Joseph Bursey

dblp:367/3749 · DBLP profile ↗
← Back
2ranked-venue papers
1as first author
2since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
1 paper
Operating systems · 33% Program analysis · 33% Concurrent programming · 33%

Topics — the 3 heaviest of 3, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Concurrent programming
deadlock detection
0.912025
Spinner: Detecting Locking Violations in the eBPF Runtime · ASE 2025
Operating systems › extensible operating systems › kernel extensibility
kernel extensions
0.912025
Spinner: Detecting Locking Violations in the eBPF Runtime · ASE 2025
Program analysis
static analysis
0.912025
Spinner: Detecting Locking Violations in the eBPF Runtime · ASE 2025

Methods — techniques the papers use, named apart from their topics

static analysis · 0.9
YearPublicationVenuePosition
2025 Spinner: Detecting Locking Violations in the eBPF Runtime
abstract
The eBPF technology is widely used for many applications, including tracing, packet filtering, network usage monitoring, and so on. The versatility of eBPF allows the kernel’s capabilities to be extended without needing to modify source code or load kernel modules. However, the eBPF subsystem may introduce new bugs that could lead to crashes, data loss, and other issues that can negatively impact system stability, reliability, availability, security, and overall performance. Specifically, locking violations, which occur when locks are not used correctly, can lead to problems like deadlocks and system hangs. Since eBPF operates at the kernel level, errors here have far-reaching consequences.To tackle this issue, we present Spinner, a tool for detecting locking violations in the eBPF runtime. Spinner uses static analysis to (1) detect cases of context confusion where incorrect locking primitives are used in eBPF helper functions given their execution context, and (2) identify locks in helper functions that can be called recursively using nested eBPF programs. Both of these situations could result in deadlocks. So far, Spinner has identified 34 locking violation bugs in the eBPF subsystem in Linux, only 5 of which were previously found by Syzbot.
Priya Govindasamy, Joseph Bursey, Hsin-Wei Hung, Ardalan Amiri Sani
ASE2
2025 SyzRetrospector: A Large-Scale Retrospective Study of Syzbot
abstract
Over the past 7 years, Syzbot has fuzzed the Linux kernel day and night to report over 6,700 bugs, of which nearly 5,500 have been patched. While this is impressive, we have found that $25 \%$ of bugs take longer than 738 days to find. Moreover, we have found that current metrics commonly used, such as time-to-find and number of bugs found, are inaccurate in evaluating Syzbot since bugs often spend the majority of their lives hidden from the fuzzer. In this paper, we set out to better understand and quantify Syzbot’s performance and improvement in finding bugs. Our tool, SyzRetrospector, takes a different approach to evaluating Syzbot by finding the earliest that Syzbot was capable of finding a bug, and why that bug was revealed. We use SyzRetrospector on a large scale to analyze 695 bugs and find that $40 \%$ of bugs are hidden for more than 258 days before Syzbot is even able to find them. We further present findings on why bugs were revealed to Syzbot (i.e., their revealing factors), the effort required to reveal bugs, the trends in delays, and how the location of bugs affects these delays. We also provide key takeaways for improving Syzbot’s delays.
Joseph Bursey, Ardalan Amiri Sani, Zhiyun Qian
RAID1