Sam Silvestro

dblp:206/6935 · DBLP profile ↗
← Back
9ranked-venue papers
4as first author
1since 2021 · last 2023
0000-0002-9470-6439ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 5 · 1 since 2021Systems, architecture and hardware · 2 · 1 first-authorSecurity and privacy · 2 · 2 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
5 papers
Debugging and program repair · 32% Operating systems · 28% Concurrent programming · 21%
Computer architecture, parallel and distributed computing, and storage systems
2 papers
Performance modeling and evaluation · 54% Memory systems · 46%
Network and information security
4 papers
Systems and software security · 100%

Topics — the 15 heaviest of 17, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security
memory safety
0.932018
Guarder: A Tunable Secure Allocator · USENIX Security Symposium 2018
Sampler: PMU-Based Sampling to Detect Memory Errors Latent in Production Software · MICRO 2018
FreeGuard: A Faster Secure Heap Allocator · CCS 2017
Memory systems › memory management
memory allocation
0.712023
MemPerf: Profiling Allocator-Induced Performance Slowdowns · Proc. ACM Program. Lang. 2023
Performance modeling and evaluation
profiling
0.712023
MemPerf: Profiling Allocator-Induced Performance Slowdowns · Proc. ACM Program. Lang. 2023
Program analysis
dynamic analysis
0.412020
WATCHER: in-situ failure diagnosis · Proc. ACM Program. Lang. 2020
Debugging and program repair
root cause analysis
0.412020
WATCHER: in-situ failure diagnosis · Proc. ACM Program. Lang. 2020
Systems and software security › memory safety
memory error detection
0.312018
Sampler: PMU-Based Sampling to Detect Memory Errors Latent in Production Software · MICRO 2018
Debugging and program repair
record and replay
0.312018
iReplayer: in-situ and identical record-and-replay for multithreaded applications · PLDI 2018
Concurrent programming
concurrency bugs
0.312017
UNDEAD: detecting and preventing deadlocks in production software · ASE 2017
Concurrent programming
deadlock detection
0.312017
UNDEAD: detecting and preventing deadlocks in production software · ASE 2017
Operating systems › resource management
deadlock prevention
0.312017
UNDEAD: detecting and preventing deadlocks in production software · ASE 2017
Operating systems › resource management › memory management
dynamic memory allocation
0.312017
FreeGuard: A Faster Secure Heap Allocator · CCS 2017
Systems and software security › exploitation
control-flow hijacking
0.112020
WATCHER: in-situ failure diagnosis · Proc. ACM Program. Lang. 2020
Debugging and program repair
bug reproduction
0.112018
iReplayer: in-situ and identical record-and-replay for multithreaded applications · PLDI 2018
Operating systems › resource management › memory management
memory allocation
0.112018
Guarder: A Tunable Secure Allocator · USENIX Security Symposium 2018
Performance modeling and evaluation › performance monitoring
hardware performance monitoring
0.112018
Sampler: PMU-Based Sampling to Detect Memory Errors Latent in Production Software · MICRO 2018

Methods — techniques the papers use, named apart from their topics

hardware support · 0.9binary analysis · 0.9record and replay · 0.8type-aware performance modeling · 0.7tunable security · 0.7top-down analysis · 0.7thread-aware performance modeling · 0.7performance monitoring unit sampling · 0.7heap allocator design · 0.7secure allocator design · 0.6record-and-replay · 0.4runtime monitoring · 0.3dynamic analysis · 0.3
YearPublicationVenuePosition
2023 MemPerf: Profiling Allocator-Induced Performance Slowdowns
abstract
The memory allocator plays a key role in the performance of applications, but none of the existing profilers can pinpoint performance slowdowns caused by a memory allocator. Consequently, programmers may spend time improving application code incorrectly or unnecessarily, achieving low or no performance improvement. This paper designs the first profiler—MemPerf—to identify allocator-induced performance slowdowns without comparing against another allocator. Based on the key observation that an allocator may impact the whole life-cycle of heap objects, including the accesses (or uses) of these objects, MemPerf proposes a life-cycle based detection to identify slowdowns caused by slow memory management operations and slow accesses separately. For the prior one, MemPerf proposes a thread-aware and type-aware performance modeling to identify slow management operations. For slow memory accesses, MemPerf utilizes a top-down approach to identify all possible reasons for slow memory accesses introduced by the allocator, mainly due to cache and TLB misses, and further proposes a unified method to identify them correctly and efficiently. Based on our extensive evaluation, MemPerf reports 98% medium and large allocator-reduced slowdowns (larger than 5%) correctly without reporting any false positives. MemPerf also pinpoints multiple known and unknown design issues in widely-used allocators.
Sam Silvestro, Steven (Jiaxun) Tang, Hanmei Yang, Hongyu Liu 0005, Guangming Zeng, Bo Wu 0002, Cong Liu 0005, Tongping Liu
Proc. ACM Program. Lang.2
2020 WATCHER: in-situ failure diagnosis
abstract
Diagnosing software failures is important but notoriously challenging. Existing work either requires extensive manual effort, imposing a serious privacy concern (for in-production systems), or cannot report sufficient information for bug fixes. This paper presents a novel diagnosis system, named WATCHER, that can pinpoint root causes of program failures within the failing process ("in-situ"), eliminating the privacy concern. It combines identical record-and-replay, binary analysis, dynamic analysis, and hardware support together to perform the diagnosis without human involvement. It further proposes two optimizations to reduce the diagnosis time and diagnose failures with control flow hijacks. WATCHER can be easily deployed, without requiring custom hardware or operating system, program modification, or recompilation. We evaluate WATCHER with 24 program failures in real-world deployed software, including large-scale applications, such as Memcached, SQLite, and OpenJPEG. Experimental results show that WATCHER can accurately identify the root causes in only a few seconds.
Hongyu Liu 0005, Sam Silvestro, Xiangyu Zhang 0001, Jian Huang 0006, Tongping Liu
Proc. ACM Program. Lang.2
2019 CSOD: Context-Sensitive Overflow Detection
abstract
Buffer overflow is possibly the most well-known memory issue. It can cause erratic program behavior, such as incorrect outputs and crashes, and can be exploited to issue security attacks. Detecting buffer overflows has drawn significant research attention for almost three decades. However, the prevalence of security attacks due to buffer overflows indicates that existing tools are still not widely utilized in production environments, possibly due to their high performance overhead or limited effectiveness. This paper proposes CSOD, a buffer overflow detection tool designed for the production environment. CSOD proposes a novel context-sensitive overflow detection technique that can dynamically adjust its detection strategy based on the behavior of different allocation calling contexts, enabling it to effectively detect overflows in millions of objects via four hardware watchpoints. It can correctly report root causes of buffer over-writes and over-reads, without any additional manual effort. Furthermore, CSOD only introduces 6.7% performance overhead on average, which makes it appealing as an always-on approach for production software.
Hongyu Liu 0005, Sam Silvestro, Xiaoyin Wang, Lide Duan, Tongping Liu
CGO2
2018 Sampler: PMU-Based Sampling to Detect Memory Errors Latent in Production Software
abstract
Deployed software is still faced with numerous in-production memory errors. They can significantly affect system reliability and security, causing application crashes, erratic execution behavior, or security attacks. Unfortunately, existing tools cannot be deployed in the production environment, since they either impose significant performance/memory overhead, or can only detect partial errors. This paper presents Sampler, a library that employs the combination of hardware-based SAMPLing and novel heap allocator design to efficiently identify a range of memory ERrors, including buffer overflows, use-after-frees, invalid frees, and double-frees. Due to the stringent Quality of Service (QoS) requirement of production services, Sampler proposes to trade detection effectiveness for performance on each execution. Rather than inspecting every memory access, Sampler proposes the use of the Performance Monitoring Unit (PMU) hardware to sample memory accesses, and only checks the validity of sampled accesses. At the same time, Sampler proposes a novel dynamic allocator supporting fast metadata lookup, and a solution to prevent false alarms potentially caused by sampling. The sampling-based approach, although it may lead to reduced effectiveness on each execution, is suitable for in-production software, since software is generally employed by a large number of individuals, and may be executed many times or over a long period of time. By randomizing the start of the sampling, different executions may sample different sequences of memory accesses, working together to enable effective detection. Experimental results demonstrate that Sampler detects all known memory bugs inside real applications, without any false positive. Sampler only imposes negligible performance overhead (2.4% on average). Sampler is the first work that simultaneously satisfies efficiency, preciseness, completeness, accuracy, and transparency, making it a practical tool for in-production deployment.
Sam Silvestro, Hongyu Liu 0005, Changhee Jung, Tongping Liu
MICRO1
2018 iReplayer: in-situ and identical record-and-replay for multithreaded applications
abstract
Reproducing executions of multithreaded programs is very challenging due to many intrinsic and external non-deterministic factors. Existing RnR systems achieve significant progress in terms of performance overhead, but none targets the in-situ setting, in which replay occurs within the same process as the recording process. Also, most existing work cannot achieve identical replay, which may prevent the reproduction of some errors.
Hongyu Liu 0005, Sam Silvestro, Wei Wang 0054, Chen Tian 0002, Tongping Liu
PLDI2
2018 A User Space-based Project for Practicing Core Memory Management Concepts
abstract
This paper presents the design and evaluation of a novel project designed to facilitate the learning of memory management concepts and interactions between different components. This project removes the complexity of a full or specific operating system by implementing memory management inside the user space. Evaluation results show that the mean exam scores improved by about 29% to 34%. On average, the total code size is less than 300 lines and time spent working on this project is under 17 hours. Therefore, this project is beneficial in helping students learn memory management while maintaining a reasonable project workload.
Sam Silvestro, Timothy T. Yuen, Corey Crosser, Dakai Zhu 0001, Turgay Korkmaz, Tongping Liu
SIGCSE1
2018 Guarder: A Tunable Secure Allocator
Sam Silvestro, Hongyu Liu 0005, Zhiqiang Lin 0001, Tongping Liu
USENIX Security Symposium1
2017 FreeGuard: A Faster Secure Heap Allocator
abstract
In spite of years of improvements to software security, heap-related attacks still remain a severe threat. One reason is that many existing memory allocators fall short in a variety of aspects. For instance, performance-oriented allocators are designed with very limited countermeasures against attacks, but secure allocators generally suffer from significant performance overhead, e.g., running up to 10x slower. This paper, therefore, introduces FreeGuard, a secure memory allocator that prevents or reduces a wide range of heap-related security attacks, such as heap overflows, heap over-reads, use-after-frees, as well as double and invalid frees. FreeGuard has similar performance to the default Linux allocator, with less than 2% overhead on average, but provides significant improvement to security guarantees.
Sam Silvestro, Hongyu Liu 0005, Corey Crosser, Zhiqiang Lin 0001, Tongping Liu
CCS1
2017 UNDEAD: detecting and preventing deadlocks in production software
abstract
Deadlocks are critical problems afflicting parallel applications, causing software to hang with no further progress. Existing detection tools suffer not only from significant recording performance overhead, but also from excessive memory and/or storage overhead. In addition, they may generate numerous false alarms. Subsequently, after problems have been reported, tremendous manual effort is required to confirm and fix these deadlocks. This paper designs a novel system, UnDead, that helps defeat deadlocks in production software. Different from existing detection tools, UnDead imposes negligible runtime performance overhead (less than 3 % on average) and small memory overhead (around 6%), without any storage consumption. After detection, UnDead automatically strengthens erroneous programs to prevent future occurrences of both existing and potential deadlocks, which is similar to the existing work-Dimmunix. However, UnDead exceeds Dimmunix with several orders of magnitude lower performance overhead, while eliminating numerous false positives. Extremely low runtime and memory overhead, convenience, and automatic prevention make UnDead an always-on detection tool, and a "band-aid" prevention system for production software.
Jinpeng Zhou, Sam Silvestro, Hongyu Liu 0005, Yan Cai 0001, Tongping Liu
ASE2