Dan Williams 0001

dblp:96/2005 · also Dan John Williams · DBLP profile ↗
← Back
31ranked-venue papers
8as first author
12since 2021 · last 2025
0000-0003-1537-0525ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 18 · 5 first-author · 7 since 2021Software engineering, systems software and programming languages · 9 · 1 first-author · 4 since 2021Security and privacy · 3 · 3 since 2021Computer networks · 2 · 1 first-author
YearPublicationVenuePosition
2025 Extending Applications Safely and Efficiently
Yusheng Zheng, Yiwei Yang 0002, Yanpeng Hu, Xiaozheng Lai, Dan Williams 0001, Andi Quinn
OSDI6
2025 Rex: Closing the language-verifier gap with safe and usable kernel extensions
Jinghao Jia, Ruowen Qin, Milo Craun, Egor Lukiyanov, Ayush Bansal, Minh Phan, Michael V. Le, Hubertus Franke, Hani Jamjoom, Tianyin Xu, Dan Williams 0001
USENIX ATC11
2024 SEVeriFast: Minimizing the root of trust for fast startup of SEV microVMs
abstract
Serverless computing platforms rely on fast container initialization to provide low latency and high throughput for requests. While hardware enforced trusted execution environments (TEEs) have gained popularity, confidential computing has yet to be widely adopted by latency-sensitive platforms due to its additional initialization overhead. We investigate the application of AMD's Secure Encrypted Virtualization (SEV) to microVMs and find that current startup times for confidential VMs are prohibitively slow due to the high cost of establishing a root of trust for each new VM.
Benjamin Holmes 0002, Jason Waterman, Dan Williams 0001
ASPLOS (2)3
2024 Fast (Trapless) Kernel Probes Everywhere
Jinghao Jia, Michael V. Le, Salman Ahmed 0001, Dan Williams 0001, Hani Jamjoom, Tianyin Xu
USENIX ATC4
2024 SeaK: Rethinking the Design of a Secure Allocator for OS Kernel
Zicheng Wang 0010, Yicheng Guang, Yueqi Chen 0001, Zhenpeng Lin, Michael V. Le, Dang K. Le, Dan Williams 0001, Xinyu Xing 0001, Zhongshu Gu, Hani Jamjoom
USENIX Security Symposium7
2024 Introduction to the Special Section on USENIX ATC 2023
abstract
Published version
Dan Williams 0001, Julia Lawall
ACM Trans. Storage1
2023 Securing Container-based Clouds with Syscall-aware Scheduling
abstract
Container-based clouds—in which containers are the basic unit of isolation—face security concerns because, unlike Virtual Machines, containers directly interface with the underlying highly privileged kernel through the wide and vulnerable system call interface. Regardless of whether a container itself requires dangerous system calls, a compromised or malicious container sharing the host (a bad neighbor) can compromise the host kernel using a vulnerable syscall, thereby compromising all other containers sharing the host.
Michael V. Le, Salman Ahmed 0001, Dan Williams 0001, Hani Jamjoom
AsiaCCS3
2023 Protect the System Call, Protect (Most of) the World with BASTION
abstract
System calls are a critical building block in many serious security attacks, such as control-flow hijacking and privilege escalation attacks. Security-sensitive system calls (e.g., execve, mprotect), especially play a major role in completing attacks. Yet, few defense efforts focus to ensure their legitimate usage, allowing attackers to maliciously leverage system calls in attacks.
Christopher Jelesnianski, Mohannad Ismail, Yeongjin Jang, Dan Williams 0001, Changwoo Min
ASPLOS (3)4
2023 Kernel extension verification is untenable
abstract
The emergence of verified eBPF bytecode is ushering in a new era of safe kernel extensions. In this paper, we argue that eBPF's verifier---the source of its safety guarantees---has become a liability. In addition to the well-known bugs and vulnerabilities stemming from the complexity and ad hoc nature of the in-kernel verifier, we highlight a concerning trend in which escape hatches to unsafe kernel functions (in the form of helper functions) are being introduced to bypass verifier-imposed limitations on expressiveness, unfortunately also bypassing its safety guarantees. We propose safe kernel extension frameworks using a balance of not just static but also lightweight runtime techniques. We describe a design centered around kernel extensions in safe Rust that will eliminate the need of the in-kernel verifier, improve expressiveness, allow for reduced escape hatches, and ultimately improve the safety of kernel extensions.
Jinghao Jia, Raj Sahu, Adam Oswald, Dan Williams 0001, Michael V. Le, Tianyin Xu
HotOS4
2022 SecQuant: Quantifying Container System Call Exposure
Sunwoo Jang, Somin Song, Byung-Chul Tak, Sahil Suneja, Michael V. Le, Chuan Yue, Dan Williams 0001
ESORICS (2)7
2022 KASLR in the age of MicroVMs
abstract
Address space layout randomization (ASLR) is a widely used component of computer security aimed at preventing code reuse and/or data-only attacks. Modern kernels utilize kernel ASLR (KASLR) and finer-grained forms, such as functional granular KASLR (FGKASLR), but do so as part of an inefficient bootstrapping process we call bootstrap self-randomization. Meanwhile, under increasing pressure to optimize their boot times, microVM architectures such as AWS Firecracker have resorted to eliminating bootstrapping steps, particularly decompression and relocation from the guest kernel boot process, leaving them without KASLR. In this paper, we present in-monitor KASLR, in which the virtual machine monitor efficiently implements KASLR for the guest kernel by skipping the expensive kernel self-relocation steps. We prototype in-monitor KASLR and FGKASLR in the open-source Firecracker virtual machine monitor demonstrating, on a microVM configured kernel, boot times 22% and 16% faster than bootstrapped KASLR and FGKASLR methods, respectively. We also show the low overhead of in-monitor KASLR, with only 4% (2 ms) increase in boot times on average compared to a kernel without KASLR. We also discuss the implications and future opportunities for in-monitor approaches.
Benjamin Holmes 0002, Jason Waterman, Dan Williams 0001
EuroSys3
2022 Verified programs can party: optimizing kernel extensions via post-verification merging
abstract
Operating system (OS) extensions are more popular than ever. For example, Linux BPF is marketed as a "superpower" that allows user programs to be downloaded into the kernel, verified to be safe and executed at kernel hook points. So, BPF extensions have high performance and are often placed at performance-critical paths for tracing and filtering.
Hsuan-Chi Kuo, Kai-Hsun Chen, Yicheng Lu, Dan Williams 0001, Sibin Mohan, Tianyin Xu
EuroSys4
2020 A Linux in unikernel clothing
abstract
Unikernels leverage library OS architectures to run isolated workloads on the cloud. They have garnered attention in part due to their promised performance characteristics such as small image size, fast boot time, low memory footprint and application performance. However, those that aimed at generality fall short of the application compatibility, robustness and, more importantly, community that is available for Linux. In this paper, we describe and evaluate Lupine Linux, a standard Linux system that---through kernel configuration specialization and system call overhead elimination---achieves unikernel-like performance, in fact outperforming at least one reference unikernel in all of the above dimensions. At the same time, Lupine can run any application (since it is Linux) when faced with more general workloads, whereas many unikernels simply crash. We demonstrate a graceful degradation of unikernel-like performance properties.
Hsuan-Chi Kuo, Dan Williams 0001, Ricardo Koller, Sibin Mohan
EuroSys2
2019 An Ounce of Prevention is Worth a Pound of Cure: Ahead-of-time Preparation for Safe High-level Container Interfaces
Ricardo Koller, Dan Williams 0001
HotStorage2
2018 Unikernels as Processes
abstract
System virtualization (e.g., the virtual machine abstraction) has been established as the de facto standard form of isolation in multi-tenant clouds. More recently, unikernels have emerged as a way to reuse VM isolation while also being lightweight by eliminating the general purpose OS (e.g., Linux) from the VM. Instead, unikernels directly run the application (linked with a library OS) on the virtual hardware. In this paper, we show that unikernels do not actually require a virtual hardware abstraction, but can achieve similar levels of isolation when running as processes by leveraging existing kernel system call whitelisting mechanisms. Moreover, we show that running unikernels as processes reduces hardware requirements, enables the use of standard process debugging and management tooling, and improves the already impressive performance that unikernels exhibit.
Dan Williams 0001, Ricardo Koller, Martin Lucina, Nikhil Prakash
SoCC1
2017 Will Serverless End the Dominance of Linux in the Cloud?
abstract
From the inception of the cloud, running multi-tenant workloads has put strain on the Linux kernel's abstractions. After years of having its abstractions bypassed via virtualization, the kernel has responded with a native container abstraction that is eagerly being applied in the cloud. In this paper, we point out that history is repeating itself: with the introduction of serverless computing, even the native container abstraction is ill-suited. We show that bypassing the kernel with unikernels can yield at least a factor of 6 better latency and throughput. Facing a more complex kernel than ever and a relatively undemanding computing model, we must revisit the question of whether the kernel should try to adapt, we should continue bypassing the kernel, or if it is finally time to try a new native OS for this important future cloud workload.
Ricardo Koller, Dan Williams 0001
HotOS2
2017 Multi-Hypervisor Virtual Machines: Enabling an Ecosystem of Hypervisor-level Services
Kartik Gopalan, Rohith Kugve, Hardik Bagdi, Yaohui Hu, Dan Williams 0001, Nilton Bila
USENIX ATC5
2016 Version Traveler: Fast and Memory-Efficient Version Switching in Graph Processing Systems
Xiaoen Ju, Dan Williams 0001, Hani Jamjoom, Kang G. Shin
USENIX ATC2
2016 Enabling Efficient Hypervisor-as-a-Service Clouds with Eemeral Virtualization
abstract
When considering a hypervisor, cloud providers must balance conflicting requirements for simple, secure code bases with more complex, feature-filled offerings. This paper introduces Dichotomy, a new two-layer cloud architecture in which the roles of the hypervisor are split. The cloud provider runs a lean hyperplexor that has the sole task of multiplexing hardware and running more substantial hypervisors (called featurevisors) that implement features. Cloud users choose featurevisors from a selection of lightly-modified hypervisors potentially offered by third-parties in an "as-a-service" model for each VM. Rather than running the featurevisor directly on the hyperplexor using nested virtualization, Dichotomy uses a new virtualization technique called eemeral virtualization which efficiently (and repeatedly) transfers control of a VM between the hyperplexor and featurevisor using memory mapping techniques. Nesting overhead is only incurred when the VM is accessed by the featurevisor. We have implemented Dichotomy in KVM/QEMU and demonstrate average switching times of 80 ms, two to three orders of magnitude faster than live VM migration. We show that, for the featurevisor applications we evaluated, VMs hosted in Dichotomy deliver up to 12% better performance than those hosted on nested hypervisors, and continue to show benefit even when the featurevisor applications run as often as every 2.5~seconds.
Dan Williams 0001, Yaohui Hu, Umesh Deshpande, Piush K. Sinha, Nilton Bila, Kartik Gopalan, Hani Jamjoom
VEE1
2015 Flux: multi-surface computing in Android
abstract
With the continued proliferation of mobile devices, apps will increasingly become multi-surface, running seamlessly across multiple user devices (e.g., phone, tablet, etc.). Yet general systems support for multi-surface app is limited to (1) screencasting, which relies on a single master device's computing power and battery life or (2) cloud backing, which is unsuitable in the face of disconnected operation or untrusted cloud providers. We present an alternative approach: Flux, an Android-based system that enables any app to become multi-surface through app migration. Flux overcomes device heterogeneity and residual dependencies through two key mechanisms. Selective Record/Adaptive Replay records just those device-agnostic app calls that lead to the generation of app-specific device-dependent state in system services and replays them on the target. Checkpoint/Restore in Android (CRIA) transitions an app into a state in which device-specific information can be safely discarded before checkpointing and restoring the app. Our implementation of Flux can migrate many popular, unmodified Android apps---including those with extensive device interactions like 3D accelerated graphics---across heterogeneous devices and is fast enough for interactive use.
Alexander Van't Hof, Hani Jamjoom, Jason Nieh, Dan Williams 0001
EuroSys4
2014 TideWatch: Fingerprinting the cyclicality of big data workloads
abstract
Intrinsic to “big data” processing workloads (e.g., iterative MapReduce, Pregel, etc.) are cyclical resource utilization patterns that are highly synchronized across different resource types as well as the workers in a cluster. In Infrastructure as a Service settings, cloud providers do not exploit this characteristic to better manage VMs because they view VMs as “black boxes.” We present TideWatch, a system that automatically identifies cyclicality and similarity in running VMs. TideWatch predicts period lengths of most VMs in Hadoop workloads within 9% of actual iteration boundaries and successfully classifies up to 95% of running VMs as participating in the appropriate Hadoop cluster. Furthermore, we show how TideWatch can be used to improve the timing of VM migrations, reducing both migration time and network impact by over 50% when compared to a random approach.
Dan Williams 0001, Shuai Zheng 0002, Xiangliang Zhang 0001, Hani Jamjoom
INFOCOM1
2013 Pico replication: a high availability framework for middleboxes
abstract
Middleboxes are being rearchitected to be service oriented, composable, extensible, and elastic. Yet system-level support for high availability (HA) continues to introduce significant performance overhead. In this paper, we propose Pico Replication (PR), a system-level framework for middleboxes that exploits their flow-centric structure to achieve low overhead, fully customizable HA. Unlike generic (virtual machine level) techniques, PR operates at the flow level. Individual flows can be checkpointed at very high frequencies while the middlebox continues to process other flows. Furthermore, each flow can have its own checkpoint frequency, output buffer and target for backup, enabling rich and diverse policies that balance---per-flow---performance and utilization. PR leverages OpenFlow to provide near instant flow-level failure recovery, by dynamically rerouting a flow's packets to its replication target. We have implemented PR and a flow-based HA policy. In controlled experiments, PR sustains checkpoint frequencies of 1000Hz, an order of magnitude improvement over current VM replication solutions. As a result, PR drastically reduces the overhead on end-to-end latency from 280% to 15.5% and throughput overhead from 99.5% to 3.2%.
Shriram Rajagopalan, Dan Williams 0001, Hani Jamjoom
SoCC2
2013 Mizan: a system for dynamic load balancing in large-scale graph processing
abstract
Pregel [23] was recently introduced as a scalable graph mining system that can provide significant performance improvements over traditional MapReduce implementations. Existing implementations focus primarily on graph partitioning as a preprocessing step to balance computation across compute nodes. In this paper, we examine the runtime characteristics of a Pregel system. We show that graph partitioning alone is insufficient for minimizing end-to-end computation. Especially where data is very large or the runtime behavior of the algorithm is unknown, an adaptive approach is needed. To this end, we introduce Mizan, a Pregel system that achieves efficient load balancing to better adapt to changes in computing needs. Unlike known implementations of Pregel, Mizan does not assume any a priori knowledge of the structure of the graph or behavior of the algorithm. Instead, it monitors the runtime characteristics of the system. Mizan then performs efficient fine-grained vertex migration to balance computation and communication. We have fully implemented Mizan; using extensive evaluation we show that---especially for highly-dynamic workloads---Mizan provides up to 84% improvement over techniques leveraging static graph pre-partitioning.
Zuhair Khayyat, Karim Awara, Amani AlOnazi, Hani Jamjoom, Dan Williams 0001, Panos Kalnis
EuroSys5
2013 Escape Capsule: Explicit State Is Robust and Scalable
Shriram Rajagopalan, Dan Williams 0001, Hani Jamjoom, Andy Warfield
HotOS2
2013 Split/Merge: System Support for Elastic Execution in Virtual Middleboxes
Shriram Rajagopalan, Dan Williams 0001, Hani Jamjoom, Andy Warfield
NSDI2
2012 The Xen-Blanket: virtualize once, run everywhere
abstract
Current Infrastructure as a Service (IaaS) clouds operate in isolation from each other. Slight variations in the virtual machine (VM) abstractions or underlying hypervisor services prevent unified access and control across clouds. While standardization efforts aim to address these issues, they will take years to be agreed upon and adopted, if ever. Instead of standardization, which is by definition provider-centric, we advocate a user-centric approach that gives users an unprecedented level of control over the virtualization layer. We introduce the Xen-Blanket, a thin, immediately deployable virtualization layer that can homogenize today's diverse cloud infrastructures. We have deployed the Xen-Blanket across Amazon's EC2, an enterprise cloud, and a private setup at Cornell University. We show that a user-centric approach to homogenize clouds can achieve similar performance to a paravirtualized environment while enabling previously impossible tasks like cross-provider live migration. The Xen-Blanket also allows users to exploit resource management opportunities like oversubscription, and ultimately can reduce costs for users.
Dan Williams 0001, Hani Jamjoom, Hakim Weatherspoon
EuroSys1
2011 Logical attestation: an authorization architecture for trustworthy computing
abstract
This paper describes the design and implementation of a new operating system authorization architecture to support trustworthy computing. Called logical attestation, this architecture provides a sound framework for reasoning about run time behavior of applications. Logical attestation is based on attributable, unforgeable statements about program properties, expressed in a logic. These statements are suitable for mechanical processing, proof construction, and verification; they can serve as credentials, support authorization based on expressive authorization policies, and enable remote principals to trust software components without restricting the local user's choice of binary implementations.
Emin Gün Sirer, Willem de Bruijn, Patrick Reynolds, Alan Shieh, Kevin Walsh 0001, Dan Williams 0001, Fred B. Schneider
SOSP6
2011 Overdriver: handling memory overload in an oversubscribed cloud
abstract
With the intense competition between cloud providers, oversubscription is increasingly important to maintain profitability. Oversubscribing physical resources is not without consequences: it increases the likelihood of overload. Memory overload is particularly damaging. Contrary to traditional views, we analyze current data center logs and realistic Web workloads to show that overload is largely transient: up to 88.1% of overloads last for less than 2 minutes. Regarding overload as a continuum that includes both transient and sustained overloads of various durations points us to consider mitigation approaches also as a continuum, complete with tradeoffs with respect to application performance and data center overhead. In particular, heavyweight techniques, like VM migration, are better suited to sustained overloads, whereas lightweight approaches, like network memory, are better suited to transient overloads. We present Overdriver, a system that adaptively takes advantage of these tradeoffs, mitigating all overloads within 8% of well-provisioned performance. Furthermore, under reasonable oversubscription ratios, where transient overload constitutes the vast majority of overloads, Overdriver requires 15% of the excess space and generates a factor of four less network traffic than a migration-only approach.
Dan Williams 0001, Hani Jamjoom, Yew-Huey Liu, Hakim Weatherspoon
VEE1
2008 Device Driver Safety Through a Reference Validation Mechanism
Dan Williams 0001, Patrick Reynolds, Kevin Walsh 0001, Emin Gün Sirer, Fred B. Schneider
OSDI1
2005 Nexus: a new operating system for trustworthy computing
abstract
Tamper-proof coprocessors for secure computing are poised to become a standard hardware feature on future computers. Such hardware provides the primitives necessary to support trustworthy computing applications, that is, applications that can provide strong guarantees about their run time behavior.
Alan Shieh, Dan Williams 0001, Emin Gün Sirer, Fred B. Schneider
SOSP2
2004 Optimal Parameter Selection for Efficient Memory Integrity Verification Using Merkle Hash Trees
abstract
A secure, tamperproof execution environment is critical for trustworthy network computing. Newly emerging hardware, such as those developed as part of the TCPA and Palladium initiatives, enables operating systems to implement such an environment through Merkle hash trees. We examine the selection of optimal parameters, namely blocksize and tree depth, for Merkle hash trees based on the size of the memory region to be protected and the number of memory updates between updates of the hash tree. We analytically derive an expression for the cost of updating the hash tree, show that there is an optimal blocksize for the leaves of a Merkle tree for a given file size and update interval that minimizes the cost of update operations, and describe a general method by which the parameters of such a tree can be determined optimally.
Dan Williams 0001, Emin Gün Sirer
NCA1