Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Ben Pfaff

dblp:42/4891 · also Benedikt Pfaff · DBLP profile ↗
← Back
21ranked-venue papers
5as first author
5since 2021 · last 2025
0000-0002-1526-4143ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 7 · 3 first-author · 2 since 2021Systems, architecture and hardware · 4 · 1 first-author · 2 since 2021Security and privacy · 4Software engineering, systems software and programming languages · 4 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer networks
6 papers
Software-defined and programmable networks · 94% Internet architecture and protocols · 6%
Databases, data mining, and information retrieval
1 paper
Query processing and optimization · 50% Data models and query languages · 50%
Computer architecture, parallel and distributed computing, and storage systems
8 papers
Cloud and datacenter computing · 96% Storage systems · 4%
Network and information security
5 papers
Systems and software security · 84% Hardware security and side channels · 16%

Topics — the 29 heaviest of 33, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Software-defined and programmable networks
programmable data plane
1.122025
Gigaflow: Pipeline-Aware Sub-Traversal Caching for Modern SmartNICs · ASPLOS (2) 2025
SoftFlow: A Middlebox Architecture for Open vSwitch · USENIX ATC 2016
Software-defined and programmable networks › software switch
virtual switch
1.122025
Gigaflow: Pipeline-Aware Sub-Traversal Caching for Modern SmartNICs · ASPLOS (2) 2025
The Design and Implementation of Open vSwitch · NSDI 2015
Query processing and optimization › view maintenance
incremental view maintenance
0.912025
DBSP: automatic incremental view maintenance for rich query languages · VLDB J. 2025
Data models and query languages › query language
query language semantics
0.912025
DBSP: automatic incremental view maintenance for rich query languages · VLDB J. 2025
Software-defined and programmable networks › programmable data plane
SmartNIC offload
0.912025
Gigaflow: Pipeline-Aware Sub-Traversal Caching for Modern SmartNICs · ASPLOS (2) 2025
Software-defined and programmable networks
software switch
0.512021
revisiting the open vSwitch dataplane ten years later · SIGCOMM 2021
Cloud and datacenter computing › datacenter network
virtual switch
0.512021
revisiting the open vSwitch dataplane ten years later · SIGCOMM 2021
Cloud and datacenter computing
virtualization
0.562016
PISCES: A Programmable, Protocol-Independent Software Switch · SIGCOMM 2016
SoftFlow: A Middlebox Architecture for Open vSwitch · USENIX ATC 2016
The Design and Implementation of Open vSwitch · NSDI 2015
Internet architecture and protocols › packet processing › packet classification
rule caching
0.312025
Gigaflow: Pipeline-Aware Sub-Traversal Caching for Modern SmartNICs · ASPLOS (2) 2025
Cloud and datacenter computing › virtualization
network virtualization
0.322015
Network Virtualization in Multi-tenant Datacenters · NSDI 2014
The Design and Implementation of Open vSwitch · NSDI 2015
Software-defined and programmable networks › software switch
open vswitch
0.212015
The Design and Implementation of Open vSwitch · NSDI 2015
Cloud and datacenter computing › multi-tenancy
multi-tenant datacenter
0.212014
Network Virtualization in Multi-tenant Datacenters · NSDI 2014
Operating systems › resource management
memory management
0.122005
Shredding Your Garbage: Reducing Data Lifetime Through Secure Deallocation · USENIX Security Symposium 2005
Understanding Data Lifetime via Whole System Simulation (Awarded Best Paper!) · USENIX Security Symposium 2004
Compilers and program optimization
domain-specific compilation
0.112016
PISCES: A Programmable, Protocol-Independent Software Switch · SIGCOMM 2016
Storage systems
file systems
0.112006
Virtualization Aware File Systems: Getting Beyond the Limitations of Virtual Disks · NSDI 2006
Software-defined and programmable networks
network virtualization
0.112014
Network Virtualization in Multi-tenant Datacenters · NSDI 2014
Runtime systems and virtual machines
garbage collection
0.112005
Shredding Your Garbage: Reducing Data Lifetime Through Secure Deallocation · USENIX Security Symposium 2005
Systems and software security
exploitation
0.012004
On the effectiveness of address-space randomization · CCS 2004
Systems and software security
operating system security
0.012004
Ostia: A Delegating Architecture for Secure System Call Interposition · NDSS 2004
Systems and software security › operating system security
system call interposition
0.012004
Ostia: A Delegating Architecture for Secure System Call Interposition · NDSS 2004
Algorithms and data structures › data structure design › search structures
search trees
0.012004
Performance analysis of BSTs in system software · SIGMETRICS 2004
Hardware security and side channels
trusted execution environments
0.012003
Terra: a virtual machine-based platform for trusted computing · SOSP 2003
Cloud and datacenter computing › virtualization › virtualization security
virtual machine isolation
0.012003
Terra: a virtual machine-based platform for trusted computing · SOSP 2003
Cloud and datacenter computing › virtualization
virtual machine migration
0.012002
Optimizing the Migration of Virtual Computers · OSDI 2002
Cloud and datacenter computing › virtualization
virtual machine storage
0.012006
Virtualization Aware File Systems: Getting Beyond the Limitations of Virtual Disks · NSDI 2006
Systems and software security › memory safety
buffer overflow
0.012004
On the effectiveness of address-space randomization · CCS 2004
Systems and software security
memory safety
0.012004
On the effectiveness of address-space randomization · CCS 2004
Systems and software security › operating system security
sandboxing
0.012004
Ostia: A Delegating Architecture for Secure System Call Interposition · NDSS 2004
Hardware security and side channels › trusted execution environments
remote attestation
0.012003
Terra: a virtual machine-based platform for trusted computing · SOSP 2003

Methods — techniques the papers use, named apart from their topics

sub-traversal caching · 0.9pipeline-aware caching · 0.9p4 · 0.8kernel datapath · 0.4flow-based switching · 0.4secure deallocation · 0.1workload experiments · 0.1whole system simulation · 0.1empirical benchmarking · 0.1virtualization · 0.1cryptographic identification · 0.1virtual disk management · 0.1brute-force derandomization · 0.0
YearPublicationVenuePosition
2025 Gigaflow: Pipeline-Aware Sub-Traversal Caching for Modern SmartNICs
abstract
The success of modern public/edge clouds hinges heavily on the performance of their end-host network stacks if they are to support the emerging and diverse tenants' workloads (e.g., distributed training in the cloud to fast inference at the edge). Virtual Switches (vSwitches) are vital components of this stack, providing a unified interface to enforce high-level policies on incoming packets and route them to physical interfaces, containers, or virtual machines. As performance demands escalate, there has been a shift toward offloading vSwitch processing to SmartNICs to alleviate CPU load and improve efficiency. However, existing solutions struggle to handle the growing flow rule space within the NIC, leading to high miss rates and poor scalability.
Annus Zulfiqar, Ali Imran 0005, Venkat Kunaparaju, Ben Pfaff, Gianni Antichi, Muhammad Shahbaz 0001
ASPLOS (2)4
2025 DBSP: automatic incremental view maintenance for rich query languages
Mihai Budiu, Leonid Ryzhyk, Gerd Zellweger, Ben Pfaff, Lalith Suresh 0001, Simon Kassing, Abhinav Gyawali, Matei Budiu, Tej Chajed, Frank McSherry, Val Tannen
VLDB J.4
2024 A Smart Cache for a SmartNIC! Scaling End-Host Networking to 400Gbps and Beyond
abstract
•Virtual switches optimize performance by caching multi-table lookup traversals to single-table Megaflow cache, which SmartNICs offload directly to hardware •We present Gigaflow: a multi-table sub-traversal cache for SmartNICs, designed to capture a much larger rule space using the same cache size •Open vSwitch caches traversals into Megaflow and can't share sub-traversals among traffic, making the captured rule space proportional to cache size •By caching sub-traversals into a multi-table cache, we can capture 3 orders of magnitude more rule space, attain 51% higher cache hit rate, and 31% lower end-to-end packet latency, with manageable processing overhead
Annus Zulfiqar, Ali Imran 0005, Venkat Kunaparaju, Ben Pfaff, Gianni Antichi, Muhammad Shahbaz 0001
HCS4
2022 Full-stack SDN
abstract
The conventional approach for building software-defined network systems requires separately developing the management, control, and data planes. Manually written code connects the management plane's configuration to the control plane, and the control plane generates the data planes' configurations as small program fragments that scatter across the codebase. Scalability and correctness become increasingly challenging as such a system develops and grows.
Debnil Sur, Ben Pfaff, Leonid Ryzhyk, Mihai Budiu
HotNets2
2021 revisiting the open vSwitch dataplane ten years later
abstract
This paper shares our experience in supporting and running the Open vSwitch (OVS) software switch, as part of the NSX product for enterprise data center virtualization used by thousands of VMware customers. Starting in 2009, the OVS design split its code between tightly coupled kernel and userspace components. This split was necessary at the time for performance, but it caused maintainability problems that persist today. In addition, in-kernel packet processing is now much slower than newer options.
William Tu, Yi-Hung Wei, Gianni Antichi, Ben Pfaff
SIGCOMM4
2016 PISCES: A Programmable, Protocol-Independent Software Switch
abstract
Hypervisors use software switches to steer packets to and from virtual machines (VMs). These switches frequently need upgrading and customization—to support new protocol headers or encapsulations for tunneling and overlays, to improve measurement and debugging features, and even to add middlebox-like functions. Software switches are typically based on a large body of code, including kernel code, and changing the switch is a formidable undertaking requiring domain mastery of network protocol design and developing, testing, and maintaining a large, complex codebase. Changing how a software switch forwards packets should not require intimate knowledge of its implementation. Instead, it should be possible to specify how packets are processed and forwarded in a high-level domain-specific language (DSL) such as P4, and compiled to run on a software switch. We present PISCES, a software switch derived from Open vSwitch (OVS), a hard-wired hypervisor switch, whose behavior is customized using P4. PISCES is not hard-wired to specific protocols; this independence makes it easy to add new features. We also show how the compiler can analyze the high-level specification to optimize forwarding performance. Our evaluation shows that PISCES performs comparably to OVS and that PISCES programs are about 40 times shorter than equivalent changes to OVS source code.
Muhammad Shahbaz 0001, Sean Choi, Ben Pfaff, Changhoon Kim, Nick Feamster, Nick McKeown, Jennifer Rexford
SIGCOMM3
2016 SoftFlow: A Middlebox Architecture for Open vSwitch
Ethan J. Jackson, Melvin Walls, Aurojit Panda, Justin Pettit, Ben Pfaff, Jarno Rajahalme, Teemu Koponen, Scott Shenker
USENIX ATC5
2015 The Design and Implementation of Open vSwitch
Ben Pfaff, Justin Pettit, Teemu Koponen, Ethan J. Jackson, Andy Zhou, Jarno Rajahalme, Jesse Gross, Joe Stringer, Pravin Shelar, Keith Amidon, Martín Casado
NSDI1
2014 Network Virtualization in Multi-tenant Datacenters
Teemu Koponen, Keith Amidon, Peter Balland, Martín Casado, Anupam Chanda, Bryan Fulton, Igor Ganichev, Jesse Gross, Paul Ingram, Ethan J. Jackson, Andrew Lambeth, Romain Lenglet, Shih-Hao Li, Amar Padmanabhan, Justin Pettit, Ben Pfaff, Rajiv Ramanathan, Scott Shenker, Alan Shieh, Jeremy Stribling, Pankaj Thakkar, Dan Wendlandt, Alexander Yip
NSDI16
2009 Extending Networking into the Virtualization Layer
Ben Pfaff, Justin Pettit, Keith Amidon, Martín Casado, Teemu Koponen, Scott Shenker
HotNets1
2009 The pintos instructional operating system kernel
abstract
Pintos is an instructional operating system, complete with documentation and ready-made, modular projects that introduce students to the principles of multi-programming, scheduling, virtual memory, and filesystems. By allowing students to run their work product on actual hardware, while simultaneously benefiting from debugging and dynamic analysis tools provided in simulated and emulated environments, Pintos increases student engagement. Unlike tailored versions of commercial or open source OS such as Linux, Pintos is designed from the ground up from an educational perspective. It has been used by multiple institutions for a number of years and is available for wider use.
Ben Pfaff, Anthony Romano, Godmar Back
SIGCSE1
2006 Virtualization Aware File Systems: Getting Beyond the Limitations of Virtual Disks
Ben Pfaff, Tal Garfinkel, Mendel Rosenblum
NSDI1
2005 Shredding Your Garbage: Reducing Data Lifetime Through Secure Deallocation
Jim Chow, Ben Pfaff, Tal Garfinkel, Mendel Rosenblum
USENIX Security Symposium2
2004 On the effectiveness of address-space randomization
abstract
Address-space randomization is a technique used to fortify systems against buffer overflow attacks. The idea is to introduce artificial diversity by randomizing the memory location of certain system components. This mechanism is available for both Linux (via PaX ASLR) and OpenBSD. We study the effectiveness of address-space randomization and find that its utility on 32-bit architectures is limited by the number of bits available for address randomization. In particular, we demonstrate a derandomization attack that will convert any standard buffer-overflow exploit into an exploit that works against systems protected by address-space randomization. The resulting exploit is as effective as the original exploit, although it takes a little longer to compromise a target machine: on average 216 seconds to compromise Apache running on a Linux PaX ASLR system. The attack does not require running code on the stack.
Hovav Shacham, Matthew Page, Ben Pfaff, Eu-Jin Goh, Nagendra Modadugu, Dan Boneh
CCS3
2004 Ostia: A Delegating Architecture for Secure System Call Interposition
Tal Garfinkel, Ben Pfaff, Mendel Rosenblum
NDSS2
2004 Performance analysis of BSTs in system software
abstract
Binary search tree (BST) based data structures, such as AVL trees, red-black trees, and splay trees, are often used in system software, such as operating system kernels. Choosing the right kind of tree can impact performance significantly, but the literature oers few empirical studies for guidance. We compare 20 BST variants using three experiments in real-world scenarios with real and artificial workloads. The results indicate that when input is expected to be randomly ordered with occasional runs of sorted order, red-black trees are preferred; when insertions often occur in sorted order, AVL trees excel for later random access, whereas splay trees perform best for later sequential or clustered access. For node representations, use of parent pointers is shown to be the fastest choice, with threaded nodes a close second choice that saves memory; nodes without parent pointers or threads suer when traversal and modification are combined; maintaining a in-order doubly linked list is advantageous when traversal is very common; and right-threaded nodes perform poorly.
Ben Pfaff
SIGMETRICS1
2004 Understanding Data Lifetime via Whole System Simulation (Awarded Best Paper!)
Jim Chow, Ben Pfaff, Tal Garfinkel, Kevin Christopher, Mendel Rosenblum
USENIX Security Symposium2
2003 Terra: a virtual machine-based platform for trusted computing
abstract
We present a flexible architecture for trusted computing, called Terra, that allows applications with a wide range of security requirements to run simultaneously on commodity hardware. Applications on Terra enjoy the semantics of running on a separate, dedicated, tamper-resistant hardware platform, while retaining the ability to run side-by-side with normal applications on a general-purpose computing platform. Terra achieves this synthesis by use of a trusted virtual machine monitor (TVMM) that partitions a tamper-resistant hardware platform into multiple, isolated virtual machines (VM), providing the appearance of multiple boxes on a single, general-purpose platform. To each VM, the TVMM provides the semantics of either an "open box," i.e. a general-purpose hardware platform like today's PCs and workstations, or a "closed box," an opaque special-purpose platform that protects the privacy and integrity of its contents like today's game consoles and cellular phones. The software stack in each VM can be tailored from the hardware interface up to meet the security requirements of its application(s). The hardware and TVMM can act as a trusted party to allow closed-box VMs to cryptographically identify the software they run, i.e. what is in the box, to remote parties. We explore the strengths and limitations of this architecture by describing our prototype implementation and several applications that we developed for it.
Tal Garfinkel, Ben Pfaff, Jim Chow, Mendel Rosenblum, Dan Boneh
SOSP2
2002 Optimizing the Migration of Virtual Computers
Constantine P. Sapuntzakis, Ramesh Chandra, Ben Pfaff, Jim Chow, Monica S. Lam, Mendel Rosenblum
OSDI3
2002 Virtual team awareness and groupware support: an evaluation of the TeamSCOPE system
Chyng-Yang Jang, Charles Steinfield, Ben Pfaff
Int. J. Hum. Comput. Stud.3
1999 Supporting virtual team collaboration: the TeamSCOPE system
abstract
In this paper, we describe a collaborative system specifically designed to address problems faced by distributed (or virtual) teams. TeamSCOPE (Team Software for a Collaborative Project Environment) is a web-based work environment that has emerged from a research project studying the communication needs of internationally distributed engineering design teams. The paper begins by outlining some of the needs of virtual teams. An integrative framework that focuses on facilitation of group members' awareness of group activities, communications and resources is proposed. These needs and awareness requirements are then translated into a set of collaborative system design goals which have guided the implementation of TeamSCOPE. The features of TeamSCOPE are briefly reviewed, and some preliminary observations from early users are provided. We conclude by noting some of the new features planned for TeamSCOPE based on our early trials.
Charles Steinfield, Chyng-Yang Jang, Ben Pfaff
GROUP3