Dan O'Keeffe

dblp:24/8298 · also Daniel Brendan O'Keeffe, Daniel O'Keeffe 0001 · DBLP profile ↗
← Back
18ranked-venue papers
2as first author
11since 2021 · last 2026
0000-0003-3751-477XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 4 · 2 since 2021Security and privacy · 4 · 3 since 2021Software engineering, systems software and programming languages · 4 · 3 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Computer networks · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 RustMC : Automated Verification of Real-World Concurrent Rust
Oliver Pearce, Julien Lange, Dan O'Keeffe
FORTE3
2025 Measuring Software Resilience Using Socially Aware Truck Factor Estimation
Alexis Butler, Dan O'Keeffe, Santanu Kumar Dash 0001
ASE2
2025 CloudFlow: Identifying Security-sensitive Data Flows in Serverless Applications
Giuseppe Raffa, Jorge Blasco Alís, Dan O'Keeffe, Santanu Kumar Dash 0001
USENIX Security Symposium3
2024 Revoke: Mitigating Ransomware Attacks Against Ethereum Validators
Alpesh Bhudia, Dan O'Keeffe, Darren Hurley-Smith
ESORICS (4)2
2024 Mangosteen: Fast Transparent Durability for Linearizable Applications using NVM
Sergey Egorov, Gregory V. Chockler, Brijesh Dongol, Dan O'Keeffe, Sadegh Keshavarzi
USENIX ATC4
2024 Towards Inter-Service Data Flow Analysis of Serverless Applications
abstract
The recent advent of serverless applications has created a need for static analysis tools to analyse them. However, the event-driven architecture of serverless applications, along with the black-box nature of the services they invoke, make static analysis challenging. In this work, we propose a novel approach to statically analysing serverless applications, with a focus on the identification of data flows that can lead to code injection and information leakage. To reach our goal, we first design a new suite of microbenchmarks, which we publicly release. The microbenchmarks are based on documented serverless-specific vulnerabilities and the characterization of an existing dataset. We then introduce our static analysis approach and show how it can factor in the effect of platform services and eventtriggered code execution by extracting relevant information from both infrastructure and application code. This information is used to obtain a synchronous equivalent of the underlying asynchronous system, which can be inspected with a general-purpose static analysis tool. Preliminary evaluation results using a prototype implementation of our approach and the microbenchmark suite confirm the potential of our analysis technique.
Giuseppe Raffa, Jorge Blasco Alís, Dan O'Keeffe, Santanu Kumar Dash 0001
SANER3
2023 A Knowledge Representation Framework for Evolutionary Simulations with Cognitive Agents
abstract
We propose a generic knowledge representation framework that supports evolutionary game-theoretic simulations using cognitive agents. The framework allows an experimenter to test a population of such agents via generations to study how specific population behaviours evolve over time. A generation is composed of rounds which can be further divided into encounters according to model-specific requirements. As agents in the population interact, events (caused either by agent actions or by separate environment processes) take place. These events change the environment, changes are then perceived by agents that, in turn, decide to take new actions that affect the environment. This process continues until it is time to evolve a new generation, when strategies of the fittest players are selected for the next generation to start evolving. This evolutionary loop continues until all the terminating conditions of the simulation are met. We use the framework to show how to successfully repeat existing experiments from evolutionary simulations of agent cooperation. Our results validate our framework and pave the way for EVOCOGNISIM, a simulation platform that implements the key aspects of the framework in a systematic manner.
Nausheen Saba Shahid, Dan O'Keeffe, Kostas Stathis
ICTAI2
2022 Evaluating Anti-Virus Effectiveness in Linux
abstract
Anti-virus (AV) software is widely recognized as one of the most important defensive tools against malware. Although historically many Linux users considered this operating system to be malware-free, recent research suggests that Linux malware is on the rise. However, to date there has not been a comprehensive observational study on the effectiveness of modern Linux AVs.In this work, we evaluate a range of Linux AVs using a dataset of 43,553 Linux malware samples, conducting our analysis over a period of ten months to identify possible regression effects. We measure the detection rates of Linux AVs available in our local test environment and on an online malware scanning service. Furthermore, we perform a Linux malware capability analysis using the open-source tool CAPA. Overall, the results of this work show that Linux AVs’ signature databases are not well maintained by AV vendors, and that several Linux AVs are affected by regression. In addition, our capability analysis suggests that malware authors are trying to further specialize existing approaches for evading AV software rather than developing new capabilities.
Giuseppe Raffa, Daniele Sgandurra, Dan O'Keeffe
IEEE Big Data3
2021 RansomClave: Ransomware Key Management using SGX
abstract
Modern ransomware often generate and manage cryptographic keys on the victim’s machine, giving defenders an opportunity to capture exposed keys and recover encrypted data without paying the ransom. However, recent work has raised the possibility of future enclave-enhanced malware that could avoid such mitigations using emerging support for hardware-enforced secure enclaves in commodity CPUs. Nonetheless, the practicality of such enclave-enhanced malware and its potential impact on all phases of the ransomware lifecyle remain unclear. Given the demonstrated capacity of ransomware authors to innovate in order to better extort their victims (e.g. through the adoption of untraceable virtual currencies and anonymity networks), it is important to better understand the risks involved and identify potential mitigations.
Alpesh Bhudia, Dan O'Keeffe, Daniele Sgandurra, Darren Hurley-Smith
ARES2
2021 Game-theoretic Simulations with Cognitive Agents
abstract
We propose a novel knowledge representation framework called COGNISIM that supports game theoretic simulation experiments using cognitive agents. The framework allows an experimenter to evolve a population of such agents with strategies expressed teleo-reactively as logic programs. When agents encounter each other, events take place in the environment, caused either by agent actions or by environment processes. Such events change the environment’s internal state, and these changes are then observed by agents that, in turn, decide to take new actions that affect the environment. This loop continues until the terminating conditions of the simulation are met. Using this framework, we show how to repeat experiments from the literature based on Axelrod’s tournament. We also evaluate our platform’s performance in efficiently supporting large simulations in game theoretic settings.
Nausheen Saba Shahid, Dan O'Keeffe, Kostas Stathis
ICTAI2
2021 Spons & Shields: practical isolation for trusted execution
abstract
Trusted execution environments (TEEs) promise a cost-effective, “lift-and-shift” solution for deploying security-sensitive applications in untrusted clouds. For this, they must support rich, multi-component applications, but a large trusted computing base (TCB) inside the TEE risks that attackers can compromise application security. Fine-grained compartmentalisation can increase security through defense-in-depth, but current solutions either run all software components unprotected in the same TEE, lack efficient shared memory support, or isolate application processes using separate TEEs, impacting performance and compatibility.
Vasily A. Sartakov, Dan O'Keeffe, David M. Eyers, Lluís Vilanova, Peter R. Pietzuch
VEE2
2020 Facilitating plausible deniability for cloud providers regarding tenants' activities using trusted execution
abstract
A cloud provider that can technically determine tenants' operations may be compelled to disclose such activities by law enforcement agencies (LEAs). The situation gets even more complex when multiple LEAs across different jurisdictions are involved, e.g., because of the distributed locations of cloud servers and data storage. Yet cloud providers typically do not need or want to know about their tenants' activities, other than measuring how such activities incur expenses for using cloud resources. Thus mechanisms should be developed for cloud providers to have sufficient plausible deniability with regards to the processing being carried out by tenants on their platform, in jurisdictions that permit cloud providers to avoid liabilities in this way. Symmetrically, such mechanisms could protect tenants from legal over-reach, for example, when the country in which the cloud provider is incorporated could force disclosure of the processing carried out by cloud tenants. But to what extent can cloud providers acquire plausible deniability? Current discussions regarding risk have focused on data confidentiality and integrity. We argue that processing operations can equally reveal sensitive information-such as trade secrets and business processes-and that for some classes of application both data protection and algorithm protection are necessary. In this paper, we examine the legal and technical motivations for achieving plausible deniability in cloud interactions. We demonstrate the likely performance overhead of using containers secured with technologies such as Intel SGX. Further, we examine the current limitations of our proposed plausible deniability mechanisms, and outline a potential approach for enabling lawful access to enclaves subject to appropriate judicial oversight.
Dan O'Keeffe, Asma Vranaki, Thomas Pasquier, David M. Eyers
IC2E1
2018 LibSEAL: revealing service integrity violations using trusted execution
abstract
Users of online services such as messaging, code hosting and collaborative document editing expect the services to uphold the integrity of their data. Despite providers' best efforts, data corruption still occurs, but at present service integrity violations are excluded from SLAs. For providers to include such violations as part of SLAs, the competing requirements of clients and providers must be satisfied. Clients need the ability to independently identify and prove service integrity violations to claim compensation. At the same time, providers must be able to refute spurious claims.
Pierre-Louis Aublin, Florian Kelbert, Dan O'Keeffe, Divya Muthukumaran, Christian Priebe, Joshua Lind, Robert Krahn, Christof Fetzer, David M. Eyers, Peter R. Pietzuch
EuroSys3
2018 Frontier: Resilient Edge Processing for the Internet of Things
abstract
In an edge deployment model, Internet-of-Things (IoT) applications, e.g. for building automation or video surveillance, must process data locally on IoT devices without relying on permanent connectivity to a cloud backend. The ability to harness the combined resources of multiple IoT devices for computation is influenced by the quality of wireless network connectivity. An open challenge is how practical edge-based IoT applications can be realised that are robust to changes in network bandwidth between IoT devices, due to interference and intermittent connectivity. We present Frontier , a distributed and resilient edge processing platform for IoT devices. The key idea is to express data-intensive IoT applications as continuous data-parallel streaming queries and to improve query throughput in an unreliable wireless network by exploiting network path diversity : a query includes operator replicas at different IoT nodes, which increases possible network paths for data. Frontier dynamically routes stream data to operator replicas based on network path conditions. Nodes probe path throughput and use backpressure stream routing to decide on transmission rates, while exploiting multiple operator replicas for data-parallelism. If a node loses network connectivity, a transient disconnection recovery mechanism reprocesses the lost data. Our experimental evaluation of Frontier shows that network path diversity improves throughput by 1.3×−2.8×for different IoT applications, while being resilient to intermittent network connectivity.
Dan O'Keeffe, Theodoros Salonidis, Peter R. Pietzuch
Proc. VLDB Endow.1
2017 Glamdring: Automatic Application Partitioning for Intel SGX
Joshua Lind, Christian Priebe, Divya Muthukumaran, Dan O'Keeffe, Pierre-Louis Aublin, Florian Kelbert, Tobias Reiher, David Goltzsche, David M. Eyers, Rüdiger Kapitza, Christof Fetzer, Peter R. Pietzuch
USENIX ATC4
2016 SCONE: Secure Linux Containers with Intel SGX
Sergei Arnautov, Bohdan Trach, Franz Gregor, Thomas Knauth, André Martin, Christian Priebe, Joshua Lind, Divya Muthukumaran, Dan O'Keeffe, Mark Stillwell, David Goltzsche, David M. Eyers, Rüdiger Kapitza, Peter R. Pietzuch, Christof Fetzer
OSDI9
2015 FlowWatcher: Defending against Data Disclosure Vulnerabilities in Web Applications
abstract
Bugs in the authorisation logic of web applications can expose the data of one user to another. Such data disclosure vulnerabilities are common---they can be caused by a single omitted access control check in the application. We make the observation that, while the implementation of the authorisation logic is complex and therefore error-prone, most web applications only use simple access control models, in which each piece of data is accessible by a user or a group of users. This makes it possible to validate the correct operation of the authorisation logic externally, based on the observed data in HTTP traffic to and from an application.
Divya Muthukumaran, Dan O'Keeffe, Christian Priebe, David M. Eyers, Brian Shand, Peter R. Pietzuch
CCS2
2004 Event dissemination in mobile wireless sensor networks
abstract
Sensor networks are composed of a large number of densely deployed sensors/actuators. Routing protocols are faced with the challenge of delivering data to sinks through multihop routes, in the presence of energy constrained sensor nodes. We present an energy-aware event dissemination protocol for mobile wireless sensor networks. In our proposed model each sink pro-actively constructs a redundant tree in the network to provide reliable delivery of events in the face of dynamic changes and mobility. Scalability is achieved by minimizing the number of participating nodes on the tree, while maintaining high coverage.
Salman Taherian, Dan O'Keeffe, Jean Bacon
MASS2