Landon P. Cox

dblp:98/5314 · DBLP profile ↗
← Back
31ranked-venue papers
7as first author
1since 2021 · last 2022
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 17 · 1 first-authorSystems, architecture and hardware · 6 · 3 first-author · 1 since 2021Software engineering, systems software and programming languages · 5 · 2 first-authorSecurity and privacy · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
15 papers
Systems and software security · 32% Web and mobile security · 32% Privacy and data protection · 26%
Computer networks
7 papers
Content delivery and video streaming · 33% Edge and fog computing · 27% Wireless networking · 20%
Software engineering, system software, and programming languages
3 papers
Operating systems · 100%
Computer architecture, parallel and distributed computing, and storage systems
7 papers
Storage systems · 37% Distributed systems · 18% Cloud and datacenter computing · 18%
Human-computer interaction and pervasive computing
5 papers
Ubiquitous computing and smart environments · 63% Interaction techniques and input · 21% Wearable and physiological sensing · 16%

Topics — the 30 heaviest of 62, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Web and mobile security
mobile security
0.732019
Permissions Plugins as Android Apps · MobiSys 2019
SpanDex: Secure Password Tracking for Android · USENIX Security Symposium 2014
TaintDroid: An Information-Flow Tracking System for Realtime Privacy Monitoring on Smartphones · OSDI 2010
Privacy and data protection › image privacy
camera privacy
0.522017
CamForensics: Understanding Visual Privacy Leaks in the Wild · SenSys 2017
What You Mark is What Apps See · MobiSys 2016
Content delivery and video streaming › interactive video streaming
cloud gaming
0.422015
Kahawai: High-Quality Mobile Gaming Using GPU Offload · MobiSys 2015
Demo: Kahawai: high-quality mobile gaming using GPU offload · MobiSys 2014
Edge and fog computing › video analytics
edge video analytics
0.412019
Video Analytics - Killer App for Edge Computing · MobiSys 2019
Web and mobile security › mobile application security
android permissions
0.412019
Permissions Plugins as Android Apps · MobiSys 2019
Operating systems
mobile systems
0.412019
Permissions Plugins as Android Apps · MobiSys 2019
Operating systems › system security › operating system security › protection mechanism › isolation
process isolation
0.412019
Permissions Plugins as Android Apps · MobiSys 2019
Systems and software security › information flow tracking
dynamic information flow tracking
0.312018
SandTrap: Tracking Information Flows On Demand with Parallel Permissions · MobiSys 2018
Operating systems › resource management › memory management
memory protection
0.312018
SandTrap: Tracking Information Flows On Demand with Parallel Permissions · MobiSys 2018
Systems and software security
information flow tracking
0.322014
TaintDroid: An Information-Flow Tracking System for Realtime Privacy Monitoring on Smartphones · ACM Trans. Comput. Syst. 2014
TaintDroid: An Information-Flow Tracking System for Realtime Privacy Monitoring on Smartphones · OSDI 2010
Privacy and data protection
image privacy
0.322016
Demo: Protecting visual secrets with privateeye · MobiSys 2014
What You Mark is What Apps See · MobiSys 2016
Wireless networking
WLAN
0.222011
Spider: improving mobile networking with concurrent wi-fi connections · SIGCOMM 2011
Concurrent Wi-Fi for mobile users: analysis and measurements · CoNEXT 2011
Systems and software security › software vulnerability
cryptographic API misuse
0.212014
Demo: Zero interaction private messaging with ZIPR · MobiSys 2014
Systems and software security › information flow tracking
dynamic taint analysis
0.212014
TaintDroid: An Information-Flow Tracking System for Realtime Privacy Monitoring on Smartphones · ACM Trans. Comput. Syst. 2014
Web and mobile security
mobile application security
0.212014
Demo: Zero interaction private messaging with ZIPR · MobiSys 2014
Cryptographic primitives and cryptanalysis
symmetric cryptography
0.212014
Demo: Zero interaction private messaging with ZIPR · MobiSys 2014
Systems and software security
operating system security
0.212013
ScreenPass: secure password entry on touchscreen devices · MobiSys 2013
Systems and software security › information flow tracking
taint analysis
0.212013
ScreenPass: secure password entry on touchscreen devices · MobiSys 2013
Hardware security and side channels
trusted execution environments
0.112011
YouProve: authenticity and fidelity in mobile sensing · SenSys 2011
Computer vision › Video understanding and tracking
video analytics
0.112019
Video Analytics - Killer App for Edge Computing · MobiSys 2019
Cloud and datacenter computing
computation offloading
0.112019
Video Analytics - Killer App for Edge Computing · MobiSys 2019
Processor architecture and microarchitecture › multithreading
multithreaded execution
0.112018
SandTrap: Tracking Information Flows On Demand with Parallel Permissions · MobiSys 2018
Wireless sensing and localization › localization algorithms
energy-efficient localization
0.112009
EnLoc: Energy-Efficient Localization for Mobile Phones · INFOCOM 2009
Wireless sensing and localization › smartphone sensing
smartphone-based localization
0.112009
EnLoc: Energy-Efficient Localization for Mobile Phones · INFOCOM 2009
Authentication and access control
anonymous credentials
0.112009
SMILE: encounter-based trust for mobile social services · CCS 2009
Privacy and data protection
location privacy
0.112009
SMILE: encounter-based trust for mobile social services · CCS 2009
Ubiquitous computing and smart environments › mobile computing
mobile media sharing
0.112008
Micro-Blog: sharing and querying content through mobile phones and social participation · MobiSys 2008
Ubiquitous computing and smart environments › mobile crowdsourcing
participatory sensing
0.112008
Micro-Blog: sharing and querying content through mobile phones and social participation · MobiSys 2008
Interaction techniques and input › sensor-based interaction
camera-based interaction
0.112016
What You Mark is What Apps See · MobiSys 2016
Systems and software security
information flow control
0.112007
TightLip: Keeping Applications from Spilling the Beans · NSDI 2007

Methods — techniques the papers use, named apart from their topics

computer vision · 1.1parallel permissions · 1.0binary instrumentation · 1.0process isolation · 0.8permission plugins · 0.8region marking · 0.53d object marking · 0.5dynamic taint analysis · 0.3user survey · 0.3computer vision analysis · 0.3dynamic taint tracking · 0.2people-centric sensing · 0.2mobile phone sensing · 0.2trusted analysis · 0.1photo and audio analysis · 0.1outdoor measurement · 0.1optimization · 0.1concurrent wi-fi connections · 0.1
YearPublicationVenuePosition
2022 BumbleBee: Application-aware adaptation for edge-cloud orchestration
abstract
Modern developers rely on container-orchestration frameworks like Kubernetes to deploy and manage hybrid workloads that span the edge and cloud. When network conditions between the edge and cloud change unexpectedly, a workload must adapt its internal behavior. Unfortunately, container-orchestration frameworks do not offer an easy way to express, deploy, and manage adaptation strategies. As a result, fine-tuning or modifying a workload's adaptive behavior can require modifying containers built from large, complex codebases that may be maintained by separate development teams. This paper presents BumbleBee, a lightweight extension for container-orchestration frameworks that separates the concerns of application logic and adaptation logic. BumbleBee provides a simple in-network programming abstraction for making decisions about network data using application semantics. Experiments with a BumbleBee prototype show that edge ML-workloads can adapt to network variability and survive disconnections, edge stream-processing workloads can improve benchmark results between 37.8% and$\boldsymbol{23\mathrm{x}}$, and HLS video-streaming can reduce stalled playback by 77%.
Shadi A. Noghabi, Brian D. Noble, Matthew Furlong, Landon P. Cox
SEC5
2020 LevelUp: A thin-cloud approach to game livestreaming
abstract
Game livestreaming is hugely popular and growing. Each month, Twitch hosts over two million unique broadcasters with a collective audience of 140 million unique viewers. Despite its success, livestreaming services are costly to run. AWS and Azure both charge hundreds of dollars to encode 100 hours of multi-bitrate video, and potentially thousands each month to transfer the video data of one gamer to a relatively small audience.In this work, we demonstrate that mobile edge devices are ready to play a more central role in multi-bitrate livestreaming. In particular, we explore a new strategy for game livestreaming that we call a thin-cloud approach. Under a thin-cloud approach, livestreaming services rely on commodity web infrastructure to store and distribute video content and leverage hardware acceleration on edge devices to transcode video and boost the video quality of low-bitrate streams. We have built a prototype system called LevelUp that embodies the thin-cloud approach, and using our prototype we demonstrate that mobile hardware acceleration can support real-time video transcoding and significantly boost the quality of low-bitrate video through a machine-learning technique called super resolution. We show that super-resolution can improve the visual quality of low-resolution game streams by up to 88% while requiring approximately half the bandwidth of higher-bitrate streams. Finally, energy experiments show that LevelUp clients consume only 5% of their battery capacity watching 30 minutes of video.
Landon P. Cox, Lixiang Ao
SEC1
2019 Video Analytics - Killer App for Edge Computing
abstract
The world is witnessing an unprecedented increase in camera deployment. The USA and UK, for instance, have one camera for every 8 people. Video analytics from these cameras are becoming more and more pervasive, exerting important functions on a wide range of verticals including manufacturing, transportation, and retails. While vision techniques have seen considerable advancement, they have come at the expense of compute and network cost.
Ganesh Ananthanarayanan, Paramvir Bahl, Landon P. Cox, Alex Crown, Shadi A. Noghabi, Yuanchao Shu
MobiSys3
2019 Permissions Plugins as Android Apps
abstract
The permissions framework for Android is frustratingly inflexible. Once granted a permission, Android will always allow an app to access the resource until the user manually revokes the app's permission. Prior work has proposed extensible plugin frameworks, but they have struggled to support flexible authorization and isolate apps and plugins from each other. In this paper, we propose DALF, a framework for extensible permissions plugins that provides both flexibility and isolation. The insight underlying DALF is that permissions plugins should be treated as apps themselves. This approach allows plugins to maintain state and access system resources such as a device's location while being restricted by Android's process-isolation mechanisms. Experiments with microbenchmarks and case studies with real third-party apps show promising results: plugins are easy to develop and impose acceptable overhead for most resources.
Nisarg Raval, Ali Razeen, Ashwin Machanavajjhala, Landon P. Cox, Andy Warfield
MobiSys4
2018 SandTrap: Tracking Information Flows On Demand with Parallel Permissions
abstract
The most promising way to improve the performance of dynamic information-flow tracking (DIFT) for machine code is to only track instructions when they process tainted data. Unfortunately, prior approaches to on-demand DIFT are a poor match for modern mobile platforms that rely heavily on parallelism to provide good interactivity in the face of computationally intensive tasks like image processing. The main shortcoming of these prior efforts is that they cannot support an arbitrary mix of parallel threads due to the limitations of page protections.
Ali Razeen, Alvin R. Lebeck, David H. Liu, Alexander Meijer, Valentin Pistol, Landon P. Cox
MobiSys6
2017 CamForensics: Understanding Visual Privacy Leaks in the Wild
abstract
Many mobile apps, including augmented-reality games, bar-code readers, and document scanners, digitize information from the physical world by applying computer-vision algorithms to live camera data. However, because camera permissions for existing mobile operating systems are coarse (i.e., an app may access a camera's entire view or none of it), users are vulnerable to visual privacy leaks. An app violates visual privacy if it extracts information from camera data in unexpected ways. For example, a user might be surprised to find that an augmented-reality makeup app extracts text from the camera's view in addition to detecting faces. This paper presents results from the first large-scale study of visual privacy leaks in the wild. We build CamForensics to identify the kind of information that apps extract from camera data. Our extensive user surveys determine what kind of information users expected an app to extract. Finally, our results show that camera apps frequently defy users' expectations based on their descriptions.
Animesh Srivastava, Puneet Jain, Soteris Demetriou, Landon P. Cox, Kyu-Han Kim
SenSys4
2016 What You Mark is What Apps See
abstract
Users are increasingly vulnerable to inadvertently leaking sensitive information through cameras. In this paper, we investigate an approach to mitigating the risk of such inadvertent leaks called privacy markers. Privacy markers give users fine-grained control of what visual information an app can access through a device's camera. We present two examples of this approach: PrivateEye, which allows a user to mark regions of a two-dimensional surface as safe to release to an app, and WaveOff, which does the same for three-dimensional objects. We have integrated both systems with Android's camera subsystem. Experiments with our prototype show that a Nexus 5 smartphone can deliver near realtime frame rates while protecting secret information, and a 26-person user study elicited positive feedback on our prototype's speed and ease-of-use.
Nisarg Raval, Animesh Srivastava, Ali Razeen, Kiron Lebeck, Ashwin Machanavajjhala, Landon P. Cox
MobiSys6
2015 Kahawai: High-Quality Mobile Gaming Using GPU Offload
abstract
This paper presents Kahawai1, a system that provides high-quality gaming on mobile devices, such as tablets and smartphones, by offloading a portion of the GPU computation to server-side infrastructure. In contrast with previous thin-client approaches that require a server-side GPU to render the entire content, Kahawai uses collaborative rendering to combine the output of a mobile GPU and a server-side GPU into the displayed output. Compared to a thin client, collaborative rendering requires significantly less network bandwidth between the mobile device and the server to achieve the same visual quality and, unlike a thin client, collaborative rendering supports disconnected operation, allowing a user to play offline - albeit with reduced visual quality.
Eduardo Cuervo Laffaye, Alec Wolman, Landon P. Cox, Kiron Lebeck, Ali Razeen, Stefan Saroiu, Madan Musuvathi
MobiSys3
2014 Demo: Kahawai: high-quality mobile gaming using GPU offload
abstract
No abstract available.
Eduardo Cuervo Laffaye, Alec Wolman, Landon P. Cox, Stefan Saroiu, Madan Musuvathi, Ali Razeen
MobiSys3
2014 Demo: Zero interaction private messaging with ZIPR
abstract
Messaging app developers are beginning to take the security and privacy of their users' communication more seriously. Unfortunately, a recent study has shown that the developers of many popular apps incorrectly use cryptography. As a result, they make mistakes that may result in trivially broken encryption schemes. For example, the developers of Snapchat use a constant symmetric encryption key hardcoded into the app and it only takes 12 lines of Ruby to crack the encryption.
Ali Razeen, Landon P. Cox
MobiSys2
2014 Demo: Protecting visual secrets with privateeye
abstract
Consider the following scenario from the not-too-distant future: the CEO of a company is presenting his vision for the next quarter to a small group of co-workers. The CEO trusts everyone in the room, but many in attendance have smartphones and camera-equipped wearable computing devices running third-party apps. The CEO is worried that this third-party software could leak the highly confidential information in his slides and on the whiteboard. This raises the question: how can the CEO prevent apps with camera access from leaking company secrets?
Animesh Srivastava, Landon P. Cox
MobiSys2
2014 SpanDex: Secure Password Tracking for Android
Landon P. Cox, Peter Gilbert, Geoffrey Lawler, Valentin Pistol, Ali Razeen, Sai Cheemalapati
USENIX Security Symposium1
2014 TaintDroid: An Information-Flow Tracking System for Realtime Privacy Monitoring on Smartphones
abstract
Today’s smartphone operating systems frequently fail to provide users with visibility into how third-party applications collect and share their private data. We address these shortcomings with TaintDroid, an efficient, system-wide dynamic taint tracking and analysis system capable of simultaneously tracking multiple sources of sensitive data. TaintDroid enables realtime analysis by leveraging Android’s virtualized execution environment. TaintDroid incurs only 32% performance overhead on a CPU-bound microbenchmark and imposes negligible overhead on interactive third-party applications. Using TaintDroid to monitor the behavior of 30 popular third-party Android applications, in our 2010 study we found 20 applications potentially misused users’ private information; so did a similar fraction of the tested applications in our 2012 study. Monitoring the flow of privacy-sensitive data with TaintDroid provides valuable input for smartphone users and security service firms seeking to identify misbehaving applications.
William Enck, Peter Gilbert, Seungyeop Han, Vasant Tendulkar, Byung-Gon Chun, Landon P. Cox, Jaeyeon Jung, Patrick D. McDaniel, Anmol N. Sheth
ACM Trans. Comput. Syst.6
2013 ScreenPass: secure password entry on touchscreen devices
abstract
Users routinely access cloud services through third-party apps on smartphones by giving apps login credentials (i.e., a username and password). Unfortunately, users have no assurance that their apps will properly handle this sensitive information. In this paper, we describe the design and implementation of ScreenPass, which significantly improves the security of passwords on touchscreen devices. ScreenPass secures passwords by ensuring that they are entered securely, and uses taint-tracking to monitor where apps send password data. The primary technical challenge addressed by ScreenPass is guaranteeing that trusted code is always aware of when a user is entering a password. ScreenPass provides this guarantee through two techniques. First, ScreenPass includes a trusted software keyboard that encourages users to specify their passwords' domains as they are entered (i.e., to tag their passwords). Second, ScreenPass performs optical character recognition (OCR) on a device's screenbuffer to ensure that passwords are entered only through the trusted software keyboard. We have evaluated ScreenPass through experiments with a prototype implementation, two in-situ user studies, and a small app study. Our prototype detected a wide range of dynamic and static keyboard-spoofing attacks and generated zero false positives. As long as a screen is off, not updated, or not tapped, our prototype consumes zero additional energy; in the worst case, when a highly interactive app rapidly updates the screen, our prototype under a typical configuration introduces only 12% energy overhead. Participants in our user studies tagged their passwords at a high rate and reported that tagging imposed no additional burden. Finally, a study of malicious and non-malicious apps running under ScreenPass revealed several cases of password mishandling.
Dongtao Liu, Eduardo Cuervo Laffaye, Valentin Pistol, Ryan Scudellari, Landon P. Cox
MobiSys5
2011 Concurrent Wi-Fi for mobile users: analysis and measurements
abstract
We present the first in-depth analysis of the performance of attempting concurrent AP connections from highly mobile clients. Previous solutions for concurrent Wi-Fi are limited to stationary wireless clients and do not take into account a myriad of mobile factors. Through an analytical model, optimization framework, and numerous outdoor experiments, we show that connection duration, AP response times, channel scheduling, available and offered bandwidth, node speed, and dhcp joins all affect performance. Building on these results, we design, implement, and evaluate a system, Spider, that establishes and maintains concurrent connections to 802.11 APs in a mobile environment. The system uses multi-AP selection, channel-based scheduling, and opportunistic scanning to maximize throughput while mitigating the overhead of association and dhcp. While Spider can manage multiple channels, we empirically demonstrate that it achieves maximum throughput when using multiple APs on a single channel. Our evaluation shows that Spider provides a 400% improvement in throughput and 54% improvement in connectivity over stock Wi-Fi implementations.
Hamed Soroush, Peter Gilbert, Nilanjan Banerjee, Brian Neil Levine, Mark D. Corner, Landon P. Cox
CoNEXT6
2011 Confidant: Protecting OSN Data without Locking It Up
Dongtao Liu, Amre Shakimov, Ramón Cáceres, Alexander Varshavsky, Landon P. Cox
Middleware5
2011 YouProve: authenticity and fidelity in mobile sensing
abstract
As more services have come to rely on sensor data such as audio and photos collected by mobile phone users, verifying the authenticity of this data has become critical for service correctness. At the same time, clients require the flexibility to tradeoff the fidelity of the data they contribute for resource efficiency or privacy. This paper describes YouProve, a partnership between a mobile device's trusted hardware and software that allows untrusted client applications to directly control the fidelity of data they upload and services to verify that the meaning of source data is preserved. The key to our approach is trusted analysis of derived data, which generates statements comparing the content of a derived data item to its source. Experiments with a prototype implementation for Android demonstrate that YouProve is feasible. Our photo analyzer is over 99% accurate at identifying regions changed only through meaning-preserving modifications such as cropping, compression, and scaling. Our audio analyzer is similarly accurate at detecting which sub-clips of a source audio clip are present in a derived version, even in the face of compression, normalization, splicing, and other modifications. Finally, performance and power costs are reasonable, with analyzers having little noticeable effect on interactive applications and CPU-intensive analysis completing asynchronously in under 70 seconds for 5-minute audio clips and under 30 seconds for 5-megapixel photos.
Peter Gilbert, Jaeyeon Jung, Kyungmin Lee, Henry Qin, Daniel Sharkey, Anmol Sheth, Landon P. Cox
SenSys7
2011 Spider: improving mobile networking with concurrent wi-fi connections
abstract
We investigate attempting concurrent connections to multiple Wi-Fi access points (APs) from highly mobile clients. Previous multi-AP solutions are limited to stationary wireless clients and do not take into account a myriad of mobile factors. We show that connection duration, AP response times, channel scheduling, available and offered bandwidth, node speed, and dhcp joins all affect performance. Building on these results, we present a system, Spider, that establishes and maintains concurrent connections to 802.11 APs in a mobile environment. While Spider can manage multiple channels, we demonstrate that it achieves maximum throughput when using multiple APs on a single channel.
Hamed Soroush, Peter Gilbert, Nilanjan Banerjee, Mark D. Corner, Brian Neil Levine, Landon P. Cox
SIGCOMM6
2010 TaintDroid: An Information-Flow Tracking System for Realtime Privacy Monitoring on Smartphones
William Enck, Peter Gilbert, Byung-Gon Chun, Landon P. Cox, Jaeyeon Jung, Patrick D. McDaniel, Anmol Sheth
OSDI4
2009 SMILE: encounter-based trust for mobile social services
abstract
Conventional mobile social services such as Loopt and Google Latitude rely on two classes of trusted relationships: participants trust a centralized server to manage their location information and trust between users is based on existing social relationships. Unfortunately, these assumptions are not secure or general enough for many mobile social scenarios: centralized servers cannot always be relied upon to preserve data confidentiality, and users may want to use mobile social services to establish new relationships. To address these shortcomings, this paper describes SMILE, a privacy-preserving service in which the service provider is untrusted and users are not assumed to have pre-established social relationships with each other. At a high-level, SMILE uses short-range wireless communication and standard cryptographic primitives to mimic the behavior of users in existing missed-connections services such as Craigslist: trust is founded solely on anonymous users' ability to prove to each other that they shared an encounter in the past. We have evaluated SMILE using protocol analysis, an informal study of Craigslist usage, and experiments with a prototype implementation and found it to be both privacy-preserving and feasible.
Justin Manweiler, Ryan Scudellari, Landon P. Cox
CCS3
2009 EnLoc: Energy-Efficient Localization for Mobile Phones
abstract
A growing number of mobile phone applications utilize physical location to express the context of information. Most of these location-based applications assume GPS capabilities. Unfortunately, GPS incurs an unacceptable energy cost that can reduce the phone's battery life to less than nine hours. Alternate localization technologies, based on WiFi or GSM, improve battery life at the expense of localization accuracy. This paper quantifies this important tradeoff that underlies a range of emerging services. Driven by measurements from Nokia N95 phones, we develop an energy-efficient localization framework called EnLoc. The framework characterizes the optimal localization accuracy for a given energy budget, and develops prediction- based heuristics for real-time use. Evaluation on traces from real users demonstrates the possibility of achieving good localization accuracy for a realistic energy budget.
Ionut Constandache, Shravan Gaonkar, Matt Sayler, Romit Roy Choudhury, Landon P. Cox
INFOCOM5
2008 Micro-Blog: sharing and querying content through mobile phones and social participation
abstract
Recent years have witnessed the impacts of distributed content sharing (Wikipedia, Blogger), social networks (Facebook, MySpace), sensor networks, and pervasive computing. We believe that significant more impact is latent in the convergence of these ideas on the mobile phone platform. Phones can be envisioned as people-centric sensors capable of aggregating participatory as well as sensory inputs from local surroundings. The inputs can be visualized in different dimensions, such as space and time. When plugged into the Internet, the collaborative inputs from phones may enable a high resolution view of the world. This paper presents the architecture and implementation of one such system, called Micro-Blog. New kinds of application-driven challenges are identified and addressed in the context of this system. Implemented on Nokia N95 mobile phones, Micro-Blog was distributed to volunteers for real life use. Promising feedback suggests that Micro-Blog can be a deployable tool for sharing, browsing, and querying global information.
Shravan Gaonkar, Romit Roy Choudhury, Landon P. Cox, Al Schmidt
MobiSys4
2007 SmokeScreen: flexible privacy controls for presence-sharing
abstract
Presence-sharing is an emerging platform for mobile applications, but presence-privacy remains a challenge. Privacy controls must be flexible enough to allow sharing between both trusted social relations and untrusted strangers. In this paper, we present a system called SmokeScreen that provides flexible and power-efficient mechanisms for privacy management.Broadcasting clique signals, which can only be interpreted by other trusted users, enables sharing between social relations; broadcasting opaque identifiers (OIDs), which can only be resolved to an identity by a trusted broker, enables sharing between strangers. Computing these messages is power-efficient since they can be pre-computed with acceptable storage costs.In evaluating these mechanisms we first analyzed traces from an actual presence-sharing application. Four months of traces provide evidence of anonymous snooping, even among trusted users. We have also implemented our mechanisms on two devices and found the power demands of clique signals and OIDs to be reasonable. A mobile phone running our software can operate for several days on a single charge.
Landon P. Cox, Angela Dalton, Varun Marupadi
MobiSys1
2007 TightLip: Keeping Applications from Spilling the Beans
Aydan R. Yumerefendi, Benjamin Mickle, Landon P. Cox
NSDI3
2006 POS: A Practical Order Statistics Service forWireless Sensor Networks
abstract
We present the design and implementation of POS, an in-network service that computes accurate order statistics energy-efficiently. POS returns a stream of periodic samples from any order statistic. It initially computes the value of the order statistic and then periodically runs a validation protocol to determine whether the value is still valid. If not, it uses an optimized binary search to determine the new value and then resumes periodic validation. POS uses in-network aggregation and transmission suppression to reduce communication complexity. Results from both experiments on a mote testbed and simulations show that POS can compute order statistics accurately while consuming less energy than the best techniques to compute averages in common cases.
Landon P. Cox, Miguel Castro 0001, Antony I. T. Rowstron
ICDCS1
2005 LLSS: toward system support for plugging privacy leaks
abstract
Imagine that two users, Alice and Bob, have a conversation about a sensitive subject over email. Alice is vigilant about protecting the secrecy of the discussion and encrypts all copies of her sent and received emails. Bob, on the other hand, is well-meaning but negligent, and does not bother to encrypt any of his on-disk files. Worse, he unwittingly stores his email files in the portion of his hard drive that is shared with the rest of the Internet via a peer-to-peer client. One night, unbeknownst to either Alice or Bob, someone on the peer-to-peer network peruses Bob's shared space, finds his email files, and reads their private conversation. Despite Alice's best efforts and Bob's best intentions, the privacy of their discussion has leaked.
Aydan R. Yumerefendi, Landon P. Cox
SOSP2
2003 Samsara: honor among thieves in peer-to-peer storage
abstract
Peer-to-peer storage systems assume that their users consume resources in proportion to their contribution. Unfortunately, users are unlikely to do this without some enforcement mechanism. Prior solutions to this problem require centralized infrastructure, constraints on data placement, or ongoing administrative costs. All of these run counter to the design philosophy of peer-to-peer systems.Samsara enforces fairness in peer-to-peer storage systems without requiring trusted third parties, symmetric storage relationships, monetary payment, or certified identities. Each peer that requests storage of another must agree to hold a claim in return---a placeholder that accounts for available space. After an exchange, each partner checks the other to ensure faithfulness. Samsara punishes unresponsive nodes probabilistically. Because objects are replicated, nodes with transient failures are unlikely to suffer data loss, unlike those that are dishonest or chronically unavailable. Claim storage overhead can be reduced when necessary by forwarding among chains of nodes, and eliminated when cycles are created. Forwarding chains increase the risk of exposure to failure, but such risk is modest under reasonable assumptions of utilization and simultaneous, persistent failure.
Landon P. Cox, Brian D. Noble
SOSP1
2002 Safety, Visibility, and Performance in a Wide-Area File System
Minkyong Kim, Landon P. Cox, Brian D. Noble
FAST2
2002 Pastiche: Making Backup Cheap and Easy
Landon P. Cox, Christopher D. Murray, Brian D. Noble
OSDI1
2001 Fast Reconciliations in Fluid Replication
abstract
Mobile users can increasingly depend on high speed connectivity. Despite this, using distributed file services across the wide area is painful. Fast approaches sacrifice one or more of safety, visibility, and consistency in the name of performance. Instead, we propose fluid replication, the ability to create replicas where and when needed. These replicas, called WayStations, maintain consistency with home servers through periodic reconciliations. Two techniques make reconciliation fast; this is crucial to the success of fluid replication. First, we defer propagation of updates, and only invalidate files during a reconciliation. Second, rather than depend on operation logs, we provide the subtrees in which all updates have occurred. These subtrees, named by their least common ancestors, or LCAs, can be constructed incrementally, and reduce the burden of checking serializability during a reconciliation. While these techniques provide better performance, they are not without risk. Bulk invalidation can lead to false sharing, optimistic updates are subject to conflict, and deferred updates may cause performance problems if they are needed elsewhere. To address these concerns, we performed a trace-based evaluation of our algorithms.
Landon P. Cox, Brian D. Noble
ICDCS1
1998 Design patterns: an essential component of CS curricula
abstract
The field of software patterns has seen an explosion in interest in the last three years. Work to date has been on the recognition, cataloging, and finding of patterns with little attention to the use of patterns, especially by students and practitioners not well-versed in object-oriented technologies. This project addresses pattern use through the development of several programming and pedagogical frameworks that supply support for using patterns throughout a computer science curriculum. Although we do not claim that patterns are Brooks' silver bullet [10], their use can help cope with the accidental complexity of software development and, we argue, their use is essential for a successful adoption of object-oriented techniques in academic computer science programs. This project addresses practical concerns of the computer science and software engineering communities in using, teaching, and learning patterns. In this paper we argue that patterns are an essential programming and pedagogical tool and report on our work in making them accessible to the educational community.
Owen L. Astrachan, W. Garrett Mitchener, Geoffrey Berry, Landon P. Cox
SIGCSE4