Steve Vandebogart

dblp:01/5498 · DBLP profile ↗
← Back
4ranked-venue papers
2as first author
0since 2021 · last 2009
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 2 · 2 first-authorSoftware engineering, systems software and programming languages · 2

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
3 papers
Programming languages and type systems · 60% Operating systems · 40%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Storage systems · 100%
Network and information security
2 papers
Systems and software security · 100%

Topics — the 5 heaviest of 7, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Programming languages and type systems
information flow control
0.122007
Labels and event processes in the Asbestos operating system · ACM Trans. Comput. Syst. 2007
Labels and event processes in the Asbestos operating system · SOSP 2005
Storage systems › i/o scheduling
disk scheduling
0.112009
Reducing Seek Overhead with Application-Directed Prefetching · USENIX ATC 2009
Storage systems › i/o optimization
disk seek time reduction
0.112009
Reducing Seek Overhead with Application-Directed Prefetching · USENIX ATC 2009
Systems and software security
operating system security
0.112007
Labels and event processes in the Asbestos operating system · ACM Trans. Comput. Syst. 2007
Operating systems › system security
operating system security
0.112005
Labels and event processes in the Asbestos operating system · SOSP 2005

Methods — techniques the papers use, named apart from their topics

kernel-enforced labels · 0.1event process abstraction · 0.1labels · 0.1event processes · 0.1
YearPublicationVenuePosition
2009 Reducing Seek Overhead with Application-Directed Prefetching
Steve Vandebogart, Christopher Frost 0001, Eddie Kohler
USENIX ATC1
2007 Labels and event processes in the Asbestos operating system
abstract
Asbestos, a new operating system, provides novel labeling and isolation mechanisms that help contain the effects of exploitable software flaws. Applications can express a wide range of policies with Asbestos's kernel-enforced labels, including controls on interprocess communication and system-wide information flow. A new event process abstraction defines lightweight, isolated contexts within a single process, allowing one process to act on behalf of multiple users while preventing it from leaking any single user's data to others. A Web server demonstration application uses these primitives to isolate private user data. Since the untrusted workers that respond to client requests are constrained by labels, exploited workers cannot directly expose user data except as allowed by application policy. The server application requires 1.4 memory pages per user for up to 145,000 users and achieves connection rates similar to Apache, demonstrating that additional security can come at an acceptable cost.
Steve Vandebogart, Petros Efstathopoulos, Eddie Kohler, Maxwell N. Krohn, Cliff Frey, David Ziegler, M. Frans Kaashoek, Robert Morris 0005, David Mazières
ACM Trans. Comput. Syst.1
2005 Make Least Privilege a Right (Not a Privilege)
Maxwell N. Krohn, Petros Efstathopoulos, Cliff Frey, M. Frans Kaashoek, Eddie Kohler, David Mazières, Robert Morris 0005, Michelle Osborne, Steve Vandebogart, David Ziegler
HotOS9
2005 Labels and event processes in the Asbestos operating system
abstract
Asbestos, a new prototype operating system, provides novel labeling and isolation mechanisms that help contain the effects of exploitable software flaws. Applications can express a wide range of policies with Asbestos's kernel-enforced label mechanism, including controls on inter-process communication and system-wide information flow. A new event process abstraction provides lightweight, isolated contexts within a single process, allowing the same process to act on behalf of multiple users while preventing it from leaking any single user's data to any other user. A Web server that uses Asbestos labels to isolate user data requires about 1.5 memory pages per user, demonstrating that additional security can come at an acceptable cost.
Petros Efstathopoulos, Maxwell N. Krohn, Steve Vandebogart, Cliff Frey, David Ziegler, Eddie Kohler, David Mazières, M. Frans Kaashoek, Robert Morris 0005
SOSP3