Alexander Yip

dblp:24/1123 · DBLP profile ↗
← Back
7ranked-venue papers
3as first author
0since 2021 · last 2014
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 3 · 1 first-authorSystems, architecture and hardware · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 2 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
3 papers
Systems and software security · 52% Web and mobile security · 16% Privacy and data protection · 16%
Computer architecture, parallel and distributed computing, and storage systems
3 papers
Cloud and datacenter computing · 78% Storage systems · 13% Parallel and multicore computing · 8%
Software engineering, system software, and programming languages
4 papers
Programming languages and type systems · 35% Operating systems · 27% Empirical software engineering · 23%
Computer networks
1 paper
Software-defined and programmable networks · 100%

Topics — the 13 heaviest of 16, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Cloud and datacenter computing › multi-tenancy
multi-tenant datacenter
0.212014
Network Virtualization in Multi-tenant Datacenters · NSDI 2014
Cloud and datacenter computing › virtualization
network virtualization
0.212014
Network Virtualization in Multi-tenant Datacenters · NSDI 2014
Systems and software security
information flow control
0.222009
Privacy-preserving browser-side scripting with BFlow · EuroSys 2009
Information flow control for standard OS abstractions · SOSP 2007
Privacy and data protection
data confidentiality
0.112009
Privacy-preserving browser-side scripting with BFlow · EuroSys 2009
Network security › traffic analysis
data flow tracking
0.112009
Improving application security with data flow assertions · SOSP 2009
Web and mobile security
web application security
0.112009
Privacy-preserving browser-side scripting with BFlow · EuroSys 2009
Systems and software security › information flow control
decentralized information flow control
0.112007
Information flow control for standard OS abstractions · SOSP 2007
Systems and software security
operating system security
0.112007
Information flow control for standard OS abstractions · SOSP 2007
Storage systems › file systems
versioning
0.112006
Pastwatch: A Distributed Version Control System · NSDI 2006
Software-defined and programmable networks
network virtualization
0.112014
Network Virtualization in Multi-tenant Datacenters · NSDI 2014
Parallel and multicore computing › programming models
event-driven programming
0.012003
Multiprocessor Support for Event-Driven Programs · USENIX ATC, General Track 2003
Operating systems › operating system interface › system call
system call interposition
0.012007
Information flow control for standard OS abstractions · SOSP 2007
Empirical software engineering
collaborative software development
0.012006
Pastwatch: A Distributed Version Control System · NSDI 2006

Methods — techniques the papers use, named apart from their topics

reference monitor · 0.1information flow control · 0.1
YearPublicationVenuePosition
2014 Network Virtualization in Multi-tenant Datacenters
Teemu Koponen, Keith Amidon, Peter Balland, Martín Casado, Anupam Chanda, Bryan Fulton, Igor Ganichev, Jesse Gross, Paul Ingram, Ethan J. Jackson, Andrew Lambeth, Romain Lenglet, Shih-Hao Li, Amar Padmanabhan, Justin Pettit, Ben Pfaff, Rajiv Ramanathan, Scott Shenker, Alan Shieh, Jeremy Stribling, Pankaj Thakkar, Dan Wendlandt, Alexander Yip
NSDI23
2009 Privacy-preserving browser-side scripting with BFlow
abstract
Some web sites provide interactive extensions using browser scripts, often without inspecting the scripts to verify that they are benign and bug-free. Others handle users' confidential data and display it via the browser. Such new features contribute to the power of online services, but their combination would allow attackers to steal confidential data. This paper presents BFlow, a security system that uses information flow control to allow the combination while preventing attacks on data confidentiality.
Alexander Yip, Neha Narula, Maxwell N. Krohn, Robert Morris 0005
EuroSys1
2009 Improving application security with data flow assertions
abstract
Resin is a new language runtime that helps prevent security vulnerabilities, by allowing programmers to specify application-level data flow assertions. Resin provides policy objects, which programmers use to specify assertion code and metadata; data tracking, which allows programmers to associate assertions with application data, and to keep track of assertions as the data flow through the application; and filter objects, which programmers use to define data flow boundaries at which assertions are checked. Resin's runtime checks data flow assertions by propagating policy objects along with data, as that data moves through the application, and then invoking filter objects when data crosses a data flow boundary, such as when writing data to the network or a file.
Alexander Yip, Xi Wang 0005, Nickolai Zeldovich, M. Frans Kaashoek
SOSP1
2007 World Wide Web Without Walls
Micah Z. Brodsky, Maxwell N. Krohn, Robert Morris 0005, Michael Walfish, Alexander Yip
HotNets5
2007 Information flow control for standard OS abstractions
abstract
Decentralized Information Flow Control (DIFC) [24] is an ap-proach to security that allows application writers to control how data flows between the pieces of an application and the outside world. As applied to privacy, DIFC allows untrusted software to compute with private data while trusted security code controls the release of that data. As applied to integrity, DIFC allows trusted code to protect untrusted software from unexpected malicious in-puts. In either case, only bugs in the trusted code, which tends to be small and isolated, can lead to security violations. We present Flume, a new DIFC model and system that applies at the granularity of operating system processes and standard OS ab-stractions (e.g., pipes and file descriptors). Flume eases DIFC’s use in existing applications and allows safe interaction between con-ventional and DIFC-aware processes. Flume runs as a user-level reference monitor on Linux. A process confined by Flume cannot perform most system calls directly; instead, an interposition layer replaces system calls with IPC to the reference monitor, which en-forces data flow policies and performs safe operations on the pro-cess’s behalf. We ported a complex Web application (MoinMoin wiki) to Flume, changing only 2 % of the original code. The Flume version is roughly 30–40 % slower due to overheads in our current implementation but supports additional security policies impossible without DIFC.
Maxwell N. Krohn, Alexander Yip, Micah Z. Brodsky, Natan Cliffer, M. Frans Kaashoek, Eddie Kohler, Robert Morris 0005
SOSP2
2006 Pastwatch: A Distributed Version Control System
Alexander Yip, Benjie Chen, Robert Morris 0005
NSDI1
2003 Multiprocessor Support for Event-Driven Programs
Nickolai Zeldovich, Alexander Yip, Frank Dabek, Robert T. Morris, David Mazières, M. Frans Kaashoek
USENIX ATC, General Track2