Gloria Mainar-Ruiz

dblp:93/3935 · DBLP profile ↗
← Back
3ranked-venue papers
0as first author
0since 2021 · last 2015
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2Systems, architecture and hardware · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
2 papers
Hardware security and side channels · 77% Systems and software security · 23%
Computer architecture, parallel and distributed computing, and storage systems
3 papers
Cloud and datacenter computing · 59% Distributed systems · 30% Parallel and multicore computing · 11%
Software engineering, system software, and programming languages
1 paper
Operating systems · 50% Program analysis · 50%

Topics — the 11 heaviest of 11, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Cloud and datacenter computing
cloud security
0.422015
VC3: Trustworthy Data Analytics in the Cloud Using SGX · IEEE Symposium on Security and Privacy 2015
STEALTHMEM: System-Level Protection Against Cache-Based Side Channel Attacks in the Cloud · USENIX Security Symposium 2012
Hardware security and side channels › trusted execution environments
Intel SGX
0.212015
VC3: Trustworthy Data Analytics in the Cloud Using SGX · IEEE Symposium on Security and Privacy 2015
Systems and software security › memory safety
memory isolation
0.212015
VC3: Trustworthy Data Analytics in the Cloud Using SGX · IEEE Symposium on Security and Privacy 2015
Hardware security and side channels
trusted execution environments
0.212015
VC3: Trustworthy Data Analytics in the Cloud Using SGX · IEEE Symposium on Security and Privacy 2015
Hardware security and side channels › side-channel countermeasures
cache partitioning
0.112012
STEALTHMEM: System-Level Protection Against Cache-Based Side Channel Attacks in the Cloud · USENIX Security Symposium 2012
Hardware security and side channels › side-channel attack
cache side-channel attacks
0.112012
STEALTHMEM: System-Level Protection Against Cache-Based Side Channel Attacks in the Cloud · USENIX Security Symposium 2012
Program analysis › dynamic analysis
dynamic instrumentation
0.112012
Fay: Extensible Distributed Tracing from Kernels to Clusters · ACM Trans. Comput. Syst. 2012
Operating systems › kernel instrumentation
kernel tracing
0.112012
Fay: Extensible Distributed Tracing from Kernels to Clusters · ACM Trans. Comput. Syst. 2012
Distributed systems › observability › distributed monitoring
distributed tracing
0.112012
Fay: Extensible Distributed Tracing from Kernels to Clusters · ACM Trans. Comput. Syst. 2012
Parallel and multicore computing › data-parallel programming
mapreduce
0.112015
VC3: Trustworthy Data Analytics in the Cloud Using SGX · IEEE Symposium on Security and Privacy 2015
Distributed systems › observability › distributed monitoring
cluster monitoring
0.012012
Fay: Extensible Distributed Tracing from Kernels to Clusters · ACM Trans. Comput. Syst. 2012

Methods — techniques the papers use, named apart from their topics

trusted execution environment · 0.4remote attestation · 0.4runtime instrumentation · 0.3query optimization · 0.3data-parallel processing · 0.3
YearPublicationVenuePosition
2015 VC3: Trustworthy Data Analytics in the Cloud Using SGX
abstract
We present VC3, the first system that allows users to run distributed MapReduce computations in the cloud while keeping their code and data secret, and ensuring the correctness and completeness of their results. VC3 runs on unmodified Hadoop, but crucially keeps Hadoop, the operating system and the hyper visor out of the TCB, thus, confidentiality and integrity are preserved even if these large components are compromised. VC3 relies on SGX processors to isolate memory regions on individual computers, and to deploy new protocols that secure distributed MapReduce computations. VC3 optionally enforces region self-integrity invariants for all MapReduce code running within isolated regions, to prevent attacks due to unsafe memory reads and writes. Experimental results on common benchmarks show that VC3 performs well compared with unprotected Hadoop: VC3's average runtime overhead is negligible for its base security guarantees, 4.5% with write integrity and 8% with read/write integrity.
Felix Schuster, Manuel Costa, Cédric Fournet, Christos Gkantsidis, Marcus Peinado, Gloria Mainar-Ruiz, Mark Russinovich
IEEE Symposium on Security and Privacy6
2012 STEALTHMEM: System-Level Protection Against Cache-Based Side Channel Attacks in the Cloud
Taesoo Kim, Marcus Peinado, Gloria Mainar-Ruiz
USENIX Security Symposium3
2012 Fay: Extensible Distributed Tracing from Kernels to Clusters
abstract
Fay is a flexible platform for the efficient collection, processing, and analysis of software execution traces. Fay provides dynamic tracing through use of runtime instrumentation and distributed aggregation within machines and across clusters. At the lowest level, Fay can be safely extended with new tracing primitives, including even untrusted, fully optimized machine code, and Fay can be applied to running user-mode or kernel-mode software without compromising system stability. At the highest level, Fay provides a unified, declarative means of specifying what events to trace, as well as the aggregation, processing, and analysis of those events. We have implemented the Fay tracing platform for Windows and integrated it with two powerful, expressive systems for distributed programming. Our implementation is easy to use, can be applied to unmodified production systems, and provides primitives that allow the overhead of tracing to be greatly reduced, compared to previous dynamic tracing platforms. To show the generality of Fay tracing, we reimplement, in experiments, a range of tracing strategies and several custom mechanisms from existing tracing frameworks. Fay shows that modern techniques for high-level querying and data-parallel processing of disagreggated data streams are well suited to comprehensive monitoring of software execution in distributed systems. Revisiting a lesson from the late 1960s [Deutsch and Grant 1971], Fay also demonstrates the efficiency and extensibility benefits of using safe, statically verified machine code as the basis for low-level execution tracing. Finally, Fay establishes that, by automatically deriving optimized query plans and code for safe extensions, the expressiveness and performance of high-level tracing queries can equal or even surpass that of specialized monitoring tools.
Úlfar Erlingsson, Marcus Peinado, Simon Peter 0001, Mihai Budiu, Gloria Mainar-Ruiz
ACM Trans. Comput. Syst.5