Roni Burd

dblp:237/0719 · DBLP profile ↗
← Back
2ranked-venue papers
0as first author
1since 2021 · last 2024
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer architecture, parallel and distributed computing, and storage systems
2 papers
Cloud and datacenter computing · 100%
Databases, data mining, and information retrieval
1 paper
Query processing and optimization · 100%
Network and information security
1 paper
Authentication and access control · 100%

Topics — the 5 heaviest of 5, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Query processing and optimization › query optimization › transformation-based optimization
query plan rewrite
0.812024
Membrane - Safe and Performant Data Access Controls in Apache Spark in the Presence of Imperative Code · Proc. VLDB Endow. 2024
Authentication and access control › access control
data access control
0.812024
Membrane - Safe and Performant Data Access Controls in Apache Spark in the Presence of Imperative Code · Proc. VLDB Endow. 2024
Cloud and datacenter computing › cluster resource management and scheduling
cluster resource management
0.412019
Hydra: a federated resource manager for data-center scale analytics · NSDI 2019
Cloud and datacenter computing › cluster resource management and scheduling
resource scheduling
0.412019
Hydra: a federated resource manager for data-center scale analytics · NSDI 2019
Cloud and datacenter computing › serverless computing
serverless analytics
0.212024
Membrane - Safe and Performant Data Access Controls in Apache Spark in the Presence of Imperative Code · Proc. VLDB Endow. 2024

Methods — techniques the papers use, named apart from their topics

query plan rewriting · 2.3container isolation · 2.3
YearPublicationVenuePosition
2024 Membrane - Safe and Performant Data Access Controls in Apache Spark in the Presence of Imperative Code
abstract
Data Governance is an increasingly critical feature of modern cloud database systems, enabling administrators to set granular access policies on their data. AWS customers want to define row or column filtering on their blob storage data and access it using popular tools such as Apache Spark. AWS EMR provides a managed and serverless solution that lets users run Spark jobs in the AWS cloud with imperative and declarative programming against their data, while securely enforcing the fine-grained access controls defined on those datasets. Spark runs its compiler and scheduler alongside the user application and embeds user-defined functions in query plans, giving a threat actor direct access to its memory space. This introduces attack vectors such as information disclosure or privilege escalation during policy enforcement, in addition to well-researched threats such as SQL side channel attacks. In this paper, we present Membrane: a novel approach to secure query plans with declarative and imperative code. The innovation comes from splitting the Spark driver in two in order to rewrite query plans with security boundaries while avoiding traditional tradeoffs when using container isolation techniques. The approach described herein enables applying fine grained data access controls to both SQL and map-reduce Spark jobs, with negligible performance and cost differences.
Andrei Paduroiu, Sungheun Wi, Roni Burd, Ruhollah A Farchtchi, Giovanni Matteo Fumarola
Proc. VLDB Endow.4
2019 Hydra: a federated resource manager for data-center scale analytics
Carlo Curino, Subru Krishnan, Konstantinos Karanasos, Sriram Rao, Giovanni Matteo Fumarola, Botong Huang, Kishore Chaliparambil, Arun Suresh, Young Chen, Solom Heddaya, Roni Burd, Sarvesh Sakalanaga, Chris Douglas, Bill Ramsey, Raghu Ramakrishnan 0001
NSDI11