Karthick Jayaraman

dblp:63/7057 · DBLP profile ↗
← Back
14ranked-venue papers
5as first author
3since 2021 · last 2023
0009-0005-9502-9360ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 7 · 1 first-author · 3 since 2021Security and privacy · 5 · 3 first-authorSystems, architecture and hardware · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer networks
5 papers
Network management and operations · 92% Routing and switching · 4% Network performance modeling · 3%
Computer architecture, parallel and distributed computing, and storage systems
2 papers
Cloud and datacenter computing · 100%
Network and information security
2 papers
Authentication and access control · 57% Web and mobile security · 29% Systems and software security · 14%
Software engineering, system software, and programming languages
2 papers
Software testing · 100%

Topics — the 19 heaviest of 21, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network management and operations
network verification
1.132021
Test coverage metrics for the network · SIGCOMM 2021
Validating datacenters at scale · SIGCOMM 2019
Checking Beliefs in Dynamic Networks · NSDI 2015
Network management and operations
configuration verification
0.822023
Lightyear: Using Modularity to Scale BGP Control Plane Verification · SIGCOMM 2023
Finding Network Misconfigurations by Automatic Template Inference · NSDI 2020
Network management and operations › network verification
control plane verification
0.712023
Lightyear: Using Modularity to Scale BGP Control Plane Verification · SIGCOMM 2023
Cloud and datacenter computing
cloud networking
0.712023
Invisinets: Removing Networking from Cloud Networks · NSDI 2023
Network management and operations
network configuration
0.522020
Finding Network Misconfigurations by Automatic Template Inference · NSDI 2020
Checking Beliefs in Dynamic Networks · NSDI 2015
Software testing
test coverage
0.512021
Test coverage metrics for the network · SIGCOMM 2021
Network management and operations › configuration verification
misconfiguration detection
0.412020
Finding Network Misconfigurations by Automatic Template Inference · NSDI 2020
Routing and switching › inter-domain routing
BGP
0.212023
Lightyear: Using Modularity to Scale BGP Control Plane Verification · SIGCOMM 2023
Network management and operations › configuration verification
BGP configuration verification
0.212023
Lightyear: Using Modularity to Scale BGP Control Plane Verification · SIGCOMM 2023
Cloud and datacenter computing
cloud infrastructure
0.212023
Invisinets: Removing Networking from Cloud Networks · NSDI 2023
Network performance modeling
network reliability
0.112021
Test coverage metrics for the network · SIGCOMM 2021
Authentication and access control
access control
0.112011
Automatic error finding in access-control policies · CCS 2011
Authentication and access control › access control
policy verification
0.112011
Automatic error finding in access-control policies · CCS 2011
Authentication and access control › access control
role-based access control
0.112011
Automatic error finding in access-control policies · CCS 2011
Cloud and datacenter computing › datacenter network
datacenter network operations
0.112019
Validating datacenters at scale · SIGCOMM 2019
Web and mobile security › web security
cross-site scripting
0.112009
Automatic creation of SQL Injection and cross-site scripting attacks · ICSE 2009
Systems and software security › exploitation › injection attacks
SQL injection
0.112009
Automatic creation of SQL Injection and cross-site scripting attacks · ICSE 2009
Web and mobile security
web application vulnerability
0.112009
Automatic creation of SQL Injection and cross-site scripting attacks · ICSE 2009
Software testing › non-functional testing
security testing
0.012009
Automatic creation of SQL Injection and cross-site scripting attacks · ICSE 2009

Methods — techniques the papers use, named apart from their topics

formal methods · 0.8automated theorem proving · 0.8modular verification · 0.7template inference · 0.4model checking · 0.1abstraction refinement · 0.1
YearPublicationVenuePosition
2023 Invisinets: Removing Networking from Cloud Networks
Sarah McClure, Zeke Medley, Deepak Bansal, Karthick Jayaraman, Ashok Narayanan, Jitendra Padhye, Sylvia Ratnasamy, Anees Shaikh, Rishabh Tewari
NSDI4
2023 Lightyear: Using Modularity to Scale BGP Control Plane Verification
abstract
Current network control plane verification tools cannot scale to large networks because of the complexity of jointly reasoning about the behaviors of all network nodes. We present a modular approach to control plane verification, where end-to-end network properties are verified via a set of purely local checks on individual nodes and edges. The approach targets verification of reachability properties for BGP configurations, and provides guarantees in the face of arbitrary external route announcements and, for some properties, arbitrary node/link failures. We have proven the approach correct and implemented it in a tool Lightyear. Experimentally we show Lightyear scales dramatically better than prior control plane verifiers. Further, Lightyear has been used for six months to verify properties of a major cloud provider network containing hundreds of routers and tens of thousands of edges, finding and fixing bugs in the process. To our knowledge no prior control-plane verification tool has been shown to scale to that size and complexity. Our modular approach also makes it easy to localize configuration errors and enables incremental re-verification.
Alan Tang, Ryan Beckett, Steven Benaloh, Karthick Jayaraman, Tejas Patil, Todd D. Millstein, George Varghese
SIGCOMM4
2021 Test coverage metrics for the network
abstract
Testing and verification have emerged as key tools in the battle to improve the reliability of networks and the services they provide. However, the success of even the best technology of this sort is limited by how effectively it is applied, and in today's enormously complex industrial networks, it is surprisingly easy to overlook particular interfaces, routes, or flows when creating a test suite. Moreover, network engineers, unlike their software counterparts, have no help to battle this problem—there are no metrics or systems to compute the quality of their test suites or the extent to which their networks have been verified.
Xieyang Xu, Ryan Beckett, Karthick Jayaraman, Ratul Mahajan, David Walker 0001
SIGCOMM3
2020 Finding Network Misconfigurations by Automatic Template Inference
Siva Kesava Reddy K., Alan Tang, Ryan Beckett, Karthick Jayaraman, Todd D. Millstein, Yuval Tamir, George Varghese
NSDI4
2019 Validating datacenters at scale
abstract
We describe our experiences using formal methods and automated theorem proving for network operation at scale. The experiences are based on developing and applying the SecGuru and RCDC (Reality Checker for Data Centers) tools in Azure. SecGuru has been used since 2013 and thus, is arguably a pioneering industrial deployment of network verification. SecGuru is used for validating ACLs and more recently RCDC checks forwarding tables at Azure scale. A central technical angle is that we use local contracts and local checks, that can be performed at scale in parallel, and without maintaining global snapshots, to validate global properties of datacenter networks. Specifications leverage declarative encodings of configurations and automated theorem proving for validation. We describe how intent is automatically derived from network architectures and verification is incorporated as prechecks for making changes, live monitoring, and for evolving legacy policies. We document how network verification, grounded in architectural constraints, can be integral to operating a reliable cloud at scale.
Karthick Jayaraman, Nikolaj S. Bjørner, Jitendra Padhye, Amar Agrawal, Ashish Bhargava, Paul-Andre C. Bissonnette, Shane Foster, Andrew Helwer, Mark Kasten, Anup Namdhari, Haseeb Niaz, Aniruddha Parkhi, Hanukumar Pinnamraju, Adrian Power, Neha Milind Raje, Parag Sharma
SIGCOMM1
2015 Checking Beliefs in Dynamic Networks
Nuno P. Lopes, Nikolaj S. Bjørner, Patrice Godefroid, Karthick Jayaraman, George Varghese
NSDI4
2014 Banking on interoperability: Secure, interoperable credential management
Glenn S. Benson, Shiu-Kai Chin, Sean Croston, Karthick Jayaraman, Susan Older
Comput. Networks4
2013 Mohawk: Abstraction-Refinement and Bound-Estimation for Verifying Access Control Policies
abstract
Verifying that access-control systems maintain desired security properties is recognized as an important problem in security. Enterprise access-control systems have grown to protect tens of thousands of resources, and there is a need for verification to scale commensurately. We present techniques for abstraction-refinement and bound-estimation for bounded model checkers to automatically find errors in Administrative Role-Based Access Control (ARBAC) security policies. ARBAC is the first and most comprehensive administrative scheme for Role-Based Access Control (RBAC) systems. In the abstraction-refinement portion of our approach, we identify and discard roles that are unlikely to be relevant to the verification question (the abstraction step). We then restore such abstracted roles incrementally (the refinement steps). In the bound-estimation portion of our approach, we lower the estimate of the diameter of the reachability graph from the worst-case by recognizing relationships between roles and state-change rules. Our techniques complement one another, and are used with conventional bounded model checking. Our approach is sound and complete: an error is found if and only if it exists. We have implemented our technique in an access-control policy analysis tool called Mohawk . We show empirically that Mohawk scales well to realistic policies, and provide a comparison with prior tools.
Karthick Jayaraman, Mahesh Tripunitara, Vijay Ganesh 0001, Martin C. Rinard, Steve J. Chapin
ACM Trans. Inf. Syst. Secur.1
2011 Automatic error finding in access-control policies
abstract
Verifying that access-control systems maintain desired security properties is recognized as an important problem in security. Enterprise access-control systems have grown to protect tens of thousands of resources, and there is a need for verification to scale commensurately. We present a new abstraction-refinement technique for automatically finding errors in Administrative Role-Based Access Control (ARBAC) security policies. ARBAC is the first and most comprehensive administrative scheme for Role-Based Access Control (RBAC) systems. Underlying our approach is a change in mindset: we propose that error finding complements verification, can be more scalable, and allows for the use of a wider variety of techniques. In our approach, we use an abstraction-refinement technique to first identify and discard roles that are unlikely to be relevant to the verification question (the abstraction step), and then restore such abstracted roles incrementally (the refinement steps). Errors are one-sided: if there is an error in the abstracted policy, then there is an error in the original policy. If there is an error in a policy whose role-dependency graph diameter is smaller than a certain bound, then we find the error. Our abstraction-refinement technique complements conventional state-space exploration techniques such as model checking. We have implemented our technique in an access-control policy analysis tool. We show empirically that our tool scales well to realistic policies, and is orders of magnitude faster than prior tools.
Karthick Jayaraman, Vijay Ganesh 0001, Mahesh Tripunitara, Martin C. Rinard, Steve J. Chapin
CCS1
2011 Re-designing the Web's Access Control System - (Extended Abstract)
Wenliang Du 0001, Tongbo Luo, Karthick Jayaraman, Zutao Zhu
DBSec4
2011 Position paper: why are there so many vulnerabilities in web applications?
abstract
As the Web has become more and more ubiquitous, the number of attacks on web applications have increased substantially. According to a recent report, over 80 percent of web applications have had at least one serious vulnerability. This percentage is alarmingly higher than traditional applications. Something must be fundamentally wrong in the web infrastructure.
Wenliang Du 0001, Karthick Jayaraman, Tongbo Luo, Steve J. Chapin
NSPW2
2010 Enforcing Request Integrity in Web Applications
Karthick Jayaraman, Grzegorz Lewandowski, Paul G. Talaga, Steve J. Chapin
DBSec1
2010 ESCUDO: A Fine-Grained Protection Model for Web Browsers
abstract
Web applications are no longer simple hyperlinked documents. They have progressively evolved to become highly complex-web pages combine content from several sources (with varying levels of trustworthiness), and incorporate significant portions of client-side code. However, the prevailing web protection model, the same-origin policy, has not adequately evolved to manage the security consequences of this additional complexity. As a result, web applications have become attractive targets of exploitation. We argue that this disconnection between the protection needs of modern web applications and the protection models used by web browsers that manage those applications amounts to a failure of access control. In this paper, we present Escudo, a new web browser protection model designed based on established principles of mandatory access control. We describe our implementation of a prototype of Escudo in the Lobo web browser, and illustrate how web applications can use Escudo for securing their resources. Our evaluation results indicate that Escudo incurs low overhead. To support backwards compatibility, Escudo defaults to the same-origin policy for legacy applications.
Karthick Jayaraman, Wenliang Du 0001, Balamurugan Rajagopalan, Steve J. Chapin
ICDCS1
2009 Automatic creation of SQL Injection and cross-site scripting attacks
abstract
We present a technique for finding security vulnerabilities in Web applications. SQL Injection (SQLI) and cross-site scripting (XSS) attacks are widespread forms of attack in which the attacker crafts the input to the application to access or modify user data and execute malicious code. In the most serious attacks (called second-order, or persistent, XSS), an attacker can corrupt a database so as to cause subsequent users to execute malicious code.
Adam Kiezun, Philip J. Guo, Karthick Jayaraman, Michael D. Ernst
ICSE3