Jörg Thalheim

dblp:180/5598 · DBLP profile ↗
← Back
6ranked-venue papers
5as first author
2since 2021 · last 2022
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 5 · 4 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer architecture, parallel and distributed computing, and storage systems
3 papers
Cloud and datacenter computing · 70% Storage systems · 30%
Network and information security
2 papers
Hardware security and side channels · 100%
Software engineering, system software, and programming languages
3 papers
Operating systems · 100%

Topics — the 10 heaviest of 10, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Cloud and datacenter computing
virtualization
0.922022
VMSH: hypervisor-agnostic guest overlays for VMs · EuroSys 2022
Cntr: Lightweight OS Containers · USENIX ATC 2018
Hardware security and side channels
trusted execution environments
0.922021
rkt-io: a direct I/O stack for shielded execution · EuroSys 2021
SPEICHER: Securing LSM-based Key-Value Stores using Shielded Execution · FAST 2019
Cloud and datacenter computing › virtualization › lightweight virtualization
lightweight virtual machines
0.612022
VMSH: hypervisor-agnostic guest overlays for VMs · EuroSys 2022
Hardware security and side channels › trusted execution environments
shielded execution
0.412019
SPEICHER: Securing LSM-based Key-Value Stores using Shielded Execution · FAST 2019
Storage systems
key-value storage
0.412019
SPEICHER: Securing LSM-based Key-Value Stores using Shielded Execution · FAST 2019
Storage systems › key-value storage
LSM-tree key-value store
0.412019
SPEICHER: Securing LSM-based Key-Value Stores using Shielded Execution · FAST 2019
Operating systems › system security › operating system security › protection mechanism › isolation
container isolation
0.312018
Cntr: Lightweight OS Containers · USENIX ATC 2018
Cloud and datacenter computing › virtualization › containerization
container-based virtualization
0.312018
Cntr: Lightweight OS Containers · USENIX ATC 2018
Operating systems
virtualization
0.212022
VMSH: hypervisor-agnostic guest overlays for VMs · EuroSys 2022
Operating systems › i/o › i/o subsystem
i/o stack
0.112021
rkt-io: a direct I/O stack for shielded execution · EuroSys 2021

Methods — techniques the papers use, named apart from their topics

file system image attachment · 1.1container-based isolation · 1.1trusted execution environment · 1.0direct i/o · 1.0containerization · 0.7
YearPublicationVenuePosition
2022 VMSH: hypervisor-agnostic guest overlays for VMs
abstract
Lightweight virtual machines (VMs) are prominently adopted for improved performance and dependability in cloud environments. To reduce boot up times and resource utilisation, they are usually "pre-baked" with only the minimal kernel and userland strictly required to run an application. This introduces a fundamental trade-off between the advantages of lightweight VMs and available services within a VM, usually leaning towards the former. We propose VMSH, a hypervisor-agnostic abstraction that enables on-demand attachment of services to a running VM---allowing developers to provide minimal, lightweight images without compromising their functionality. The additional applications are made available to the guest via a file system image. To ensure that the newly added services do not affect the original applications in the VM, VMSH uses lightweight isolation mechanisms based on containers. We evaluate VMSH on multiple KVM-based hypervisors and Linux LTS kernels and show that: (i) VMSH adds no overhead for the applications running in the VM, (ii) de-bloating images from the Docker registry can save up to 60% of their size on average, and (iii) VMSH enables cloud providers to offer services to customers, such as recovery shells, without interfering with their VM's execution.
Jörg Thalheim, Peter Okelmann, Harshavardhan Unnibhavi, Redha Gouicem, Pramod Bhatotia
EuroSys1
2021 rkt-io: a direct I/O stack for shielded execution
abstract
The shielding of applications using trusted execution environments (TEEs) can provide strong security guarantees in untrusted cloud environments. When executing I/O operations, today's shielded execution frameworks, however, exhibit performance and security limitations: they assign resources to the I/O path inefficiently, perform redundant data copies, use untrusted host I/O stacks with security risks and performance overheads. This prevents TEEs from running modern I/O-intensive applications that require high-performance networking and storage.
Jörg Thalheim, Harshavardhan Unnibhavi, Christian Priebe, Pramod Bhatotia, Peter R. Pietzuch
EuroSys1
2019 SPEICHER: Securing LSM-based Key-Value Stores using Shielded Execution
Maurice Bailleu, Jörg Thalheim, Pramod Bhatotia, Christof Fetzer, Michio Honda, Kapil Vaswani
FAST2
2018 Cntr: Lightweight OS Containers
Jörg Thalheim, Pramod Bhatotia, Pedro Fonseca 0001, Baris Kasikci
USENIX ATC1
2017 Sieve: actionable insights from monitored metrics in distributed systems
abstract
Major cloud computing operators provide powerful monitoring tools to understand the current (and prior) state of the distributed systems deployed in their infrastructure. While such tools provide a detailed monitoring mechanism at scale, they also pose a significant challenge for the application developers/operators to transform the huge space of monitored metrics into useful insights. These insights are essential to build effective management tools for improving the efficiency, resiliency, and dependability of distributed systems.
Jörg Thalheim, Antonio Rodrigues, Istemi Ekin Akkus, Pramod Bhatotia, Ruichuan Chen, Bimal Viswanath, Lei Jiao 0002, Christof Fetzer
Middleware1
2016 INSPECTOR: Data Provenance Using Intel Processor Trace (PT)
abstract
Data provenance strives for explaining how the computation was performed by recording a trace of the execution. The provenance trace is useful across a wide-range of workflows to improve the dependability, security, and efficiency of software systems. In this paper, we present Inspector, a POSIX-compliant data provenance library for shared-memory multithreaded programs. The Inspector library is completely transparent and easy to use: it can be used as a replacement for the pthreads library by a simple exchange of libraries linked, without even recompiling the application code. To achieve this result, we present a parallel provenance algorithm that records control, data, and schedule dependencies using a Concurrent Provenance Graph (CPG). We implemented our algorithm to operate at the compiled binary code level by leveraging a combination of OS-specific mechanisms, and recently released Intel PT ISA extensions as part of the Broadwell micro-architecture. Our evaluation on a multicore platform using applications from multithreaded benchmarks suites (PARSEC and Phoenix) shows reasonable provenance overheads for a majority of applications. Lastly, we briefly describe three case-studies where the generic interface exported by Inspector is being used to improve the dependability, security, and efficiency of systems. The Inspector library is publicly available for further use in a wide range of other provenance workflows.
Jörg Thalheim, Pramod Bhatotia, Christof Fetzer
ICDCS1