Scott M. Baker

dblp:64/2569 · DBLP profile ↗
← Back
8ranked-venue papers
5as first author
0since 2021 · last 2008
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 3 · 3 first-authorSoftware engineering, systems software and programming languages · 2 · 1 first-authorSystems, architecture and hardware · 1Security and privacy · 1Databases, data management, data science and information retrieval · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Systems and software security · 50% Network security · 50%
Software engineering, system software, and programming languages
1 paper
Software maintenance and evolution · 100%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Cloud and datacenter computing · 77% Distributed systems · 23%

Topics — the 6 heaviest of 7, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network security › attack strategy
man-in-the-middle attack
0.112008
A look in the mirror: attacks on package managers · CCS 2008
Systems and software security
software supply chain security
0.112008
A look in the mirror: attacks on package managers · CCS 2008
Software maintenance and evolution › software ecosystems
package repositories
0.012008
A look in the mirror: attacks on package managers · CCS 2008
Software maintenance and evolution › software configuration management › software release management
software deployment
0.012008
A look in the mirror: attacks on package managers · CCS 2008
Cloud and datacenter computing › datacenter services › online service systems › internet services
web server architecture
0.011999
Scalable Web Server Design for Distributed Data Management · ICDE 1999
Distributed systems
distributed data processing
0.011999
Scalable Web Server Design for Distributed Data Management · ICDE 1999

Methods — techniques the papers use, named apart from their topics

security mechanism analysis · 0.2mirror exploitation · 0.2load adaptation · 0.0concurrent request handling · 0.0
YearPublicationVenuePosition
2008 A look in the mirror: attacks on package managers
abstract
This work studies the security of ten popular package managers. These package managers use different security mechanisms that provide varying levels of usability and resilience to attack. We find that, despite their existing security mechanisms, all of these package managers have vulnerabilities that can be exploited by a man-in-the-middle or a malicious mirror. While all current package managers suffer from vulnerabilities, their security is also positively or negatively impacted by the distribution's security practices. Weaknesses in package managers are more easily exploited when distributions use third-party mirrors as official mirrors. We were successful in using false credentials to obtain an official mirror on all five of the distributions we attempted. We also found that some security mechanisms that control where a client obtains metadata and packages from may actually decrease security. We analyze current package managers to show that by exploiting vulnerabilities, an attacker with a mirror can compromise or crash hundreds to thousands of clients weekly. The problems we disclose are now being corrected by many different package manager maintainers.
Justin Cappos, Justin Samuel, Scott M. Baker, John H. Hartman
CCS3
2007 Stork: Package Management for Distributed VM Environments
Justin Cappos, Scott M. Baker, Jeremy Plichta, Duy Nguyen 0002, Jason Hardies, Matt Borgard, Jeffry Johnston, John H. Hartman
LISA2
2006 Customizing the swarm storage system using agents
abstract
Abstract Swarm is a scalable, modular storage system that uses agents to customize low‐level storage functions to meet the needs of high‐level services. Agents influence low‐level storage functions such as data layout, metadata management, and crash recovery. An agent is a program that is attached to data in the storage system and invoked when events occur during the data's lifetime. For example, before Swarm writes data to disk, agents attached to the data are invoked to determine a layout policy. Agents are typically persistent, remaining attached to the data they manage until the data are deleted; this allows agents to continue to affect how the data are handled long after the application or storage service that created the data has terminated. In this paper, we present Swarm's agent architecture, describe the types of agents that Swarm supports and the infrastructure used to support them, and discuss their performance overhead and security implications. We describe how several storage services and applications use agents, and the benefits they derive from doing so. Copyright © 2005 John Wiley & Sons, Ltd.
John H. Hartman, Scott M. Baker, Ian Murdock
Softw. Pract. Exp.2
2004 The Mirage NFS Router
abstract
Mirage aggregates multiple NFS (network file system) servers into a single, virtual NFS file server. It is interposed between the NFS clients and servers, making the clients believe that they are communicating with a single, large server. Mirage is an NFS router because it routes an NFS request from a client to the proper NFS server, and routes the reply back to the proper client. Experiments with a Mirage prototype show that Mirage effectively virtualizes an NFS server using unmodified clients and servers. Mirage imposes a negligible overhead on a realistic NFS workload. On real world workloads, such as a collection of clients executing compile jobs over NFS, Mirage imposes an overhead of 3% as compared to a proxy that simply forwards packets.
Scott M. Baker, John H. Hartman
LCN1
2001 The design and implementation of the Gecko NFS Web proxy
abstract
Abstract The World Wide Web uses a naming scheme (URLs), transfer protocol (HTTP), and cache algorithms that are different from traditional network file systems. This makes it impossible for unmodified Unix applications to access the Web; as a result, the Web is only accessible to special Web‐enabled applications. Gecko bridges the gap between Web‐enabled applications and conventional applications, allowing any unmodified Unix application to access the Web. We developed two prototypes of the Gecko system at the University of Arizona and incorporated the many lessons learned from the first into the second. Minimizing the amount of state was a key goal of the Gecko redesign and the second prototype uses a unique compression technique to reduce server state. Experiments performed on the prototype show that Gecko not only makes the Web accessible to unmodified applications, but does so at a performance that meets or exceeds that of HTTP. Copyright © 2001 John Wiley & Sons, Ltd.
Scott M. Baker, John H. Hartman
Softw. Pract. Exp.1
1999 Scalable Web Server Design for Distributed Data Management
abstract
With the explosive popularity of the internet and the world wide web (WWW), there is a rapidly growing need to provide unprecedented access to globally distributed data sources through the internet. Web accessibility will be an essential component of the services that future digital libraries should provide for clients. This need has created a strong demand for database access capability through the internet, and high performance scalable web servers. As most popular web sites are experiencing overload from an increasing number of users accessing the sites at the same time, it is desired that scalable web servers should adapt to the changing access characteristics and should be capable of handling a large number of concurrent requests simultaneously, with reasonable response times and minimal request drop rates.
Scott M. Baker, Bongki Moon
ICDE1
1999 The Gecko NFS Web Proxy
Scott M. Baker, John H. Hartman
Comput. Networks1
1999 Distributed Cooperative Web Servers
Scott M. Baker, Bongki Moon
Comput. Networks1