Galen C. Hunt

dblp:58/3811 · DBLP profile ↗
← Back
18ranked-venue papers
6as first author
0since 2021 · last 2015
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 10 · 3 first-authorSoftware engineering, systems software and programming languages · 8 · 2 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1Theory of computation · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
5 papers
Hardware security and side channels · 70% Systems and software security · 30%
Software engineering, system software, and programming languages
7 papers
Operating systems · 82% Debugging and program repair · 9% Software maintenance and evolution · 3%
Computer architecture, parallel and distributed computing, and storage systems
8 papers
Memory systems · 38% Cloud and datacenter computing · 35% Distributed systems · 17%

Topics — the 25 heaviest of 33, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Hardware security and side channels › trusted execution environments
shielded execution
0.422015
Shielding Applications from an Untrusted Cloud with Haven · ACM Trans. Comput. Syst. 2015
Shielding Applications from an Untrusted Cloud with Haven · OSDI 2014
Hardware security and side channels
trusted execution environments
0.422015
Shielding Applications from an Untrusted Cloud with Haven · ACM Trans. Comput. Syst. 2015
Shielding Applications from an Untrusted Cloud with Haven · OSDI 2014
Operating systems › operating system design
library operating systems
0.322013
Composing OS extensions safely and efficiently with Bascule · EuroSys 2013
Rethinking the library OS from the top down · ASPLOS 2011
Systems and software security › data security
confidentiality and integrity
0.212015
Shielding Applications from an Untrusted Cloud with Haven · ACM Trans. Comput. Syst. 2015
Operating systems › system security › operating system security › protection mechanism › isolation
process isolation
0.122007
Sealing OS processes to improve dependability and safety · EuroSys 2007
Language support for fast and reliable message-based communication in singularity OS · EuroSys 2006
Cloud and datacenter computing
virtualization
0.112011
Rethinking the library OS from the top down · ASPLOS 2011
Systems and software security
operating system security
0.122011
Sealing OS processes to improve dependability and safety · EuroSys 2007
Rethinking the library OS from the top down · ASPLOS 2011
Debugging and program repair
fault localization
0.112009
Debugging in the (very) large: ten years of implementation and experience · SOSP 2009
Memory systems › shared memory
distributed shared memory
0.122005
Shared memory computing on clusters with symmetric multiprocessors and system area networks · ACM Trans. Comput. Syst. 2005
VM-Based Shared Memory on Low-Latency, Remote-Memory-Access Networks · ISCA 1997
Memory systems › shared memory › distributed shared memory
software distributed shared memory
0.122005
Shared memory computing on clusters with symmetric multiprocessors and system area networks · ACM Trans. Comput. Syst. 2005
VM-Based Shared Memory on Low-Latency, Remote-Memory-Access Networks · ISCA 1997
Operating systems › i/o › i/o subsystem
device drivers
0.112006
Solving the starting problem: device drivers as self-describing artifacts · EuroSys 2006
Operating systems › resource management
resource contention detection
0.112006
Solving the starting problem: device drivers as self-describing artifacts · EuroSys 2006
Operating systems
resource management
0.112006
Solving the starting problem: device drivers as self-describing artifacts · EuroSys 2006
Cloud and datacenter computing
cloud security
0.112014
Shielding Applications from an Untrusted Cloud with Haven · OSDI 2014
Memory systems › cache coherence
cache coherence protocol
0.112005
Shared memory computing on clusters with symmetric multiprocessors and system area networks · ACM Trans. Comput. Syst. 2005
Memory systems
cache coherence
0.022005
VM-Based Shared Memory on Low-Latency, Remote-Memory-Access Networks · ISCA 1997
Shared memory computing on clusters with symmetric multiprocessors and system area networks · ACM Trans. Comput. Syst. 2005
Software maintenance and evolution
bug triage
0.012009
Debugging in the (very) large: ten years of implementation and experience · SOSP 2009
Embedded and real-time systems › embedded system design
application partitioning
0.011999
The Coign Automatic Distributed Partitioning System · OSDI 1999
Systems and software security › isolation
software isolation
0.012006
Solving the starting problem: device drivers as self-describing artifacts · EuroSys 2006
Program verification
verification
0.012006
Language support for fast and reliable message-based communication in singularity OS · EuroSys 2006
Memory systems › memory consistency › memory consistency model
release consistency
0.011997
VM-Based Shared Memory on Low-Latency, Remote-Memory-Access Networks · ISCA 1997
Memory systems
shared memory
0.011997
Cashmere-2L: Software Coherent Shared Memory on a Clustered Remote-Write Network · SOSP 1997
Interconnection networks and networks-on-chip
cluster interconnect
0.012005
Shared memory computing on clusters with symmetric multiprocessors and system area networks · ACM Trans. Comput. Syst. 2005
Parallel and multicore computing › parallel computing › parallel communication
user-level communication
0.012005
Shared memory computing on clusters with symmetric multiprocessors and system area networks · ACM Trans. Comput. Syst. 2005
High-performance computing
cluster computing
0.011997
Cashmere-2L: Software Coherent Shared Memory on a Clustered Remote-Write Network · SOSP 1997

Methods — techniques the papers use, named apart from their topics

Intel SGX · 0.4hardware enclaves · 0.4system design · 0.4progressive data collection · 0.2error statistics · 0.2bucketing · 0.2user-mode library · 0.2sealing · 0.1application abstraction · 0.1affinity metric · 0.1simulation · 0.1verification techniques · 0.1offline reasoning · 0.1language support · 0.1declarative hardware requirements · 0.1performance measurement · 0.1automatic distributed partitioning · 0.0directory-based coherence · 0.0
YearPublicationVenuePosition
2015 Shielding Applications from an Untrusted Cloud with Haven
abstract
Today’s cloud computing infrastructure requires substantial trust. Cloud users rely on both the provider’s staff and its globally distributed software/hardware platform not to expose any of their private data. We introduce the notion of shielded execution, which protects the confidentiality and integrity of a program and its data from the platform on which it runs (i.e., the cloud operator’s OS, VM, and firmware). Our prototype, Haven, is the first system to achieve shielded execution of unmodified legacy applications, including SQL Server and Apache, on a commodity OS (Windows) and commodity hardware. Haven leverages the hardware protection of Intel SGX to defend against privileged code and physical attacks such as memory probes, and also addresses the dual challenges of executing unmodified legacy binaries and protecting them from a malicious host. This work motivated recent changes in the SGX specification.
Andrew Baumann, Marcus Peinado, Galen C. Hunt
ACM Trans. Comput. Syst.3
2014 Shielding Applications from an Untrusted Cloud with Haven
Andrew Baumann, Marcus Peinado, Galen C. Hunt
OSDI3
2014 Experiences in the land of virtual abstractions
abstract
The Microsoft Research Drawbridge Project began with a simple question: Is it possible to achieve the benefits of hardware virtual machines without the overheads? Following that question, we have built a line of exploratory prototypes. These prototypes range from an ARM-based phone that runs x86 Windows binaries to new forms of secure computation. In this talk, I'll briefly describe our various prototypes and the evidence we have accumulated that our first question can be answered in the affirmative.
Galen C. Hunt
VEE1
2013 Composing OS extensions safely and efficiently with Bascule
abstract
Library OS (LibOS) architectures implement the OS personality as a user-mode library, giving each application the flexibility to choose its LibOS. This approach is appealing for many reasons, not least the ability to extend or customise the LibOS. Recent work with Drawbridge [29] showed that an existing commodity OS (Windows 7) could be refactored to produce a LibOS while retaining application compatibility.
Andrew Baumann, Pedro Fonseca 0001, Lisa Glendenning, Jacob R. Lorch, Barry Bond, Reuben Olinsky, Galen C. Hunt
EuroSys8
2011 Rethinking the library OS from the top down
abstract
This paper revisits an old approach to operating system construc-tion, the library OS, in a new context. The idea of the library OS is that the personality of the OS on which an application depends runs in the address space of the application. A small, fixed set of abstractions connects the library OS to the host OS kernel, offering the promise of better system security and more rapid independent evolution of OS components.
Donald E. Porter, Silas Boyd-Wickizer, Jon Howell, Reuben Olinsky, Galen C. Hunt
ASPLOS5
2010 User experiences with activity-based navigation on mobile devices
abstract
We introduce activity-based navigation, which uses human activities derived from sensor data to help people navigate, in particular to retrace a "trail" previously taken by that person or another person. Such trails may include step counts, walking up/down stairs or taking elevators, compass directions, and photos taken along a user's path, in addition to absolute positioning (GPS and maps) when available. To explore the user experience of activity-based navigation, we built Greenfield, a mobile device interface for finding a car. We conducted a ten participant user study comparing users' ability to find cars across three different presentations of activity-based information as well as verbal instructions. Our results show that activity-based navigation can be used for car finding and suggest its promise more generally for supporting navigation tasks. We present lessons for future activity-based navigation interfaces, and motivate further work in this space, particularly in the area of robust activity inference.
A. J. Bernheim Brush, Amy K. Karlson, James Scott, Raman Sarin, Andy Jacobs, Barry Bond, Oscar Murillo, Galen C. Hunt, Mike Sinclair, Kerry Hammil, Steven Levi
Mobile HCI8
2010 Looking beyond a singularity
abstract
How does one build a truly dependable software system? Seven years ago, Microsoft Research started the Singularity project to answer this question. The premise was to start with the best known software development tools and to build a new kind of operating system from the ground up. The operating system was to be both an output artifact and a laboratory for the research. Portions of the code and ideas have been incorporated into three separate Microsoft operating systems so far. I will give a brief overview of Singularity planned and built, then describe what we learned, both positive and negative. I will speculate on OS futures including current research to build an operating system in which every last assembly instruction has been verified for type safety, a system for truly mobile computation, and new tools for automatically restructuring large software systems.
Galen C. Hunt
VEE1
2009 Debugging in the (very) large: ten years of implementation and experience
abstract
Windows Error Reporting (WER) is a distributed system that automates the processing of error reports coming from an installed base of a billion machines. WER has collected billions of error reports in ten years of operation. It collects error data automatically and classifies errors into buckets, which are used to prioritize developer effort and report fixes to users. WER uses a progressive approach to data collection, which minimizes overhead for most reports yet allows developers to collect detailed information when needed. WER takes advantage of its scale to use error statistics as a tool in debugging; this allows developers to isolate bugs that could not be found at smaller scale. WER has been designed for large scale: one pair of database servers can record all the errors that occur on all Windows computers worldwide.
Kirk Glerum, Kinshuman Kinshumann, Steve Greenberg, Gabriel Aul, Vince R. Orgovan, Greg Nichols, David Grant, Gretchen Loihle, Galen C. Hunt
SOSP9
2009 Helios: heterogeneous multiprocessing with satellite kernels
abstract
Helios is an operating system designed to simplify the task of writing, deploying, and tuning applications for heterogeneous platforms. Helios introduces satellite kernels, which export a single, uniform set of OS abstractions across CPUs of disparate architectures and performance characteristics. Access to I/O services such as file systems are made transparent via remote message passing, which extends a standard microkernel message-passing abstraction to a satellite kernel infrastructure. Helios retargets applications to available ISAs by compiling from an intermediate language. To simplify deploying and tuning application performance, Helios exposes an affinity metric to developers. Affinity provides a hint to the operating system about whether a process would benefit from executing on the same platform as a service it depends upon.
Ed Nightingale, Orion Hodson, Ross McIlroy, Chris Hawblitzel, Galen C. Hunt
SOSP5
2007 Sealing OS processes to improve dependability and safety
abstract
In most modern operating systems, a process is a hardware-protected abstraction for isolating code and data. This protection, however, is selective. Many common mechanisms---dynamic code loading, run-time code generation, shared memory, and intrusive system APIs---make the barrier between processes very permeable. This paper argues that this traditional open process architecture exacerbates the dependability and security weaknesses of modern systems.
Galen C. Hunt, Mark Aiken, Manuel Fähndrich, Chris Hawblitzel, Orion Hodson, James R. Larus, Steven Levi, Bjarne Steensgaard, David Tarditi, Ted Wobber
EuroSys1
2006 Language support for fast and reliable message-based communication in singularity OS
abstract
Message-based communication offers the potential benefits of providing stronger specification and cleaner separation between components. Compared with shared-memory interactions, message passing has the potential disadvantages of more expensive data exchange (no direct sharing) and more complicated programming.In this paper we report on the language, verification, and run-time system features that make messages practical as the sole means of communication between processes in the Singularity operating system. We show that using advanced programming language and verification techniques, it is possible to provide and enforce strong system-wide invariants that enable efficient communication and low-overhead software-based process isolation. Furthermore, specifications on communication channels help in detecting programmer mistakes early---namely at compile-time---thereby reducing the difficulty of the message-based programming model.The paper describes our communication invariants, the language and verification features that support them, as well as implementation details of the infrastructure. A number of benchmarks show the competitiveness of this approach.
Manuel Fähndrich, Mark Aiken, Chris Hawblitzel, Orion Hodson, Galen C. Hunt, James R. Larus, Steven Levi
EuroSys5
2006 Solving the starting problem: device drivers as self-describing artifacts
abstract
Run-time conflicts can affect even the most rigorously tested software systems. A reliance on execution-based testing makes it prohibitively costly to test every possible interaction among potentially thousands of programs with complex configurations. In order to reduce configuration problems, detect developer errors, and reduce developer effort, we have created a new first class operating system abstraction, the application abstraction, which enables both online and offline reasoning about programs and their configuration requirements.We have implemented a subset of the application abstraction for device drivers in the Singularity operating system. Programmers use the application abstraction by placing declarative statements about hardware and communication requirements within their code. Our design enables Singularity to learn the input/output and interprocess communication requirements of drivers without executing driver code. By reasoning about this information within the domain of Singularity's strong software isolation architecture, the installer can execute a subset the system's resource management algorithm at install time to verify that a new driver will not conflict with existing software. This abstract representation also allows the system to run the full algorithm at driver start time to ensure that there are never resource conflicts between executing drivers, and that drivers never use undeclared resources.
Michael F. Spear, Tom Roeder, Orion Hodson, Galen C. Hunt, Steven Levi
EuroSys4
2005 Broad New OS Research: Challenges and Opportunities
Galen C. Hunt, James R. Larus, David Tarditi, Ted Wobber
HotOS1
2005 Shared memory computing on clusters with symmetric multiprocessors and system area networks
abstract
Cashmere is a software distributed shared memory (S-DSM) system designed for clusters of server-class machines. It is distinguished from most other S-DSM projects by (1) the effective use of fast user-level messaging, as provided by modern system-area networks, and (2) a “two-level” protocol structure that exploits hardware coherence within multiprocessor nodes. Fast user-level messages change the tradeoffs in coherence protocol design; they allow Cashmere to employ a relatively simple directory-based coherence protocol. Exploiting hardware coherence within SMP nodes improves overall performance when care is taken to avoid interference with inter-node software coherence.We have implemented Cashmere on a Compaq AlphaServer/Memory Channel cluster, an architecture that provides fast user-level messages. Experiments indicate that a one-level, version of the Cashmere protocol provides performance comparable to, or slightly better than, that of TreadMarks' lazy release consistency. Comparisons to Compaq's Shasta protocol also suggest that while fast user-level messages make finer-grain software DSMs competitive, VM-based systems continue to outperform software-based access control for applications without extensive fine-grain sharing.Within the family of Cashmere protocols, we find that leveraging intranode hardware coherence provides a 37% performance advantage over a more straightforward one-level implementation. Moreover, contrary to our original expectations, noncoherent hardware support for remote memory writes, total message ordering, and broadcast, provide comparatively little in the way of additional benefits over just fast messaging for our application suite.
Leonidas I. Kontothanassis, Robert Stets, Galen C. Hunt, Umit Rencuzogullari, Gautam Altekar, Sandhya Dwarkadas, Michael L. Scott
ACM Trans. Comput. Syst.3
1999 The Coign Automatic Distributed Partitioning System
Galen C. Hunt, Michael L. Scott
OSDI1
1997 VM-Based Shared Memory on Low-Latency, Remote-Memory-Access Networks
abstract
Recent technological advances have produced network interfaces that provide users with very low-latency access to the memory of remote machines. We examine the impact of such networks on the implementation and performance of software DSM. Specifically, we compare two DSM systems---Cashmere and TreadMarks---on a 32-processor DEC Alpha cluster connected by a Memory Channel network.Both Cashmere and TreadMarks use virtual memory to maintain coherence on pages, and both use lazy, multi-writer release consistency. The systems differ dramatically, however, in the mechanisms used to track sharing information and to collect and merge concurrent updates to a page, with the result that Cashmere communicates much more frequently, and at a much finer grain.Our principal conclusion is that low-latency networks make DSM based on fine-grain communication competitive with more coarse-grain approaches, but that further hardware improvements will be needed before such systems can provide consistently superior performance. In our experiments, Cashmere scales slightly better than TreadMarks for applications with false sharing. At the same time, it is severely constrained by limitations of the current Memory Channel hardware. In general, performance is better for TreadMarks.
Leonidas I. Kontothanassis, Galen C. Hunt, Robert Stets, Nikos Hardavellas, Michal Cierniak, Srinivasan Parthasarathy 0001, Wagner Meira Jr., Sandhya Dwarkadas, Michael L. Scott
ISCA2
1997 Cashmere-2L: Software Coherent Shared Memory on a Clustered Remote-Write Network
abstract
Low-latency remote-write networks, such as DEC's Memory Channel, provide the possibility of transparent, inexpensive, huge-scale shared-memory parallel computing on clusters of shared memory multiprocessors (SMPs).The challenge is to take advantage of hardwaresharedmemoryfor sharing within an SMI: and to ensure that software overheadis incurredonly when actively sharing data across SMPs in the cluster.In this paper, we describe a 'Ywolevel" software coherent shared memory system-Cashmere-2Lthat meets this challenge.CashmereSL uses hardware to share memory within a node, while exploiting the Memory Channel's remote-write capabilities to implement "moderately lazy" release consistency with multiple concurrent writers, directories, home nodes, and page-size coherence blocks across nodes.Cashmere-2L employs a novel coherence protocol that allows a high level of asynchrony by eliminating global directory locks and the needfor TLB shootdown.Remote interrupts are minimized by exploiting the remote-write capabilities of the Memory Channel network Cashmere-2L currently runs on an &node, 32-processor DEC AlphaServersystem.Speedups rangefrom 8 to 31 on 32processors for our benchmark suite, depending on the application's characteristics.We quanhfi the importance of ourprotocol optimizations by comparing perjormance to that of several alternative protocols that do not share memory in hardware within an SMP, and require more synchronization.In comparison to a one-level protocol that does not share memory in hardware within an SMP Cashmere-2L improves performance by up to 46%.
Robert Stets, Sandhya Dwarkadas, Nikos Hardavellas, Galen C. Hunt, Leonidas I. Kontothanassis, Srinivasan Parthasarathy 0001, Michael L. Scott
SOSP4
1996 An Efficient Algorithm for Concurrent Priority Queue Heaps
abstract
We present a new algorithm for concurrent access to array-based priority queue heaps. Deletions proceed top-down as they do in a previous algorithm due to Rao and Kumar (1988), but insertions proceed bottom-up, and consecutive insertions use a bit-reversal technique to scatter accesses across the fringe of the tree, to reduce contention. Because insertions do not have to traverse the entire height of the tree (as they do in previous work), as many as O(M) operations can proceed in parallel, rather than O(log M) on a heap of size M. Experimental results on a Silicon Graphics Challenge multiprocessor demonstrate good overall performance for the new algorithm on small heaps, and significant performance improvements over known alternatives on large heaps with mixed insertion/deletion workloads.
Galen C. Hunt, Maged M. Michael, Srinivasan Parthasarathy 0001, Michael L. Scott
Inf. Process. Lett.1