VLDB 2026 Research / reviewers in the wild / expert
Daniel Marino
dblp:92/5876
· DBLP profile ↗
14ranked-venue papers
5as first author
0since 2021 · last 2020
0000-0002-8686-4752ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 11 · 5 first-authorSystems, architecture and hardware · 2Security and privacy · 2
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
9 papers |
Concurrent programming · 45% Programming languages and type systems · 22% Program analysis · 21% | |
| Network and information security
1 paper |
Network security · 70% Digital forensics and information hiding · 30% | |
| Computer architecture, parallel and distributed computing, and storage systems
2 papers |
Memory systems · 90% Parallel and multicore computing · 10% |
Topics — the 24 heaviest of 28, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Concurrent programming
memory models |
0.6 | 4 | 2016 | DRFx: An Understandable, High Performance, and Flexible Memory Model for Concurrent Languages · ACM Trans. Program. Lang. Syst. 2016 A case for an SC-preserving compiler · PLDI 2011 Efficient processor support for DRFx, a memory model with exceptions · ASPLOS 2011 |
Digital forensics and information hiding
data provenance |
0.4 | 1 | 2020 | Tactical Provenance Analysis for Endpoint Detection and Response Systems · SP 2020 |
Network security › intrusion detection and prevention › intrusion detection
endpoint detection and response |
0.4 | 1 | 2020 | Tactical Provenance Analysis for Endpoint Detection and Response Systems · SP 2020 |
Network security › intrusion detection and prevention
intrusion detection |
0.4 | 1 | 2020 | Tactical Provenance Analysis for Endpoint Detection and Response Systems · SP 2020 |
Programming languages and type systems
language semantics |
0.2 | 1 | 2016 | DRFx: An Understandable, High Performance, and Flexible Memory Model for Concurrent Languages · ACM Trans. Program. Lang. Syst. 2016 |
Concurrent programming › synchronization
data-centric synchronization |
0.2 | 2 | 2013 | A data-centric approach to synchronization · ACM Trans. Program. Lang. Syst. 2012 Detecting deadlock in programs with data-centric synchronization · ICSE 2013 |
Concurrent programming
deadlock detection |
0.2 | 1 | 2013 | Detecting deadlock in programs with data-centric synchronization · ICSE 2013 |
Program analysis
static analysis |
0.2 | 1 | 2013 | Detecting deadlock in programs with data-centric synchronization · ICSE 2013 |
Program analysis
type-based analysis |
0.2 | 1 | 2013 | Detecting deadlock in programs with data-centric synchronization · ICSE 2013 |
Programming languages and type systems
type systems |
0.2 | 2 | 2012 | JavaCOP: Declarative pluggable types for java · ACM Trans. Program. Lang. Syst. 2010 A data-centric approach to synchronization · ACM Trans. Program. Lang. Syst. 2012 |
Compilers and program optimization
compiler optimization |
0.1 | 1 | 2012 | End-to-end sequential consistency · ISCA 2012 |
Memory systems › memory consistency
memory consistency model |
0.1 | 1 | 2012 | End-to-end sequential consistency · ISCA 2012 |
Memory systems › memory consistency › memory consistency model
sequential consistency |
0.1 | 1 | 2012 | End-to-end sequential consistency · ISCA 2012 |
Compilers and program optimization
compiler correctness |
0.1 | 1 | 2011 | A case for an SC-preserving compiler · PLDI 2011 |
Concurrent programming › memory models
sequential consistency |
0.1 | 1 | 2011 | A case for an SC-preserving compiler · PLDI 2011 |
Memory systems
memory consistency |
0.1 | 1 | 2011 | Efficient processor support for DRFx, a memory model with exceptions · ASPLOS 2011 |
Program analysis
data flow analysis |
0.1 | 1 | 2010 | JavaCOP: Declarative pluggable types for java · ACM Trans. Program. Lang. Syst. 2010 |
Program analysis › data flow analysis
flow-sensitive analysis |
0.1 | 1 | 2010 | JavaCOP: Declarative pluggable types for java · ACM Trans. Program. Lang. Syst. 2010 |
Programming languages and type systems › type systems › static typing
pluggable type systems |
0.1 | 1 | 2010 | JavaCOP: Declarative pluggable types for java · ACM Trans. Program. Lang. Syst. 2010 |
Software testing › system software testing › language processor testing
type system testing |
0.1 | 1 | 2010 | JavaCOP: Declarative pluggable types for java · ACM Trans. Program. Lang. Syst. 2010 |
Concurrent programming
concurrency bugs |
0.1 | 1 | 2009 | LiteRace: effective sampling for lightweight data-race detection · PLDI 2009 |
Concurrent programming › concurrency bug detection
data race detection |
0.1 | 1 | 2009 | LiteRace: effective sampling for lightweight data-race detection · PLDI 2009 |
Program analysis
dynamic analysis |
0.1 | 1 | 2009 | LiteRace: effective sampling for lightweight data-race detection · PLDI 2009 |
Concurrent programming › concurrency bug detection › data race detection
sampling-based race detection |
0.1 | 1 | 2009 | LiteRace: effective sampling for lightweight data-race detection · PLDI 2009 |
Methods — techniques the papers use, named apart from their topics
threat scoring · 0.4provenance graph analysis · 0.4hardware-software co-design · 0.3DRFx · 0.2type-based static analysis · 0.2lock ordering annotations · 0.2declarative constraint language · 0.1abstract syntax tree constraints · 0.1sampling · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2020 | Tactical Provenance Analysis for Endpoint Detection and Response SystemsabstractEndpoint Detection and Response (EDR) tools provide visibility into sophisticated intrusions by matching system events against known adversarial behaviors. However, current solutions suffer from three challenges: 1) EDR tools generate a high volume of false alarms, creating backlogs of investigation tasks for analysts; 2) determining the veracity of these threat alerts requires tedious manual labor due to the overwhelming amount of low-level system logs, creating a "needle-in-a-haystack" problem; and 3) due to the tremendous resource burden of log retention, in practice the system logs describing long-lived attack campaigns are often deleted before an investigation is ever initiated.This paper describes an effort to bring the benefits of data provenance to commercial EDR tools. We introduce the notion of Tactical Provenance Graphs (TPGs) that, rather than encoding low-level system event dependencies, reason about causal dependencies between EDR-generated threat alerts. TPGs provide compact visualization of multi-stage attacks to analysts, accelerating investigation. To address EDR's false alarm problem, we introduce a threat scoring methodology that assesses risk based on the temporal ordering between individual threat alerts present in the TPG. In contrast to the retention of unwieldy system logs, we maintain a minimally-sufficient skeleton graph that can provide linkability between existing and future threat alerts. We evaluate our system, RapSheet, using the Symantec EDR tool in an enterprise environment. Results show that our approach can rank truly malicious TPGs higher than false alarm TPGs. Moreover, our skeleton graph reduces the long-term burden of log retention by up to 87%. Wajih Ul Hassan, Adam Bates 0001, Daniel Marino |
SP | 3 |
| 2016 | DRFx: An Understandable, High Performance, and Flexible Memory Model for Concurrent Languages
Daniel Marino, Abhayendra Singh, Todd D. Millstein, Madan Musuvathi, Satish Narayanasamy |
ACM Trans. Program. Lang. Syst. | 1 |
| 2015 | Harbormaster: Policy Enforcement for ContainersabstractLightweight virtualization, as implemented by application container solutions such as Docker, have the potential to revolutionize the way multi-tier applications are developed and deployed, especially in the cloud. The success of application containers can be partly attributed to their ability to share resources with the underlying platform that hosts them. As such, the isolation provided by such containers is not as strict as with traditional VMs. These very characteristics that have contributed to the success of application containers can also be seen as factors that limit their widespread commercial adoption, since enterprise IT administrators cannot implement the various -- and often fine-grained -- security policies they are required to abide by. This problem is of limited consequence when a host is running a single user's application containers. But sharing compute resources among multiple users is an important benefit of containers and cloud-based deployment. In this paper we present a preliminary discussion of the challenges associated with enterprise security policy management for application containers deployed in multi-user environments. Furthermore, we present Harbormaster, a system that addresses some of these challenges by enforcing policy checks on Docker container management operations and allowing administrators to implement the principle of least privilege. Daniel Marino, Petros Efstathopoulos |
CloudCom | 2 |
| 2014 | Some Vulnerabilities Are Different Than Others - Studying Vulnerabilities and Attack Surfaces in the Wild
Kartik Nayak, Daniel Marino, Petros Efstathopoulos, Tudor Dumitras |
RAID | 2 |
| 2013 | Detecting deadlock in programs with data-centric synchronizationabstractPreviously, we developed a data-centric approach to concurrency control in which programmers specify synchronization constraints declaratively, by grouping shared locations into atomic sets. We implemented our ideas in a Java extension called AJ, using Java locks to implement synchronization. We proved that atomicity violations are prevented by construction, and demonstrated that realistic Java programs can be refactored into AJ without significant loss of performance. This paper presents an algorithm for detecting possible deadlock in AJ programs by ordering the locks associated with atomic sets. In our approach, a type-based static analysis is extended to handle recursive data structures by considering programmer-supplied, compiler-verified lock ordering annotations. In an evaluation of the algorithm, all 10 AJ programs under consideration were shown to be deadlock-free. One program needed 4 ordering annotations and 2 others required minor refactorings. For the remaining 7 programs, no programmer intervention of any kind was required. Daniel Marino, Christian Hammer 0001, Julian Dolby, Mandana Vaziri, Frank Tip, Jan Vitek |
ICSE | 1 |
| 2012 | End-to-end sequential consistencyabstractSequential consistency (SC) is arguably the most intuitive behavior for a shared-memory multithreaded program. It is widely accepted that language-level SC could significantly improve programmability of a multiprocessor system. However, efficiently supporting end-to-end SC remains a challenge as it requires that both compiler and hardware optimizations preserve SC semantics. While a recent study has shown that a compiler can preserve SC semantics for a small performance cost, an efficient and complexity-effective SC hardware remains elusive. Past hardware solutions relied on aggressive speculation techniques, which has not yet been realized in a practical implementation. Abhayendra Singh, Satish Narayanasamy, Daniel Marino, Todd D. Millstein, Madan Musuvathi |
ISCA | 3 |
| 2012 | A data-centric approach to synchronizationabstractConcurrency-related errors, such as data races, are frustratingly difficult to track down and eliminate in large object-oriented programs. Traditional approaches to preventing data races rely on protecting instruction sequences with synchronization operations. Such control-centric approaches are inherently brittle, as the burden is on the programmer to ensure that all concurrently accessed memory locations are consistently protected. Data-centric synchronization is an alternative approach that offloads some of the work on the language implementation. Data-centric synchronization groups fields of objects into atomic sets to indicate that these fields must always be updated atomically. Each atomic set has associated units of work , that is, code fragments that preserve the consistency of that atomic set. Synchronization operations are added automatically by the compiler. We present an extension to the Java programming language that integrates annotations for data-centric concurrency control. The resulting language, called AJ, relies on a type system that enables separate compilation and supports atomic sets that span multiple objects and that also supports full encapsulation for more efficient code generation. We evaluate our proposal by refactoring classes from standard libraries, as well as a number of multithreaded benchmarks, to use atomic sets. Our results suggest that data-centric synchronization is easy to use and enjoys low annotation overhead, while successfully preventing data races. Moreover, experiments on the SPECjbb benchmark suggest that acceptable performance can be achieved with a modest amount of tuning. Julian Dolby, Christian Hammer 0001, Daniel Marino, Frank Tip, Mandana Vaziri, Jan Vitek |
ACM Trans. Program. Lang. Syst. | 3 |
| 2011 | Efficient processor support for DRFx, a memory model with exceptionsabstractA longstanding challenge of shared-memory concurrency is to provide a memory model that allows for efficient implementation while providing strong and simple guarantees to programmers. The C++0x and Java memory models admit a wide variety of compiler and hardwareoptimizations and provide sequentially consistent (SC) semantics for data-race-free programs. However, they either do not provide any semantics (C++0x) or provide a hard-to-understand semantics (Java) for racy programs, compromising the safety and debuggability of such programs. Abhayendra Singh, Daniel Marino, Satish Narayanasamy, Todd D. Millstein, Madan Musuvathi |
ASPLOS | 2 |
| 2011 | A case for an SC-preserving compilerabstractThe most intuitive memory consistency model for shared-memory multi-threaded programming is sequential consistency (SC). However, current concurrent programming languages support a relaxed model, as such relaxations are deemed necessary for enabling important optimizations. This paper demonstrates that an SC-preserving compiler, one that ensures that every SC behavior of a compiler-generated binary is an SC behavior of the source program, retains most of the performance benefits of an optimizing compiler. The key observation is that a large class of optimizations crucial for performance are either already SC-preserving or can be modified to preserve SC while retaining much of their effectiveness. An SC-preserving compiler, obtained by restricting the optimization phases in LLVM, a state-of-the-art C/C++ compiler, incurs an average slowdown of 3.8% and a maximum slowdown of 34% on a set of 30 programs from the SPLASH-2, PARSEC, and SPEC CINT2006 benchmark suites. Daniel Marino, Abhayendra Singh, Todd D. Millstein, Madan Musuvathi, Satish Narayanasamy |
PLDI | 1 |
| 2010 | DRFX: a simple and efficient memory model for concurrent programming languagesabstractThe most intuitive memory model for shared-memory multithreaded programming is sequential consistency(SC), but it disallows the use of many compiler and hardware optimizations thereby impacting performance. Data-race-free (DRF) models, such as the proposed C++0x memory model, guarantee SC execution for datarace-free programs. But these models provide no guarantee at all for racy programs, compromising the safety and debuggability of such programs. To address the safety issue, the Java memory model, which is also based on the DRF model, provides a weak semantics for racy executions. However, this semantics is subtle and complex, making it difficult for programmers to reason about their programs and for compiler writers to ensure the correctness of compiler optimizations. Daniel Marino, Abhayendra Singh, Todd D. Millstein, Madan Musuvathi, Satish Narayanasamy |
PLDI | 1 |
| 2010 | JavaCOP: Declarative pluggable types for javaabstractPluggable types enable users to enforce multiple type systems in one programming language. We have developed a suite of tools, called the JavaCOP framework, that allows developers to create pluggable type systems for Java. JavaCOP provides a simple declarative language in which program constraints are defined over a program's abstract syntax tree. The JavaCOP compiler automatically enforces these constraints on programs during compilation. The JavaCOP framework also includes a dataflow analysis API in order to support type systems which depend on flow-sensitive information. Finally, JavaCOP includes a novel test framework which helps users gain confidence in the correctness of their pluggable type systems. We demonstrate the framework by discussing a number of pluggable type systems which have been implemented in JavaCOP in order to detect errors and enforce strong invariants in programs. These type systems range from general-purpose checkers, such as a type system for nonnull references, to domain-specific ones, such as a checker for conformance to a library's usage rules. Shane Markstrum, Daniel Marino, Matthew Esquivel, Todd D. Millstein, Chris Andreae, James Noble 0001 |
ACM Trans. Program. Lang. Syst. | 2 |
| 2009 | Fine-Grained Access Control with Object-Sensitive Roles
Jeffrey Fischer, Daniel Marino, Rupak Majumdar, Todd D. Millstein |
ECOOP | 2 |
| 2009 | LiteRace: effective sampling for lightweight data-race detectionabstractData races are one of the most common and subtle causes of pernicious concurrency bugs. Static techniques for preventing data races are overly conservative and do not scale well to large programs. Past research has produced several dynamic data race detectors that can be applied to large programs. They are precise in the sense that they only report actual data races. However, dynamic data race detectors incur a high performance overhead, slowing down a program's execution by an order of magnitude. Daniel Marino, Madan Musuvathi, Satish Narayanasamy |
PLDI | 1 |
| 2007 | Enforcing and validating user-defined programming disciplinesabstractNo abstract available. Brian Chin, Daniel Marino, Shane Markstrum, Todd D. Millstein |
PASTE | 2 |