Jed Liu

dblp:20/5913 · DBLP profile ↗
← Back
13ranked-venue papers
6as first author
2since 2021 · last 2023
0000-0002-2753-5174ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 4 · 2 first-author · 2 since 2021Security and privacy · 4 · 1 first-authorSoftware engineering, systems software and programming languages · 4 · 3 first-authorSystems, architecture and hardware · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer networks
3 papers
Software-defined and programmable networks · 67% Network management and operations · 33%
Computer architecture, parallel and distributed computing, and storage systems
5 papers
Distributed systems · 100%
Network and information security
3 papers
Systems and software security · 69% Web and mobile security · 19% Authentication and access control · 12%
Software engineering, system software, and programming languages
3 papers
Program verification · 69% Programming languages and type systems · 26% Compilers and program optimization · 4%
Databases, data mining, and information retrieval
1 paper
Transaction processing and concurrency control · 100%

Topics — the 19 heaviest of 26, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Software-defined and programmable networks
programmable data plane
1.022023
P4Testgen: An Extensible Test Oracle For P4-16 · SIGCOMM 2023
p4v: practical verification for programmable data planes · SIGCOMM 2018
Network management and operations
network verification
0.712023
P4Testgen: An Extensible Test Oracle For P4-16 · SIGCOMM 2023
Distributed systems
distributed coordination
0.622019
Efficient, Consistent Distributed Computation with Predictive Treaties · EuroSys 2019
Warranties for Faster Strong Consistency · NSDI 2014
Distributed systems › consistency models
strong consistency
0.622019
Efficient, Consistent Distributed Computation with Predictive Treaties · EuroSys 2019
Warranties for Faster Strong Consistency · NSDI 2014
Software-defined and programmable networks › programmable data plane
p4 program verification
0.312018
p4v: practical verification for programmable data planes · SIGCOMM 2018
Distributed systems
replication
0.322019
Warranties for Faster Strong Consistency · NSDI 2014
Efficient, Consistent Distributed Computation with Predictive Treaties · EuroSys 2019
Transaction processing and concurrency control › transaction scheduling
serializable scheduling
0.212016
Safe Serializable Secure Scheduling: Transactions and the Trade-Off Between Security and Consistency · CCS 2016
Systems and software security
information flow control
0.222012
Sharing Mobile Code Securely with Information Flow Control · IEEE Symposium on Security and Privacy 2012
Fabric: a platform for secure distributed computation and storage · SOSP 2009
Network management and operations
network configuration
0.112021
Avenir: Managing Data Plane Diversity with Control Plane Synthesis · NSDI 2021
Systems and software security › data security
confidentiality and integrity
0.112012
Sharing Mobile Code Securely with Information Flow Control · IEEE Symposium on Security and Privacy 2012
Web and mobile security › mobile security
mobile code security
0.112012
Sharing Mobile Code Securely with Information Flow Control · IEEE Symposium on Security and Privacy 2012
Authentication and access control › security policy
confidentiality and integrity policies
0.112009
Fabric: a platform for secure distributed computation and storage · SOSP 2009
Distributed systems › distributed database
distributed transactions
0.112009
Fabric: a platform for secure distributed computation and storage · SOSP 2009
Distributed systems › transaction processing
nested transactions
0.112009
Fabric: a platform for secure distributed computation and storage · SOSP 2009
Distributed systems
peer-to-peer systems
0.112009
Fabric: a platform for secure distributed computation and storage · SOSP 2009
Distributed systems › distributed system security
secure distributed computing
0.112009
Fabric: a platform for secure distributed computation and storage · SOSP 2009
Systems and software security › information flow control
information flow policies
0.112007
Secure web application via automatic partitioning · SOSP 2007
Programming languages and type systems › control operators
coroutines
0.112006
Interruptible iterators · POPL 2006
Programming languages and type systems
language design
0.112006
Interruptible iterators · POPL 2006

Methods — techniques the papers use, named apart from their topics

taint tracking · 0.7formal verification · 0.7domain-specific optimization · 0.7concolic execution · 0.7static compiler checking · 0.5staged commit protocol · 0.5time-dependent local enforcement · 0.4predicate partitioning · 0.4information flow analysis · 0.3optimistic nested transactions · 0.2function shipping · 0.2data shipping · 0.2compile-time and run-time policy enforcement · 0.2consistency protocols · 0.2max-flow algorithm · 0.1information flow policies · 0.1exception handling · 0.1coroutine mechanism · 0.1
YearPublicationVenuePosition
2023 P4Testgen: An Extensible Test Oracle For P4-16
abstract
We present P4Testgen, a test oracle for the P416 language. P4Testgen supports automatic test generation for any P4 target and is designed to be extensible to many P4 targets. It models the complete semantics of the target's packet-processing pipeline including the P4 language, architectures and externs, and target-specific extensions. To handle non-deterministic behaviors and complex externs (e.g., checksums and hash functions), P4Testgen uses taint tracking and concolic execution. It also provides path selection strategies that reduce the number of tests required to achieve full coverage.
Fabian Ruffy, Jed Liu, Prathima Kotikalapudi, Vojtech Havel, Hanneli Tavante, Rob Sherwood, Vladyslav Dubina, Vladimir S. Peschanenko, Anirudh Sivaraman, Nate Foster
SIGCOMM2
2021 Avenir: Managing Data Plane Diversity with Control Plane Synthesis
Eric Hayden Campbell, William T. Hallahan, Priya Srikumar, Carmelo Cascone, Jed Liu, Vignesh Ramamurthy, Hossein Hojjat, Ruzica Piskac, Robert Soulé, Nate Foster
NSDI5
2019 Efficient, Consistent Distributed Computation with Predictive Treaties
abstract
To achieve good performance, modern applications often partition their state across multiple geographically distributed nodes. While this approach reduces latency in the common case, it can be challenging for programmers to use correctly, especially in applications that require strong consistency. We introduce predictive treaties, a mechanism that can significantly reduce distributed coordination without losing strong consistency. The central insight behind our approach is that many computations can be expressed in terms of predicates over distributed state that can be partitioned and enforced locally. Predictive treaties improve on previous work by allowing the locally enforced predicates to depend on time. Intuitively, by predicting the evolution of system state, coordination can be significantly reduced compared to static approaches. We implemented predictive treaties in a distributed system that exposes them in an intuitive programming model. We evaluate performance on several benchmarks, including TPC-C, showing that predictive treaties can significantly increase performance by orders of magnitude and can even outperform customized algorithms.
Tom Magrino, Jed Liu, Nate Foster, Johannes Gehrke, Andrew C. Myers
EuroSys2
2018 p4v: practical verification for programmable data planes
abstract
We present the design and implementation of p4v, a practical tool for verifying data planes described using the P4 programming language. The design of p4v is based on classic verification techniques but adds several key innovations including a novel mechanism for incorporating assumptions about the control plane and domain-specific optimizations which are needed to scale to large programs. We present case studies showing that p4v verifies important properties and finds bugs in real-world programs. We conduct experiments to quantify the scalability of p4v on a wide range of additional examples. We show that with just a few hundred lines of control-plane annotations, p4v is able to verify critical safety properties for switch.p4, a program that implements the functionality of on a modern data center switch, in under three minutes.
Jed Liu, William T. Hallahan, Cole Schlesinger, Milad Sharif, Jeongkeun Lee, Robert Soulé, Han Wang 0009, Calin Cascaval, Nick McKeown, Nate Foster
SIGCOMM1
2017 Fabric: Building open distributed systems securely by construction
abstract
Distributed information systems are prevalent in modern computing but difficult to build securely. Because systems commonly span domains of trust, host nodes share data and code of varying degrees of trustworthiness. Modern systems are often open and extensible, making security even harder to reaso n about. Unfortunately, standard methods for software construction do not help programmers enough with ensuring their software is secure. Fabric is a system and language for building open, distributed, extensible information systems that are secure by construction. Fabric is a decentralized system that allows nodes to securely share both data and code despite mutual distrust. All resources are labeled with confidentiality and integrity policies that are enforced through a combination of compile-time and run-time mechanisms. The Fabric language offers a high-level but powerful model of computation. All resources appear as objects in the language, and the distribution and persistence of code and data are largely transparent to programmers. Fabric supports both data-shipping and query/RPC styles of computation: computation and information can both move between nodes. Optimistic, nested transactions ensure consistency across all objects and nodes. Fabric programs can securely share mobile code across trust domains, enabling more reuse and evolution of code and supporting new kinds of secure applications not possible in other distributed systems. Results from applications built using Fabric suggest that Fabric enforces strong security while offering a clean, concise, powerful programming model with good performance. An open-source prototype is available for download.
Jed Liu, Owen Arden, Michael D. George, Andrew C. Myers
J. Comput. Secur.1
2016 Safe Serializable Secure Scheduling: Transactions and the Trade-Off Between Security and Consistency
abstract
Modern applications often operate on data in multiple administrative domains. In this federated setting, participants may not fully trust each other. These distributed applications use transactions as a core mechanism for ensuring reliability and consistency with persistent data. However, the coordination mechanisms needed for transactions can both leak confidential information and allow unauthorized influence. By implementing a simple attack, we show these side channels can be exploited. However, our focus is on preventing such attacks. We explore secure scheduling of atomic, serializable transactions in a federated setting. While we prove that no protocol can guarantee security and liveness in all settings, we establish conditions for sets of transactions that can safely complete under secure scheduling. Based on these conditions, we introduce \ti{staged commit}, a secure scheduling protocol for federated transactions. This protocol avoids insecure information channels by dividing transactions into distinct stages. We implement a compiler that statically checks code to ensure it meets our conditions, and a system that schedules these transactions using the staged commit protocol. Experiments on this implementation demonstrate that realistic federated transactions can be scheduled securely, atomically, and efficiently.
Isaac C. Sheff, Tom Magrino, Jed Liu, Andrew C. Myers, Robbert van Renesse
CCS3
2015 Flow-Limited Authorization
abstract
Because information flow control mechanisms often rely on an underlying authorization mechanism, their security guarantees can be subverted by weaknesses in authorization. Conversely, the security of authorization can be subverted by information flows that leak information or that influence how authority is delegated between principals. We argue that interactions between information flow and authorization create security vulnerabilities that have not been fully identified or addressed in prior work. We explore how the security of decentralized information flow control (DIFC) is affected by three aspects of its underlying authorization mechanism: first, delegation of authority between principals, second, revocation of previously delegated authority, third, information flows created by the authorization mechanisms themselves. It is no surprise that revocation poses challenges, but we show that even delegation is problematic because it enables unauthorized downgrading. Our solution is a new security model, the Flow-Limited Authorization Model (FLAM), which offers a new, integrated approach to authorization and information flow control. FLAM ensures robust authorization, a novel security condition for authorization queries that ensures attackers cannot influence authorization decisions or learn confidential trust relationships. We discuss our prototype implementation and its algorithm for proof search.
Owen Arden, Jed Liu, Andrew C. Myers
CSF2
2014 Warranties for Faster Strong Consistency
Jed Liu, Tom Magrino, Owen Arden, Michael D. George, Andrew C. Myers
NSDI1
2012 Sharing Mobile Code Securely with Information Flow Control
abstract
Mobile code is now a nearly inescapable component of modern computing, thanks to client-side code that runs within web browsers. The usual tension between security and functionality is particularly acute in a mobile-code setting, and current platforms disappoint on both dimensions. We introduce a new architecture for secure mobile code, with which developers can use, publish, and share mobile code securely across trust domains. This architecture enables new kinds of distributed applications, and makes it easier to reuse and evolve code from untrusted providers. The architecture gives mobile code considerable expressive power: it can securely access distributed, persistent, shared information from multiple trust domains, unlike web applications bound by the same-origin policy. The core of our approach is analyzing how flows of information within mobile code affect confidentiality and integrity. Because mobile code is untrusted, this analysis requires novel constraints on information flow and authority. We show that these constraints offer principled enforcement of strong security while avoiding the limitations of current mobile-code security mechanisms. We evaluate our approach by demonstrating a variety of mobile-code applications, showing that new functionality can be offered along with strong security.
Owen Arden, Michael D. George, Jed Liu, K. Vikram, Aslan Askarov, Andrew C. Myers
IEEE Symposium on Security and Privacy3
2009 Fabric: a platform for secure distributed computation and storage
abstract
Fabric is a new system and language for building secure distributed information systems. It is a decentralized system that allows heterogeneous network nodes to securely share both information and computation resources despite mutual distrust. Its high-level programming language makes distribution and persistence largely transparent to programmers. Fabric supports data-shipping and function-shipping styles of computation: both computation and information can move between nodes to meet security requirements or to improve performance. Fabric provides a rich, Java-like object model, but data resources are labeled with confidentiality and integrity policies that are enforced through a combination of compile-time and run-time mechanisms. Optimistic, nested transactions ensure consistency across all objects and nodes. A peer-to-peer dissemination layer helps to increase availability and to balance load. Results from applications built using Fabric suggest that Fabric has a clean, concise programming model, offers good performance, and enforces security.
Jed Liu, Michael D. George, K. Vikram, Xin Qi 0012, Lucas Waye, Andrew C. Myers
SOSP1
2007 Secure web application via automatic partitioning
abstract
Swift is a new, principled approach to building web applications that are secure by construction. In modern web applications, some application functionality is usually implemented as client-side code written in JavaScript. Moving code and data to the client can create security vulnerabilities, but currently there are no good methods for deciding when it is secure to do so. Swift automatically partitions application code while providing assurance that the resulting placement is secure and efficient. Application code is written as Java-like code annotated with information flow policies that specify the confidentiality and integrity of web application information. The compiler uses these policies to automatically partition the program into JavaScript code running in the browser, and Java code running on the server. To improve interactive performance, code and data are placed on the client side. However, security-critical code and data are always placed on the server. Code and data can also be replicated across the client and server, to obtain both security and performance. A max-flow algorithm is used to place code and data in a way that minimizes client-server communication.
Stephen Chong, Jed Liu, Andrew C. Myers, Xin Qi 0012, K. Vikram, Lantian Zheng
SOSP2
2006 Interruptible iterators
abstract
This paper introduces interruptible iterators, a language feature that makes expressive iteration abstractions much easier to implement. Iteration abstractions are valuable for software design, as shown by their frequent use in well-designed data structure libraries such as the Java Collections Framework. While Java iterators support iteration abstraction well from the standpoint of client code, they are awkward to implement correctly and efficiently, especially if the iterator needs to support imperative update of the underlying collection, such as removing the current element. Some languages, such as CLU and C# 2.0, support iteration through a limited coroutine mechanism, but these mechanisms do not support imperative updates. Interruptible iterators are more powerful coroutines in which the loop body is able to interrupt the iterator with requests to perform updates. Interrupts are similar to exceptions, but propagate differently and have resumption semantics. Interruptible iterators have been implemented as part of the JMatch programming language, an extended version of Java. A JMatch reimplementation of the Java Collections Framework shows that implementations can be made substantially shorter and simpler; performance results show that this language mechanism can also be implemented efficiently.
Jed Liu, Aaron Kimball, Andrew C. Myers
POPL1
2003 JMatch: Iterable Abstract Pattern Matching for Java
Jed Liu, Andrew C. Myers
PADL1