EDBT 2026 Demo / reviewers in the wild / expert
Ioannis Doudalis
dblp:50/4778
· DBLP profile ↗
6ranked-venue papers
3as first author
0since 2021 · last 2012
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 5 · 3 first-authorSoftware engineering, systems software and programming languages · 2 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Computer architecture, parallel and distributed computing, and storage systems
5 papers |
Hardware accelerators and domain-specific architectures · 28% Processor architecture and microarchitecture · 22% Hardware reliability and fault tolerance · 22% | |
| Network and information security
4 papers |
Systems and software security · 100% | |
| Software engineering, system software, and programming languages
2 papers |
Program analysis · 77% Debugging and program repair · 23% |
Topics — the 14 heaviest of 16, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security
memory safety |
0.3 | 3 | 2012 | Effective and Efficient Memory Protection Using Dynamic Tainting · IEEE Trans. Computers 2012 MemTracker: An accelerator for memory debugging and monitoring · ACM Trans. Archit. Code Optim. 2009 Effective memory protection using dynamic tainting · ASE 2007 |
Systems and software security › information flow tracking
dynamic taint analysis |
0.2 | 2 | 2012 | Effective and Efficient Memory Protection Using Dynamic Tainting · IEEE Trans. Computers 2012 FlexiTaint: A programmable accelerator for dynamic taint propagation · HPCA 2008 |
Distributed systems › fault tolerance
checkpointing |
0.1 | 1 | 2012 | Euripus: A flexible unified hardware memory checkpointing accelerator for bidirectional-debugging and reliability · ISCA 2012 |
Hardware reliability and fault tolerance
error recovery |
0.1 | 1 | 2012 | Euripus: A flexible unified hardware memory checkpointing accelerator for bidirectional-debugging and reliability · ISCA 2012 |
Processor architecture and microarchitecture
debugging support |
0.1 | 1 | 2010 | HARE: Hardware assisted reverse execution · HPCA 2010 |
Systems and software security › memory safety
memory error detection |
0.1 | 1 | 2009 | MemTracker: An accelerator for memory debugging and monitoring · ACM Trans. Archit. Code Optim. 2009 |
Memory systems › memory access
memory access monitoring |
0.1 | 1 | 2009 | MemTracker: An accelerator for memory debugging and monitoring · ACM Trans. Archit. Code Optim. 2009 |
Hardware accelerators and domain-specific architectures
security accelerator |
0.1 | 1 | 2008 | FlexiTaint: A programmable accelerator for dynamic taint propagation · HPCA 2008 |
Systems and software security
memory protection |
0.1 | 1 | 2007 | Effective memory protection using dynamic tainting · ASE 2007 |
Program analysis
dynamic analysis |
0.1 | 1 | 2007 | Effective memory protection using dynamic tainting · ASE 2007 |
Program analysis › static analysis
taint analysis |
0.1 | 1 | 2007 | Effective memory protection using dynamic tainting · ASE 2007 |
Processor architecture and microarchitecture
hardware-assisted security |
0.0 | 1 | 2012 | Effective and Efficient Memory Protection Using Dynamic Tainting · IEEE Trans. Computers 2012 |
Hardware reliability and fault tolerance
execution replay |
0.0 | 1 | 2010 | HARE: Hardware assisted reverse execution · HPCA 2010 |
Processor architecture and microarchitecture › pipelining
pipeline design |
0.0 | 1 | 2008 | FlexiTaint: A programmable accelerator for dynamic taint propagation · HPCA 2008 |
Methods — techniques the papers use, named apart from their topics
hardware-assisted implementation · 0.4dynamic tainting · 0.4simulation · 0.2programmable state transition · 0.2taint propagation · 0.2caching · 0.2hardware checkpointing · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2012 | Euripus: A flexible unified hardware memory checkpointing accelerator for bidirectional-debugging and reliabilityabstractBidirectional debugging and error recovery have different goals (programmer productivity and system reliability, respectively), yet they both require the ability to roll-back the program or the system to a past state. This rollback functionality is typically implemented using checkpoints that can restore the system/application to a specific point in time. There are several types of checkpoints, and bidirectional debugging and error-recovery use them in different ways. This paper presents Euripus1, a flexible hardware accelerator for memory checkpointing which can create different combinations of checkpoints needed for bidirectional debugging, error recovery, or both. In particular, Euripus is the first hardware technique to provide consolidation-friendly undo-logs (for bidirectional debugging), to allow simultaneous construction of both undo and redo logs, and to support multi-level checkpointing for the needs of error-recovery. Euripus incurs low performance overheads (;30%, and supports rapid multi-level error recovery that allows >;95% system efficiency even with very high error rates. Ioannis Doudalis, Milos Prvulovic |
ISCA | 1 |
| 2012 | Effective and Efficient Memory Protection Using Dynamic TaintingabstractPrograms written in languages allowing direct access to memory through pointers often contain memory-related faults, which cause nondeterministic failures and security vulnerabilities. We present a new dynamic tainting technique to detect illegal memory accesses. When memory is allocated, at runtime, we taint both the memory and the corresponding pointer using the same taint mark. Taint marks are then propagated and checked every time a memory address m is accessed through a pointer p; if the associated taint marks differ, an illegal access is reported. To allow always-on checking using a low overhead, hardware-assisted implementation, we make several key technical decisions. We use a configurable, low number of reusable taint marks instead of a unique mark for each allocated area of memory, reducing the performance overhead without losing the ability to target most memory-related faults. We also define the technique at the binary level, which helps handle applications using third-party libraries whose source code is unavailable. We created a software-only prototype of our technique and simulated a hardware-assisted implementation. Our results show that 1) it identifies a large class of memory-related faults, even when using only two unique taint marks, and 2) a hardware-assisted implementation can achieve performance overheads in single-digit percentages. Ioannis Doudalis, James Clause, Guru Venkataramani, Milos Prvulovic, Alessandro Orso |
IEEE Trans. Computers | 1 |
| 2010 | HARE: Hardware assisted reverse executionabstractBidirectional execution is a powerful debugging technique that allows program execution to proceed both forward and in reverse. Many software-only techniques and tools have emerged that use checkpointing and replay to provide the effect of reverse execution, although with considerable performance overheads in both forward and reverse execution. Recent hardware proposals for checkpointing and execution replay minimize these performance overheads, but in a way that prevents checkpoint consolidation, a key technique for reducing memory use while retaining the ability to reverse long periods of execution. This paper presents HARE, a hardware technique that efficiently supports both checkpointing and consolidation. Our experiments show that on average HARE incurs <3% performace overheads even when creating tens of checkpoints per second, provides reverse execution times similar to forward execution times, and reduces the total space used by checkpoints by a factor of 36 on average (this factor gets better for longer runs) relative to prior consolidation-less hardware checkpointing schemes. Ioannis Doudalis, Milos Prvulovic |
HPCA | 1 |
| 2009 | MemTracker: An accelerator for memory debugging and monitoringabstractMemory bugs are a broad class of bugs that is becoming increasingly common with increasing software complexity, and many of these bugs are also security vulnerabilities. Existing software and hardware approaches for finding and identifying memory bugs have a number of drawbacks including considerable performance overheads, target only a specific type of bug, implementation cost, and inefficient use of computational resources. This article describes MemTracker, a new hardware support mechanism that can be configured to perform different kinds of memory access monitoring tasks. MemTracker associates each word of data in memory with a few bits of state, and uses a programmable state transition table to react to different events that can affect this state. The number of state bits per word, the events to which MemTracker reacts, and the transition table are all fully programmable. MemTracker's rich set of states, events, and transitions can be used to implement different monitoring and debugging checkers with minimal performance overheads, even when frequent state updates are needed. To evaluate MemTracker, we map three different checkers onto it, as well as a checker that combines all three. For the most demanding (combined) checker with 8 bits state per memory word, we observe performance overheads of only around 3%, on average, and 14.5% worst-case across different benchmark suites. Such low overheads allow continuous (always-on) use of MemTracker-enabled checkers, even in production runs. Guru Venkataramani, Ioannis Doudalis, Yan Solihin, Milos Prvulovic |
ACM Trans. Archit. Code Optim. | 2 |
| 2008 | FlexiTaint: A programmable accelerator for dynamic taint propagationabstractThis paper presents FlexiTaint, a hardware accelerator for dynamic taint propagation. FlexiTaint is implemented as an in-order addition to the back-end of the processor pipeline, and the taints for memory locations are stored as a packed array in regular memory. The taint propagation scheme is specified via a software handler that, given the operation and the sourcespsila taints, computes the new taint for the result. To keep performance overheads low, FlexiTaint caches recent taint propagation lookups and uses a filter to avoid lookups for simple common-case behavior. We also describe how to implement consistent taint propagation in a multi-core environment. Our experiments show that FlexiTaint incurs average performance overheads of only 1% for SPEC2000 benchmarks and 3.7% for Splash-2 benchmarks, even when simultaneously following two different taint propagation policies. Guru Venkataramani, Ioannis Doudalis, Yan Solihin, Milos Prvulovic |
HPCA | 2 |
| 2007 | Effective memory protection using dynamic taintingabstractPrograms written in languages that provide direct access tomemory through pointers often contain memory-related faults, which may cause non-deterministic failures and even security vulnerabilities. In this paper, we present a new technique based on dynamic tainting for protecting programs from illegal memory accesses. When memory is allocated, at runtime, our technique taints both the memory and the corresponding pointer using the same taint mark. Taint marks are then suitably propagated while the program executes and are checked every time a memory address m is accessed through a pointer p; if the taint marks associated with mand p differ, the execution is stopped and the illegalaccess is reported. To allow for a low-overhead, hardware-assisted implementation of the approach, we make several key technical and engineering decisions in the definition of our technique. In particular, we use a configurable, low number of reusable taint marks instead of a unique mark for each area of memory allocated, which reduces the overhead of the approach without limiting its flexibility and ability to target most memory-related faults and attacks known to date. We also define the technique at the binary level, which lets us handle the (very) common case of applications that use third-party libraries whose source code is unavailable. To investigate the effectiveness and practicality of our approach, we implemented it for heap-allocated memory and performed a preliminary empirical study on a set of programs. Our results show that (1) our technique can identify a large class of memory-related faults, even when using only two unique taint marks, and (2)a hardware-assisted implementation of the technique could achieve overhead in the single digits James Clause, Ioannis Doudalis, Alessandro Orso, Milos Prvulovic |
ASE | 2 |