Faiz Alam

dblp:362/8738 · DBLP profile ↗
← Back
2ranked-venue papers
2as first author
2since 2021 · last 2026
0009-0000-4045-7281ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer architecture, parallel and distributed computing, and storage systems
1 paper
Hardware accelerators and domain-specific architectures · 62% Memory systems · 38%
Network and information security
1 paper
Hardware security and side channels · 100%

Topics — the 3 heaviest of 4, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Hardware security and side channels
trusted execution environments
0.712023
CryptoMMU: Enabling Scalable and Secure Access Control of Third-Party Accelerators · MICRO 2023
Memory systems › memory management › memory management unit
IOMMU
0.212023
CryptoMMU: Enabling Scalable and Secure Access Control of Third-Party Accelerators · MICRO 2023
Memory systems › memory management
memory management unit
0.212023
CryptoMMU: Enabling Scalable and Secure Access Control of Third-Party Accelerators · MICRO 2023

Methods — techniques the papers use, named apart from their topics

memory management unit · 1.3access control · 1.3
YearPublicationVenuePosition
2026 VirtShield: A Security Evaluation Framework for Virtualized and Containerized Systems
abstract
Virtualization is a foundational technology in modern cloud computing. However, it is subject to security threats such as malicious co-located tenants, hypervisor vulnerabilities, and side-channel attacks. Such a threat is countered by deploying advanced and complex security solutions that have significant performance overhead.Prior work on VMs and containers has mainly evaluated basic security solutions, such as firewalls, using narrow performance metrics and synthetic models within limited evaluation frameworks. These studies often overlook advanced security modules in both user and kernel space, lack flexibility to incorporate emerging features, and fail to capture detailed system-level impacts. To address these gaps, we present VirtShield, an open-source framework for unified security testing in VMs and containers that mimics realistic cloud infrastructures. VirtShield supports advanced security modules across user and kernel space, providing rich, system-level performance metrics for comprehensive evaluation.Our evaluation shows that containers generally outperform VMs due to their lower virtualization overhead, achieving a throughput of 9.38 Gb/s compared to 1.98 Gb/s for VMs. However, VMs are comparable for kernel-space deployments, as Docker utilizes the shared kernel space Docker bridge, which can result in packet congestion. In latency-sensitive workloads, VM access latency (14.91 ms) is comparable to Docker (12.86 ms). In storage benchmarks (FIO), however, VMs outperform Docker due to the overhead of Docker’s layered, copy-on-write file system, whereas VMs leverage optimized virtual block devices with near-native I/O performance. These results highlight essential trade-offs in partitioning security workloads between user and kernel space, as well as across containerized and virtualized environments.
Faiz Alam, Mohammed Mubeen Mifthak, Sahil Purohit, Md Shadab, Greg Byrd, Khaled Harfoush
CCNC1
2023 CryptoMMU: Enabling Scalable and Secure Access Control of Third-Party Accelerators
abstract
Due to increasing energy and performance gaps between general-purpose processors and hardware accelerators (e.g., FPGA or ASIC), clear trends for leveraging accelerators arise in various fields or workloads, such as edge devices, cloud systems, and data centers. Moreover, system integrators desire higher flexibility to deploy custom accelerators based on their performance, power, and cost constraints, where such integration can be as early as (1) at the design time when third-party intellectual properties (IPs) are used, (2) at integration/upgrade time when third-party discrete chip accelerators are used, or (3) during runtime as in reconfigurable logic.
Faiz Alam, Hyokeun Lee, Abhishek Bhattacharjee, Amro Awad
MICRO1