EDBT 2026 Demo / reviewers in the wild / expert
Hari Kannan
dblp:72/6493
· DBLP profile ↗
7ranked-venue papers
2as first author
0since 2021 · last 2009
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 5 · 2 first-authorSecurity and privacy · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 2
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
4 papers |
Systems and software security · 85% Hardware security and side channels · 15% | |
| Software engineering, system software, and programming languages
3 papers |
Program analysis · 33% Runtime systems and virtual machines · 29% Concurrent programming · 29% | |
| Computer architecture, parallel and distributed computing, and storage systems
2 papers |
Parallel and multicore computing · 57% Hardware accelerators and domain-specific architectures · 43% |
Topics — the 13 heaviest of 14, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Program analysis
dynamic analysis |
0.1 | 1 | 2009 | Ordering decoupled metadata accesses in multiprocessors · MICRO 2009 |
Parallel and multicore computing
multiprocessor system |
0.1 | 1 | 2009 | Ordering decoupled metadata accesses in multiprocessors · MICRO 2009 |
Systems and software security › memory safety › memory corruption defense
buffer overflow protection |
0.1 | 1 | 2008 | Real-World Buffer Overflow Protection for Userspace and Kernelspace · USENIX Security Symposium 2008 |
Systems and software security
memory safety |
0.1 | 1 | 2008 | Real-World Buffer Overflow Protection for Userspace and Kernelspace · USENIX Security Symposium 2008 |
Systems and software security › memory safety › hardware-enforced memory safety
memory tagging |
0.1 | 1 | 2008 | Hardware Enforcement of Application Security Policies Using Tagged Memory · OSDI 2008 |
Runtime systems and virtual machines › binary translation
dynamic binary translation |
0.1 | 1 | 2008 | Thread-safe dynamic binary translation using transactional memory · HPCA 2008 |
Concurrent programming
transactional memory |
0.1 | 1 | 2008 | Thread-safe dynamic binary translation using transactional memory · HPCA 2008 |
Systems and software security › information flow tracking
dynamic information flow tracking |
0.1 | 1 | 2007 | Raksha: a flexible information flow architecture for software security · ISCA 2007 |
Hardware security and side channels
hardware information flow tracking |
0.1 | 1 | 2007 | Raksha: a flexible information flow architecture for software security · ISCA 2007 |
Hardware accelerators and domain-specific architectures
security accelerator |
0.1 | 1 | 2007 | Raksha: a flexible information flow architecture for software security · ISCA 2007 |
Systems and software security › trusted computing
trusted execution |
0.0 | 1 | 2008 | Hardware Enforcement of Application Security Policies Using Tagged Memory · OSDI 2008 |
Operating systems › system security › operating system security
kernel security |
0.0 | 1 | 2008 | Real-World Buffer Overflow Protection for Userspace and Kernelspace · USENIX Security Symposium 2008 |
Systems and software security › vulnerability discovery
software vulnerability detection |
0.0 | 1 | 2007 | Raksha: a flexible information flow architecture for software security · ISCA 2007 |
Methods — techniques the papers use, named apart from their topics
decoupled metadata processing · 0.3FPGA prototype · 0.1software transactions · 0.1dynamic information flow tracking · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2009 | Decoupling Dynamic Information Flow Tracking with a dedicated coprocessorabstractDynamic information flow tracking (DIFT) is a promising security technique. With hardware support, DIFT prevents a wide range of attacks on vulnerable software with minimal performance impact. DIFT architectures, however, require significant changes in the processor pipeline that increase design and verification complexity and may affect clock frequency. These complications deter hardware vendors from supporting DIFT. This paper makes hardware support for DIFT cost effective by decoupling DIFT functionality onto a simple, separate coprocessor. Decoupling is possible because DIFT operations and regular computation need only synchronize on system calls. The coprocessor is a small hardware engine that performs logical operations and caches 4-bit tags. It introduces no changes to the design or layout of the main processor's logic, pipeline, or caches, and can be combined with various processors. Using a full-system hardware prototype and realistic Linux workloads, we show that the DIFT coprocessor provides the same security guarantees as current DIFT architectures with low runtime overheads. Hari Kannan, Michael Dalton, Christoforos E. Kozyrakis |
DSN | 1 |
| 2009 | Ordering decoupled metadata accesses in multiprocessorsabstractHardware support for dynamic analysis can minimize the performance overhead of useful applications such as security checks, debugging, and profiling. To eliminate implementation complexity and improve flexibility, recent hardware proposals have decoupled the processing of the metadata needed for analysis from the application running on the main processor core. However, such decoupling can lead to inconsistencies between application data and analysis metadata in multiprocessor systems. If updates to data and metadata occur in different orders, the analysis can be rendered incorrect, leading to issues such as undetected security attacks or unnecessary program termination. Hari Kannan |
MICRO | 1 |
| 2008 | Thread-safe dynamic binary translation using transactional memoryabstractDynamic binary translation (DBT) is a runtime instrumentation technique commonly used to support profiling, optimization, secure execution, and bug detection tools for application binaries. However, DBT frameworks may incorrectly handle multithreaded programs due to races involving updates to the application data and the corresponding metadata maintained by the DBT. Existing DBT frameworks handle this issue by serializing threads, disallowing multithreaded programs, or requiring explicit use of locks. This paper presents a practical solution for correct execution of multithreaded programs within DBT frameworks. To eliminate races involving metadata, we propose the use of transactional memory (TM). The DBT uses memory transactions to encapsulate the data and metadata accesses in a trace, within one atomic block. This approach guarantees correct execution of concurrent threads of the translated program, as TM mechanisms detect and correct races. To demonstrate this approach, we implemented a DBT-based tool for secure execution of x86 binaries using dynamic information flow tracking. This is the first such framework that correctly handles multithreaded binaries without serialization. We show that the use of software transactions in the DBT leads to a runtime overhead of 40%. We also show that software optimizations in the DBT and hardware support for transactions can reduce the runtime overhead to 6%. JaeWoong Chung, Michael Dalton, Hari Kannan, Christoforos E. Kozyrakis |
HPCA | 3 |
| 2008 | Hardware Enforcement of Application Security Policies Using Tagged Memory
Nickolai Zeldovich, Hari Kannan, Michael Dalton, Christoforos E. Kozyrakis |
OSDI | 2 |
| 2008 | Real-World Buffer Overflow Protection for Userspace and Kernelspace
Michael Dalton, Hari Kannan, Christoforos E. Kozyrakis |
USENIX Security Symposium | 2 |
| 2007 | qTLB: Looking Inside the Look-Aside Buffer
Omesh Tickoo, Hari Kannan, Vineet Chadha, Ramesh Illikkal, Ravi R. Iyer 0001, Donald Newell |
HiPC | 2 |
| 2007 | Raksha: a flexible information flow architecture for software securityabstractHigh-level semantic vulnerabilities such as SQL injection and crosssite scripting have surpassed buffer overflows as the most prevalent security exploits. The breadth and diversity of software vulnerabilities demand new security solutions that combine the speed and practicality of hardware approaches with the flexibility and robustness of software systems.This paper proposes Raksha, an architecture for software security based on dynamic information flow tracking (DIFT). Raksha provides three novel features that allow for a flexible hardware/software approach to security. First, it supports flexible and programmable security policies that enable software to direct hardware analysis towards a wide range of high-level and low-level attacks. Second, it supports multiple active security policies that can protect the system against concurrent attacks. Third, it supports low-overhead security handlers that allow software to correct, complement, or extend the hardware-based analysis without the overhead associated with operating system traps.We present an FPGA prototype for Raksha that provides a full featured Linux workstation for security analysis. Using unmodified binaries for real-world applications, we demonstrate that Raksha can detect high-level attacks such as directory traversal, command injection, SQL injection, and cross-site scripting as well as low-level attacks such as buffer overflows. We also show that low overhead exception handling is critical for analyses such as memory corruption protection in order to address false positives that occur due to the diverse code patterns in frequently used software. Michael Dalton, Hari Kannan, Christoforos E. Kozyrakis |
ISCA | 2 |