Ben Wiedermann

dblp:44/1019 · DBLP profile ↗
← Back
11ranked-venue papers
2as first author
0since 2021 · last 2017
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 8 · 2 first-authorHuman-computer interaction and ubiquitous computing · 2Security and privacy · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
6 papers
Program analysis · 64% Program synthesis and code generation · 22% Programming languages and type systems · 12%
Databases, data mining, and information retrieval
2 papers
Information retrieval · 50% Query processing and optimization · 27% Database system architecture and tuning · 23%
Network and information security
1 paper
Systems and software security · 87% Network security · 13%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Performance modeling and evaluation · 91% Memory systems · 9%
Human-computer interaction and pervasive computing
1 paper
User interface design and tools · 100%

Topics — the 17 heaviest of 23, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Program analysis
static analysis
0.332014
JSAI: a static analysis platform for JavaScript · SIGSOFT FSE 2014
Interprocedural query extraction for transparent persistence · OOPSLA 2008
Extracting queries by static analysis of transparent persistence · POPL 2007
Program analysis › static analysis
abstract interpretation
0.322014
JSAI: a static analysis platform for JavaScript · SIGSOFT FSE 2014
Extracting queries by static analysis of transparent persistence · POPL 2007
Program analysis › dynamic language analysis
javascript analysis
0.212014
JSAI: a static analysis platform for JavaScript · SIGSOFT FSE 2014
Program analysis › static analysis
pointer analysis
0.212014
JSAI: a static analysis platform for JavaScript · SIGSOFT FSE 2014
Programming languages and type systems
type inference
0.212014
JSAI: a static analysis platform for JavaScript · SIGSOFT FSE 2014
Information retrieval › query understanding
query extraction
0.222008
Interprocedural query extraction for transparent persistence · OOPSLA 2008
Extracting queries by static analysis of transparent persistence · POPL 2007
Systems and software security
information flow control
0.112011
Timing- and Termination-Sensitive Secure Information Flow: Exploring a New Approach · IEEE Symposium on Security and Privacy 2011
Systems and software security › information flow control › noninterference
termination-sensitive noninterference
0.112011
Timing- and Termination-Sensitive Secure Information Flow: Exploring a New Approach · IEEE Symposium on Security and Privacy 2011
Program analysis
dynamic analysis
0.112010
Jinn: synthesizing dynamic bug detectors for foreign language interfaces · PLDI 2010
Query processing and optimization › runtime optimization › prefetching
query prefetching
0.112008
Interprocedural query extraction for transparent persistence · OOPSLA 2008
Program analysis › static analysis
interprocedural analysis
0.112008
Interprocedural query extraction for transparent persistence · OOPSLA 2008
Performance modeling and evaluation
benchmarking
0.112006
The DaCapo benchmarks: java benchmarking development and analysis · OOPSLA 2006
Performance modeling and evaluation › benchmarking › benchmark design
benchmark suite design
0.112006
The DaCapo benchmarks: java benchmarking development and analysis · OOPSLA 2006
Performance modeling and evaluation
workload characterization
0.112006
The DaCapo benchmarks: java benchmarking development and analysis · OOPSLA 2006
Network security › covert channel
covert channel analysis
0.012011
Timing- and Termination-Sensitive Secure Information Flow: Exploring a New Approach · IEEE Symposium on Security and Privacy 2011
Programming languages and type systems
object-oriented programming
0.012008
Interprocedural query extraction for transparent persistence · OOPSLA 2008
Operating systems
persistence
0.012008
Interprocedural query extraction for transparent persistence · OOPSLA 2008

Methods — techniques the papers use, named apart from their topics

usability study · 0.6case study · 0.6program transformation · 0.3reduced product · 0.2path sensitivity · 0.2heap sensitivity · 0.2context sensitivity · 0.2abstract domain · 0.2formal verification · 0.1specification inference · 0.1dynamic analysis · 0.1static analysis · 0.1time-series metrics · 0.1statistical metrics · 0.1
YearPublicationVenuePosition
2017 User-Guided Synthesis of Interactive Diagrams
abstract
Interactive diagrams are expensive to build, requiring significant programming experience. The cost of building such diagrams often prevents novice programmers or non-programmers from doing so. In this paper, we present user-guided techniques that transform a static diagram into an interactive one without requiring the user to write code. We also present a tool called EDDIE that prototypes these techniques. We evaluate EDDIE through: (1) a case study in which we use EDDIE to implement existing real-world diagrams from the literature and (2) a usability session with target users in which subjects build several diagrams in EDDIE and provide feedback on EDDIE's user experience. Our experiments demonstrate that EDDIE is usable and expressive, and that EDDIE enables real-world diagrams to be implemented without requiring programming expertise.
John Sarracino, Odaris Barrios-Arciga, Jasmine Zhu, Noah Marcus, Sorin Lerner, Ben Wiedermann
CHI6
2015 Understanding the Challenges Faced by Neurodiverse Software Engineering Employees: Towards a More Inclusive and Productive Technical Workforce
abstract
Technology workers are often stereotyped as being socially awkward or having difficulty communicating, often with humorous intent; however, for many technology workers with atypical cognitive profiles, such issues are no laughing matter. In this paper, we explore the hidden lives of neurodiverse technology workers, e.g., those with autism spectrum disorder (ASD), attention deficit hyperactivity disorder (ADHD), and/or other learning disabilities, such as dyslexia. We present findings from interviews with 10 neurodiverse technology workers, identifying the challenges that impede these employees from fully realizing their potential in the workplace. Based on the interview findings, we developed a survey that was taken by 846 engineers at a large software company. In this paper, we reflect on the differences between the neurotypical (N = 781) and neurodiverse (N = 59) respondents. Technology companies struggle to attract, develop, and retain talented software developers; our findings offer insight into how employers can better support the needs of this important worker constituency.
Meredith Ringel Morris, Andrew Begel, Ben Wiedermann
ASSETS3
2014 JSAI: a static analysis platform for JavaScript
abstract
JavaScript is used everywhere from the browser to the server, including desktops and mobile devices. However, the current state of the art in JavaScript static analysis lags far behind that of other languages such as C and Java. Our goal is to help remedy this lack. We describe JSAI, a formally specified, robust abstract interpreter for JavaScript. JSAI uses novel abstract domains to compute a reduced product of type inference, pointer analysis, control-flow analysis, string analysis, and integer and boolean constant propagation. Part of JSAI's novelty is user-configurable analysis sensitivity, i.e., context-, path-, and heap-sensitivity. JSAI is designed to be provably sound with respect to a specific concrete semantics for JavaScript, which has been extensively tested against a commercial JavaScript implementation. We provide a comprehensive evaluation of JSAI's performance and precision using an extensive benchmark suite, including real-world JavaScript applications, machine generated JavaScript code via Emscripten, and browser addons. We use JSAI's configurability to evaluate a large number of analysis sensitivities (some well-known, some novel) and observe some surprising results that go against common wisdom. These results highlight the usefulness of a configurable analysis platform such as JSAI.
Vineeth Kashyap, Kyle Dewey, Ethan A. Kuefner, John Wagner, Kevin Gibbons, John Sarracino, Ben Wiedermann, Ben Hardekopf
SIGSOFT FSE7
2014 Widening for Control-Flow
Ben Hardekopf, Ben Wiedermann, Berkeley R. Churchill, Vineeth Kashyap
VMCAI2
2013 Type refinement for static analysis of JavaScript
abstract
Static analysis of JavaScript has proven useful for a variety of purposes, including optimization, error checking, security auditing, program refactoring, and more. We propose a technique called type refinement that can improve the precision of such static analyses for JavaScript without any discernible performance impact. Refinement is a known technique that uses the conditions in branch guards to refine the analysis information propagated along each branch path. The key insight of this paper is to recognize that JavaScript semantics include many implicit conditional checks on types, and that performing type refinement on these implicit checks provides significant benefit for analysis precision.
Vineeth Kashyap, John Sarracino, John Wagner, Ben Wiedermann, Ben Hardekopf
DLS4
2012 Language design and analyzability: a retrospective
abstract
SUMMARY There is tension between programming language design for modularity and flexibility of programming and the amenability of the resulting programs to static analysis. At the start of Software Practice and Experience in 1971, most languages in commercial use were procedural (e.g., FORTRAN, ALGOL, PL/I) and on the whole were easier to analyze than languages of today such as JavaScript and Python. Modern languages include dynamic features, which enhance prototyping of approaches, often resulting in programs that are difficult for software tools or humans to understand. Starting with this perspective, we explore the relationship between language features and the ability of static analysis to precisely determine control flow and data flow in programs, thus enabling program optimization, transformation and understanding. Copyright © 2011 John Wiley & Sons, Ltd.
Barbara G. Ryder, Ben Wiedermann
Softw. Pract. Exp.2
2011 Timing- and Termination-Sensitive Secure Information Flow: Exploring a New Approach
abstract
Secure information flow guarantees the secrecy and integrity of data, preventing an attacker from learning secret information (secrecy) or injecting untrusted information (integrity). Covert channels can be used to subvert these security guarantees, for example, timing and termination channels can, either intentionally or inadvertently, violate these guarantees by modifying the timing or termination behavior of a program based on secret or untrusted data. Attacks using these covert channels have been published and are known to work in practiceâ as techniques to prevent non-covert channels are becoming increasingly practical, covert channels are likely to become even more attractive for attackers to exploit. The goal of this paper is to understand the subtleties of timing and termination-sensitive noninterference, explore the space of possible strategies for enforcing noninterference guarantees, and formalize the exact guarantees that these strategies can enforce. As a result of this effort we create a novel strategy that provides stronger security guarantees than existing work, and we clarify claims in existing work about what guarantees can be made.
Vineeth Kashyap, Ben Wiedermann, Ben Hardekopf
IEEE Symposium on Security and Privacy2
2010 Jinn: synthesizing dynamic bug detectors for foreign language interfaces
abstract
Programming language specifications mandate static and dynamic analyses to preclude syntactic and semantic errors. Although individual languages are usually well-specified, composing languages is not, and this poor specification is a source of many errors in multilingual programs. For example, virtually all Java programs compose Java and C using the Java Native Interface (JNI). Since JNI is informally specified, developers have difficulty using it correctly, and current Java compilers and virtual machines (VMs) inconsistently check only a subset of JNI constraints.
Byeongcheol Lee, Ben Wiedermann, Martin Hirzel, Robert Grimm 0001, Kathryn S. McKinley
PLDI2
2008 Interprocedural query extraction for transparent persistence
abstract
Transparent persistence promises to integrate programming languages and databases by allowing programs to access persistent data with the same ease as non-persistent data. In this work we demonstrate the feasibility of optimizing transparently persistent programs by extracting queries to efficiently prefetch required data. A static analysis derives query structure and conditions across methods that access persistent data. Using the static analysis, our system transforms the program to execute explicit queries. The transformed program composes queries across methods to handle method calls that return persistent data. We extend an existing Java compiler to implement the static analysis and program transformation, handling recursion and parameterized queries. We evaluate the effectiveness of query extraction on the OO7 and TORPEDO benchmarks. This work is focused on programs written in the current version of Java, without languages changes. However, the techniques developed here may also be of value in conjunction with object-oriented languages extended with high-level query syntax.
Ben Wiedermann, Ali Ibrahim, William R. Cook
OOPSLA1
2007 Extracting queries by static analysis of transparent persistence
abstract
Transparent persistence promises to integrate programming languages and databases by allowing procedural programs to access persistent data with the same ease as non-persistent data. When the data is stored in a relational database, however, transparent persistence does not naturally leverage the performance benefits of relational query optimization. We present a program analysis that combines the benefits of both approaches by extracting database queries from programs with transparent access to persistent data. The analysis uses a sound abstract interpretation of the original program to approximate the data traversal paths in the program and the conditions under which the paths are used. The resulting paths are then converted into a query, and the program is simplified by removing redundant tests. We study an imperative kernel language with read-only access to persistent data and identify the conditions under which the transformations can be applied. This analysis approach promises to combine the software engineering benefits of transparent data persistence with the performance benefits of database query optimization.
Ben Wiedermann, William R. Cook
POPL1
2006 The DaCapo benchmarks: java benchmarking development and analysis
abstract
Since benchmarks drive computer science research and industry product development, which ones we use and how we evaluate them are key questions for the community. Despite complex runtime tradeoffs due to dynamic compilation and garbage collection required for Java programs, many evaluations still use methodologies developed for C, C++, and Fortran. SPEC, the dominant purveyor of benchmarks, compounded this problem by institutionalizing these methodologies for their Java benchmark suite. This paper recommends benchmarking selection and evaluation methodologies, and introduces the DaCapo benchmarks, a set of open source, client-side Java benchmarks. We demonstrate that the complex interactions of (1) architecture, (2) compiler, (3) virtual machine, (4) memory management, and (5) application require more extensive evaluation than C, C++, and Fortran which stress (4) much less, and do not require (3). We use and introduce new value, time-series, and statistical metrics for static and dynamic properties such as code complexity, code size, heap composition, and pointer mutations. No benchmark suite is definitive, but these metrics show that DaCapo improves over SPEC Java in a variety of ways, including more complex code, richer object behaviors, and more demanding memory system requirements. This paper takes a step towards improving methodologies for choosing and evaluating benchmarks to foster innovation in system design and implementation for Java and other managed languages.
Steve Blackburn, Robin Garner, Chris Hoffmann, Asjad M. Khan, Kathryn S. McKinley, Rotem Bentzur, Amer Diwan, Daniel Feinberg, Daniel Frampton, Samuel Z. Guyer, Martin Hirzel, Antony L. Hosking, Maria Jump, Han Bok Lee, J. Eliot B. Moss, Aashish Phansalkar, Darko Stefanovic, Thomas VanDrunen, Daniel von Dincklage, Ben Wiedermann
OOPSLA20