow, an architecture that uses a logically centralized control plane to enable high-level flow policies. IOFlow adds a queuing abstraction at data-plane stages and exposes this to the controller. The controller can then translate policies into queuing rules at individual stages. It can also choose among multiple stages for policy enforcement.
Eno Thereska, Hitesh Ballani, Greg O'Shea, Thomas Karagiannis, Antony I. T. Rowstron, Tom Talpey, Richard Black, Timothy Zhu
SOSP3
2013 Measurement-Based Design of Roadside Content Delivery Systems
abstract
With today's ubiquity of thin computing devices, mobile users are accustomed to having rich location-aware information at their fingertips, such as restaurant menus, shopping mall maps, movie showtimes, and trailers. However, delivering rich content is challenging, particularly for highly mobile users in vehicles. Technologies such as cellular-3G provide limited bandwidth at significant costs. In contrast, providers can cheaply and easily deploy a small number of WiFi infostations that quickly deliver large content to vehicles passing by for future offline browsing. While several projects have proposed systems for disseminating content via roadside infostations, most use simplified models and simulations to guide their design for scalability. Many suspect that scalability with increasing vehicle density is the major challenge for infostations, but few if any have studied the performance of these systems via real measurements. Intuitively, per-vehicle throughput for unicast infostations degrades with the number of vehicles near the infostation, while broadcast infostations are unreliable, and lack rate adaptation. In this work, we collect over 200 h of detailed highway measurements with a fleet of WiFi-enabled vehicles. We use analysis of these results to explore the design space of WiFi infostations, in order to determine whether unicast or broadcast should be used to build high-throughput infostations that scale with device density. Our measurement results demonstrate the limitations of both approaches. Our insights lead to Starfish, a high-bandwidth and scalable infostation system that incorporates device-to-device data scavenging, where nearby vehicles share data received from the infostation. Data scavenging increases dissemination throughput by a factor of 2-6, allowing both broadcast and unicast throughput to scale with device density.
Vinod Kone, Haitao Zheng 0001, Antony I. T. Rowstron, Greg O'Shea, Ben Y. Zhao
IEEE Trans. Mob. Comput.4
2012 Camdoop: Exploiting In-network Aggregation for Big Data Applications
Paolo Costa, Austin Donnelly, Antony I. T. Rowstron, Greg O'Shea
NSDI4
2010 Symbiotic routing in future data centers
abstract
Building distributed applications that run in data centers is hard. The CamCube project explores the design of a shipping container sized data center with the goal of building an easier platform on which to build these applications. CamCube replaces the traditional switch-based network with a 3D torus topology, with each server directly connected to six other servers. As in other proposals, e.g. DCell and BCube, multi-hop routing in CamCube requires servers to participate in packet forwarding. To date, as in existing data centers, these approaches have all provided a single routing protocol for the applications.
Hussam Abu-Libdeh, Paolo Costa, Antony I. T. Rowstron, Greg O'Shea, Austin Donnelly
SIGCOMM4
2009 Feasibility of content dissemination between devices in moving vehicles
abstract
We investigate the feasibility of content distribution between devices mounted in moving vehicles using commodity WiFi. We assume that each device stores content in a set of files, and that each file has a version number. When two devices come into wireless range, they attempt to synchronize the latest versions of any files they have in common. This is challenging because connections are often short-lived and have variable link quality. Prior work demonstrates that current protocols perform badly under these conditions. To motivate this work, we use the example of Personal Navigation Devices (PNDs), or SatNavs, where the content to be exchanged includes maps and points-of-interest files.
Thomas Zahn, Greg O'Shea, Antony I. T. Rowstron
CoNEXT2
2006 Network coding with traffic engineering
abstract
In network coding, a router in the network mixes information from different flows. In the seminal work by Ahlswede et al [1], network coding is established as a technique to potentially increase the network capacity.
Miguel Castro 0001, Jon Crowcroft, Greg O'Shea, Antony I. T. Rowstron
CoNEXT4
2006 Virtual ring routing: network routing inspired by DHTs
abstract
This paper presents Virtual Ring Routing (VRR), a new network routing protocol that occupies a unique point in the design space. VRR is inspired by overlay routing algorithms in Distributed Hash Tables (DHTs) but it does not rely on an underlying network routing protocol. It is implemented directly on top of the link layer. VRR provides both raditional point-to-point network routing and DHT routing to the node responsible for a hash table key.VRR can be used with any link layer technology but this paper describes a design and several implementations of VRR that are tuned for wireless networks. We evaluate the performance of VRR using simulations and measurements from a sensor network and an 802.11a testbed. The experimental results show that VRR provides robust performance across a wide range of environments and workloads. It performs comparably to, or better than, the best wireless routing protocol in each experiment. VRR performs well because of its unique features: it does not require network flooding or trans-lation between fixed identifiers and location-dependent addresses.
Matthew Caesar 0001, Miguel Castro 0001, Ed Nightingale, Greg O'Shea, Antony I. T. Rowstron
SIGCOMM4
2001 A Logic of Access Control
abstract
The effectiveness of an access control mechanism in implementing a security policy in a centralized operating system is often weakened because of the large number of possible access rights involved, informal specification of security policy and a lack of tools for assisting systems administrators. Herein we present a logical foundation for automated tools that assist in determining which access rights should be granted by reasoning about the effects of an access control mechanism on the computations performed by an operating system. We demonstrate the practicality and utility of our logical approach by showing how it allows us to construct a deductive database capable of answering questions about the security of two real-world operating systems. We illustrate the application of our techniques by presenting the results of an experiment designed to assess how accurately the configuration of an access control mechanism implements a given security policy.
Jason Crampton, George Loizou, Greg O'Shea
Comput. J.3
2001 A Logic of Access Control
abstract
The effectiveness of an access control mechanism in implementing a security policy in a centralized operating system is often weakened because of the large number of possible access rights involved, informal specification of security policy and a lack of tools for assisting systems administrators. Herein we present a logical foundation for automated tools that assist in determining which access rights should be granted by reasoning about the effects of an access control mechanism on the computations performed by an operating system. We demonstrate the practicality and utility of our logical approach by showing how it allows us to construct a deductive database capable of answering questions about the security of two real-world operating systems. We illustrate the application of our techniques by presenting the results of an experiment designed to assess how accurately the configuration of an access control mechanism implements a given security policy.
Jason Crampton, George Loizou, Greg O'Shea
Comput. J.3
1995 Redundant access rights
Greg O'Shea
Comput. Secur.1
1994 On the Specification, Validation and Verification of Security in Access Control Systems
abstract
The poor reliability of access control mechanisms for security enforcement is investigated. Fundamental problems effecting the specification, validation and verification of access controls as security enforcing functions are identified.
Greg O'Shea
Comput. J.1
1988 Controlling the Dependency of User Access Control Mechanisms on Correctness of User Identification
abstract
The effectiveness of User Access Control mechanisms is largely dependent upon correctly establishing user identity, and a diversity of techniques with varying degrees of accuracy, reliability cost and convenience to the user may be employed in verification of identity. This paper describes an approach allowing this dependency of the accuracy and reliability of identity verification techniques to be considered and controlled within programmed User Access Control mechanisms.
Greg O'Shea
Comput. J.1