EDBT 2026 Demo / reviewers in the wild / expert
Nikos Vasilakis
dblp:70/2619
· DBLP profile ↗
31ranked-venue papers
8as first author
22since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 14 · 4 first-author · 10 since 2021Security and privacy · 7 · 3 first-author · 6 since 2021Computer networks · 6 · 3 since 2021Systems, architecture and hardware · 5 · 1 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Fractal: Fault-Tolerant Shell-Script Distribution
Ramiz Dundar, Yizheng Xie, Konstantinos Kallas, Nikos Vasilakis |
NSDI | 5 |
| 2026 | Slowpoke: End-to-end Throughput Optimization Modeling for Microservice Applications
Yizheng Xie, Di Jin 0004, Oguzhan Çölkesen, Vasiliki Kalavri, John Liagouris, Nikos Vasilakis |
NSDI | 6 |
| 2025 | From Ahead-of- to Just-in-Time and Back Again: Static Analysis for Unix Shell ProgramsabstractShell programming is as prevalent as ever. It is also quite complex, due to the structure of shell programs, their use of opaque software components, and their complex interactions with the broader environment. As a result, even when exercising an abundance of care, shell developers discover devastating bugs in their programs only at runtime: at best, shell programs going wrong crash the execution of a long-running task; at worst, they silently corrupt the broader environment in which they execute---affecting user data, modifying system files, and rendering entire systems unusable. Could the shell's users enjoy the benefits of semantics-driven static analysis before their programs' execution---as offered by most other production languages? Lukas Lazarek, Seong-Heon Jung, Evangelos Lamprou, Anirudh Narsipur, Eric Zhao 0006, Michael Greenberg 0002, Konstantinos Kallas, Konstantinos Mamouras, Nikos Vasilakis |
HotOS | 10 |
| 2025 | KLean: Extending Operating System Kernels with LeanabstractSafe kernel extension is an extremely successful feature in OS kernels with a plethora of interesting applications. It provides significant performance benefits by avoiding context switching and data copying, without compromising the kernel's integrity due to its verifiable safety. The most mature existing approach, namely BPF, verifies extension safety using sound abstract interpretation techniques with best effort precision. Such design not only increases the kernel maintenance burden due to its complexity, but also restricts extension expressiveness due to its approximations. The core of the problem, we argue, is the BPF verifier's dual mandate of precision and soundness in its safety analysis. Di Jin 0004, Ethan Lavi, Jinghao Jia, Robert Y. Lewis, Nikos Vasilakis |
PLOS@SOSP | 5 |
| 2025 | Towards Hybrid Cooperative-Preemptive SchedulingabstractCooperative scheduling avoids the many shared-state pitfalls of preemption, but risks fairness---in the limit resulting in denial of service and resource exhaustion. This paper argues that a careful hybrid between cooperation and preemption is both feasible and advantageous: by allowing only carefully controlled and developer-configurable preemption in an otherwise cooperative environment, the scheduler can maintain key invariants while restoring fairness. The paper presents a series of case-study workloads that motivate the need for preemption in real-world cooperative environments, sketches a hybrid design that introduces controlled preemption while maintaining cooperation benefits, and discusses the benefits by applying this hybrid design on the case-study workloads. A hybrid scheduling implementation, Cx, is in progress. Yizheng Xie, Di Jin 0004, Nikos Vasilakis |
PLOS@SOSP | 3 |
| 2025 | The Koala Benchmarks for the Shell: Characterization and Implications
Evangelos Lamprou, Ethan Williams, Georgios Kaoukis, Zhuoxuan Zhang, Michael Greenberg 0002, Konstantinos Kallas, Lukas Lazarek, Nikos Vasilakis |
USENIX ATC | 8 |
| 2023 | BinWrap: Hybrid Protection against Native Node.js Add-onsabstractModern applications, written in high-level programming languages, enjoy the security benefits of memory and type safety. Unfortunately, even a single memory-unsafe library can wreak havoc on the rest of an otherwise safe application, nullifying all the security guarantees offered by the high-level language and its managed runtime. We perform a study across the Node.js ecosystem to understand the use patterns of binary add-ons. Taking the identified trends into account, we propose a new hybrid permission model aimed at protecting both a binary add-on and its language-specific wrapper. The permission model is applied all around a native add-on and is enforced through a hybrid language-binary scheme that interposes on accesses to sensitive resources from all parts of the native library. We infer the add-on’s permission set automatically over both its binary and JavaScript sides, via a set of novel program analyses. Applied to a wide variety of native add-ons, we show that our framework, BinWrap, reduces access to sensitive resources, defends against real-world exploits, and imposes an overhead that ranges between 0.71%–10.4%. George Christou, Grigoris Ntousakis, Eric Lahtinen, Sotiris Ioannidis, Vasileios P. Kemerlis, Nikos Vasilakis |
AsiaCCS | 6 |
| 2023 | Executing Shell Scripts in the Wrong Order, CorrectlyabstractShell scripts are critical infrastructure for developers, administrators, and scientists; and ought to enjoy the performance benefits of the full suite of advances in compiler optimizations. But between the shell's inherent challenges and neglect from the community, shell tooling and performance lags far behind the state of the art. We propose executing scripts out-of-order to better use modern computational resources. Optimizing any part of an arbitrary shell script is very challenging: the shell language's complex, late-bound semantics makes extensive use of opaque external commands with arbitrary side effects. Georgios Liargkovas, Konstantinos Kallas, Michael Greenberg 0002, Nikos Vasilakis |
HotOS | 4 |
| 2023 | SecBench.js: An Executable Security Benchmark Suite for Server-Side JavaScriptabstractNPM is the largest software ecosystem in the world, offering millions of free, reusable packages. In recent years, various security threats to packages published on npm have been reported, including vulnerabilities that affect millions of users. To continuously improve techniques for detecting vulnerabilities and mitigating attacks that exploit them, a reusable benchmark of vulnerabilities would be highly desirable. Ideally, such a benchmark should be realistic, come with executable exploits, and include fixes of vulnerabilities. Unfortunately, there currently is no such benchmark, forcing researchers to repeatedly develop their own evaluation datasets and making it difficult to compare techniques with each other. This paper presents SecBench.js,, the first comprehensive benchmark suite of vulnerabilities and executable exploits for npm. The benchmark comprises 600 vulnerabilities, which cover the five most common vulnerability classes for server-side JavaScript. Each vulnerability comes with a payload that exploits the vulnerability and an oracle that validates successful exploitation. SecBench.js, enables various applications, of which we explore three in this paper: (i) cross-checking SecBench.js, against public security advisories reveals 168 vulnerable versions in 19 packages that are mislabeled in the advisories; (ii) applying simple code transformations to the exploits in our suite helps identify flawed fixes of vulnerabilities; (iii) dynamically analyzing calls to common sink APIs, e.g., exec(), yields a ground truth of code locations for evaluating vulnerability detectors. Beyond providing a reusable benchmark to the community, our work identified 20 zero-day vulnerabilities, most of which are already acknowledged by practitioners. Masudul Hasan Masud Bhuiyan, Adithya Srinivas Parthasarathy, Nikos Vasilakis, Michael Pradel, Cristian-Alexandru Staicu |
ICSE | 3 |
| 2023 | DiSh: Dynamic Shell-Script Distribution
Tammam Mustafa, Konstantinos Kallas, Pratyush Das 0001, Nikos Vasilakis |
NSDI | 4 |
| 2022 | Themis: A Secure Decentralized Framework for Microservice Interaction in Serverless ComputingabstractIn serverless computing, applications are composed of stand-alone microservices that are invoked and scale up independently. Peer-to-peer protocols can be used to enable decentralized communication among the services that compose each application. This paper presents Themis, a framework for secure service-to-service interaction targeting these environments and the underlying service mesh architectures. Themis builds on a notion of decentralized identity management to allow confidential and authenticated service-to-service interaction without the need for a centralized certificate authority. Themis adopts a layered architecture. Its lower layer forms a core communication protocol pair that offers strong security guarantees without depending on a centralized point of authority. Building on this pair, an upper layer provides a series of actions related to communication and identifier management—e.g., store, find, and join. This paper analyzes the security properties of Themis’s protocol suite and shows how it provides a decentralized and flexible communication platform. The evaluation of our Themis prototype targeting serverless applications written in JavaScript shows that these security benefits come with small runtime latency and throughput overheads, and modest startup overheads. Angeliki Aktypi, Dimitris Karnikis, Nikos Vasilakis, Kasper Bonne Rasmussen |
ARES | 3 |
| 2022 | Towards Practical Application-level Support for Privilege SeparationabstractPrivilege separation (privsep) is an effective technique for improving software’s security, but privsep involves decomposing software into components and assigning them different privileges. This is often laborious and error-prone. This paper contributes the following for applying privsep to C software: (1) a portable, lightweight, and distributed runtime library that abstracts externally-enforced compartment isolation; (2) an abstract compartmentalization model of software for reasoning about privsep; and (3) a privsep-aware Clang-based tool for code analysis and semi-automatic software transformation to use the runtime library. The evaluation spans 19 compartmentalizations of third-party software and examines: Security: 4 CVEs in widely-used software were rendered unexploitable; Approximate Effort Saving: on average, the synthesis-to-annotation code ratio was greater than 11.9 (i.e., 10 × lines of code were generated for each annotation); and Overhead: execution-time overhead was less than 2%, and memory overhead was linear in the number of compartments. Nik Sultana, Henry Zhu, Ke Zhong, Zhilei Zheng, Ruijie Mao, Digvijaysinh Chauhan, Stephen Carrasquillo, Junyong Zhao, Lei Shi 0011, Nikos Vasilakis, Boon Thau Loo |
ACSAC | 10 |
| 2022 | Practically Correct, Just-in-Time Shell Script Parallelization
Konstantinos Kallas, Tammam Mustafa, Jan Bielak, Dimitris Karnikis, Thurston H. Y. Dang, Michael Greenberg 0002, Nikos Vasilakis |
OSDI | 7 |
| 2022 | Automatic synthesis of parallel unix commands and pipelines with KumQuatabstractWe present KumQuat, a system for automatically generating data-parallel implementations of Unix shell commands and pipelines. The generated parallel versions split input streams, execute multiple instantiations of the original pipeline commands to process the splits in parallel, then combine the resulting parallel outputs to produce the final output stream. KumQuat automatically synthesizes the combine operators, with a domain-specific combiner language acting as a strong regularizer that promotes efficient inference of correct combiners. We present experimental results that show that these combiners enable the effective parallelization of our benchmark scripts. Jiasi Shen 0001, Martin C. Rinard, Nikos Vasilakis |
PPoPP | 3 |
| 2021 | Demo: Detecting Third-Party Library Problems with Combined Program AnalysisabstractThird-party libraries ease the software development process and thus have become an integral part of modern software engineering. Unfortunately, they are not usually vetted by human developers and thus are often responsible for introducing bugs, vulnerabilities, or attacks to programs that will eventually reach end-users. In this demonstration, we present a combined static and dynamic program analysis for inferring and enforcing third-party library permissions in server-side JavaScript. This analysis is centered around a RWX permission system across library boundaries. We demonstrate that our tools can detect zero-day vulnerabilities injected into popular libraries and often missed by state-of-the-art tools such as snyk test and npm audit. Grigoris Ntousakis, Sotiris Ioannidis, Nikos Vasilakis |
CCS | 3 |
| 2021 | Supply-Chain Vulnerability Elimination via Active Learning and RegenerationabstractSoftware supply-chain attacks target components that are integrated into client applications. Such attacks often target widely-used components, with the attack taking place via operations (for example, file system or network accesses) that do not affect those aspects of component behavior that the client observes. We propose new active library learning and regeneration (ALR) techniques for inferring and regenerating the client-observable behavior of software components. Using increasingly sophisticated rounds of exploration, ALR generates inputs, provides these inputs to the component, and observes the resulting outputs to infer a model of the component's behavior as a program in a domain-specific language. We present Harp, an ALR system for string processing components. We apply Harp to successfully infer and regenerate string-processing components written in JavaScript and C/C++. Our results indicate that, in the majority of cases, Harp completes the regeneration in less than a minute, remains fully compatible with the original library, and delivers performance indistinguishable from the original library. We also demonstrate that Harp can eliminate vulnerabilities associated with libraries targeted in several highly visible security incidents, specifically event-stream, left-pad, and string-compare. Nikos Vasilakis, Achilleas Benetopoulos, Shivam Handa, Alizee Schoen, Jiasi Shen 0001, Martin C. Rinard |
CCS | 1 |
| 2021 | Preventing Dynamic Library Compromise on Node.js via RWX-Based Privilege ReductionabstractThird-party libraries ease the development of large-scale software systems. However, libraries often execute with significantly more privilege than needed to complete their task. Such additional privilege is sometimes exploited at runtime via inputs passed to a library, even when the library itself is not actively malicious. We present Mir, a system addressing dynamic compromise by introducing a fine-grained read-write-execute (RWX) permission model at the boundaries of libraries: every field of every free variable name in the context of an imported library is governed by a permission set. To help specify the permissions given to existing code, Mir's automated inference generates default permissions by analyzing how libraries are used by their clients. Applied to over 1,000 JavaScript libraries for Node.js, Mir shows practical security (61/63 attacks mitigated), performance (2.1s for static analysis and +1.93% for dynamic enforcement), and compatibility (99.09%) characteristics---and enables a novel quantification of privilege reduction. Nikos Vasilakis, Cristian-Alexandru Staicu, Grigoris Ntousakis, Konstantinos Kallas, Ben Karel, André DeHon, Michael Pradel |
CCS | 1 |
| 2021 | PaSh: light-touch data-parallel shell processingabstractThis paper presents PaSh, a system for parallelizing POSIX shell scripts. Given a script, PaSh converts it to a dataflow graph, performs a series of semantics-preserving program transformations that expose parallelism, and then converts the dataflow graph back into a script---one that adds POSIX constructs to explicitly guide parallelism coupled with PaSh-provided Unix-aware runtime primitives for addressing performance- and correctness-related issues. A lightweight annotation language allows command developers to express key parallelizability properties about their commands. An accompanying parallelizability study of POSIX and GNU commands---two large and commonly used groups---guides the annotation language and optimized aggregator library that PaSh uses. PaSh's extensive evaluation over 44 unmodified Unix scripts shows significant speedups (0.89--61.1×, avg: 6.7×) stemming from the combination of its program transformations and runtime primitives. Nikos Vasilakis, Konstantinos Kallas, Konstantinos Mamouras, Achilleas Benetopoulos, Lazar Cvetkovich |
EuroSys | 1 |
| 2021 | The future of the shell: Unix and beyondabstractThe Unix shell is fifty years old, and it continues to be the primary way to configure, deploy, and manage systems of all kinds. What do the next fifty years hold? What is the command-line interface of the 21st century? Michael Greenberg 0002, Konstantinos Kallas, Nikos Vasilakis |
HotOS | 3 |
| 2021 | Unix shell programming: the next 50 yearsabstractThe Unix shell is a powerful, ubiquitous, and reviled tool for managing computer systems. The shell has been largely ignored by academia and industry. While many replacement shells have been proposed, the Unix shell persists. Two recent threads of formal and practical research on the shell enable new approaches. We can help manage the shell's essential shortcomings (dynamism, power, and abstruseness) and address its inessential ones. Improving the shell holds much promise for development, ops, and data processing. Michael Greenberg 0002, Konstantinos Kallas, Nikos Vasilakis |
HotOS | 3 |
| 2021 | Efficient module-level dynamic analysis for dynamic languages with module recontextualizationabstractDynamic program analysis is a long-standing technique for obtaining information about program execution. We present module recontextualization, a new dynamic analysis approach that targets modern dynamic languages such as JavaScript and Racket, enabled by the fact that they feature a module-import mechanism that loads code at runtime as a string. This approach uses lightweight load-time code transformations that operate on the string representation of the module, as well as the context to which it is about to be bound, to insert developer-provided, analysis-specific code into the module before it is loaded. This code implements the dynamic analysis, enabling this approach to capture all interactions around the module in unmodified production language runtime environments. We implement this approach in two systems targeting the JavaScript and Racket ecosystems. Our evaluation shows that this approach can deliver order-of-magnitude performance improvements over state-of-the-art dynamic analysis systems while supporting a range of analyses, implemented on average in about 100 lines of code. Nikos Vasilakis, Grigoris Ntousakis, Veit Heller, Martin C. Rinard |
ESEC/SIGSOFT FSE | 1 |
| 2021 | An order-aware dataflow model for parallel Unix pipelinesabstractWe present a dataflow model for modelling parallel Unix shell pipelines. To accurately capture the semantics of complex Unix pipelines, the dataflow model is order-aware, i.e., the order in which a node in the dataflow graph consumes inputs from different edges plays a central role in the semantics of the computation and therefore in the resulting parallelization. We use this model to capture the semantics of transformations that exploit data parallelism available in Unix shell computations and prove their correctness. We additionally formalize the translations from the Unix shell to the dataflow model and from the dataflow model back to a parallel shell script. We implement our model and transformations as the compiler and optimization passes of a system parallelizing shell pipelines, and use it to evaluate the speedup achieved on 47 pipelines. Shivam Handa, Konstantinos Kallas, Nikos Vasilakis, Martin C. Rinard |
Proc. ACM Program. Lang. | 3 |
| 2019 | TMC: Pay-as-you-Go Distributed CommunicationabstractWe revisit the gap between what distributed systems need from the transport layer and what protocols in wide deployment provide. Such a gap complicates the implementation of distributed systems and impacts their performance. We introduce Tunable Multicast Communication (TMC), an abstraction that allows developers to easily specialize communication channels in distributed systems. TMC is presented as a deployable and extensible user-space library that exposes high-level tunable guarantees. TMC has the potential of improving the performance of distributed applications with minimal-to-zero development and deployment effort. Henri Maxime Demoulin, Nikos Vasilakis, John Sonchack, Isaac Pedisich, Vincent Liu 0001, Boon Thau Loo, Linh T. X. Phan, Jonathan M. Smith, Irene Zhang |
APNet | 2 |
| 2019 | Ignis: scaling distribution-oblivious systems with light-touch distributionabstractDistributed systems offer notable benefits over their centralized counterparts. Reaping these benefits, however, requires burdensome developer effort to identify and rewrite bottlenecked components. Light-touch distribution is a new approach that converts a legacy system into a distributed one using automated transformations. Transformations operate at the boundaries of bottlenecked modules and are parametrizable by light distribution recipes that guide the intended semantics of the resulting distribution. Transformations and recipes operate at runtime, adapting to load by scaling out only saturated components. Our Ignis prototype shows substantial speedups, attractive elasticity characteristics, and memory gains over full replication, achieved by small and backward-compatible code changes. Nikos Vasilakis, Ben Karel, Yash Palkhiwala, John Sonchack, André DeHon, Jonathan M. Smith |
PLDI | 1 |
| 2019 | Detecting Asymmetric Application-layer Denial-of-Service Attacks In-Flight with Finelame
Henri Maxime Demoulin, Isaac Pedisich, Nikos Vasilakis, Vincent Liu 0001, Boon Thau Loo, Linh T. X. Phan |
USENIX ATC | 3 |
| 2018 | BreakApp: Automated, Flexible Application Compartmentalization
Nikos Vasilakis, Ben Karel, Nick Roessler, Nathan Dautenhahn, André DeHon, Jonathan M. Smith |
NDSS | 1 |
| 2017 | Towards Fine-grained, Automated Application CompartmentalizationabstractThe rise of language-specific, third-party packages simplifies application development. However, relying on untrusted code poses a threat to security and reliability. Nikos Vasilakis, Ben Karel, Nick Roessler, Nathan Dautenhahn, André DeHon, Jonathan M. Smith |
PLOS@SOSP | 1 |
| 2015 | Architectural Support for Software-Defined Metadata ProcessingabstractOptimized hardware for propagating and checking software-programmable metadata tags can achieve low runtime overhead. We generalize prior work on hardware tagging by considering a generic architecture that supports software-defined policies over metadata of arbitrary size and complexity; we introduce several novel microarchitectural optimizations that keep the overhead of this rich processing low. Our model thus achieves the efficiency of previous hardware-based approaches with the flexibility of the software-based ones. We demonstrate this by using it to enforce four diverse safety and security policies---spatial and temporal memory safety, taint tracking, control-flow integrity, and code and data separation---plus a composite policy that enforces all of them simultaneously. Experiments on SPEC CPU2006 benchmarks with a PUMP-enhanced RISC processor show modest impact on runtime (typically under 10%) and power ceiling (less than 10%), in return for some increase in energy usage (typically under 60%) and area for on-chip memory structures (110%). Udit Dhawan, Catalin Hritcu, Raphael Rubin, Nikos Vasilakis, Silviu Chiricescu, Jonathan M. Smith, Thomas F. Knight Jr., Benjamin C. Pierce, André DeHon |
ASPLOS | 4 |
| 2015 | From Lone Dwarfs to Giant Superclusters: Rethinking Operating System Abstractions for the Cloud
Nikos Vasilakis, Ben Karel, Jonathan M. Smith |
HotOS | 1 |
| 2008 | A software platform for developing multi-player pervasive games using small programmable object technologiesabstractIn this paper we present a platform for developing mobile, locative and collaborative distributed games comprised of small programmable object technologies (e.g., wireless sensor networks) and traditional networked processors. The platform is implemented using a combination of JAVA Standard and Mobile editions, targeting also mobile phones that have some kind of sensors installed. We briefly present the architecture of our platform and demonstrate its capabilities by reporting two pervasive multiplayer games. The key characteristic of these games is that players interact with each other and their surrounding environment by moving, running and gesturing as a means to perform game related actions, using small programmable object technologies. Orestis Akribopoulos, Dimitrios Bousis, Dionysios Efstathiou, Haris Koutsouridis, Marios Logaras, Andreas Loukas, Alexandros Nafas, George C. Oikonomou, Irini Thireou, Nikos Vasilakis, Panagiotis C. Kokkinos, Georgios Mylonas, Ioannis Chatzigiannakis |
MASS | 10 |
| 2008 | Using wireless sensor networks to develop pervasive multi-player gamesabstractIn this work we present two mobile, locative and collaborative distributed games that are played using wireless sensor devices. We briefly present the architecture of the two games and demonstrate their capabilities. The key characteristic of these games is that players interact with each other and their surrounding environment by moving, running and gesturing as a means to perform game related actions, using sensor devices. We demonstrate our system's implementation, which uses a combination of JAVA Standard and Mobile editions. Orestis Akribopoulos, Marios Logaras, Nikos Vasilakis, Panagiotis C. Kokkinos, Georgios Mylonas, Ioannis Chatzigiannakis |
SenSys | 3 |