EDBT 2026 Demo / reviewers in the wild / expert
Chad Verbowski
dblp:78/2444
· DBLP profile ↗
14ranked-venue papers
5as first author
0since 2021 · last 2018
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 9 · 4 first-authorSecurity and privacy · 5Software engineering, systems software and programming languages · 2 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
4 papers |
Software maintenance and evolution · 65% Operating systems · 35% | |
| Network and information security
3 papers |
Malware analysis · 31% Web and mobile security · 24% Systems and software security · 24% | |
| Computer architecture, parallel and distributed computing, and storage systems
2 papers |
Distributed systems · 62% Cloud and datacenter computing · 38% |
Topics — the 11 heaviest of 14, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Software maintenance and evolution › software configuration management
configuration-error detection |
0.1 | 1 | 2011 | Context-based Online Configuration-Error Detection · USENIX ATC 2011 |
Software maintenance and evolution
software configuration management |
0.1 | 1 | 2011 | Context-based Online Configuration-Error Detection · USENIX ATC 2011 |
Malware analysis
rootkit |
0.1 | 1 | 2006 | SubVirt: Implementing malware with virtual machines · S&P 2006 |
Operating systems
system administration |
0.1 | 1 | 2006 | Flight Data Recorder: Monitoring Persistent-State Interactions to Improve Systems Management · OSDI 2006 |
Distributed systems
fault tolerance |
0.1 | 1 | 2006 | Flight Data Recorder: Monitoring Persistent-State Interactions to Improve Systems Management · OSDI 2006 |
Authentication and access control › access control
least privilege |
0.1 | 1 | 2005 | A Black-Box Tracing Technique to Identify Causes of Least-Privilege Incompatibilities · NDSS 2005 |
Operating systems › system administration
system configuration |
0.0 | 1 | 2011 | Context-based Online Configuration-Error Detection · USENIX ATC 2011 |
Malware analysis › web-based malware
drive-by downloads |
0.0 | 1 | 2006 | Automated Web Patrol with Strider HoneyMonkeys: Finding Web Sites That Exploit Browser Vulnerabilities · NDSS 2006 |
Cloud and datacenter computing
virtualization |
0.0 | 1 | 2006 | SubVirt: Implementing malware with virtual machines · S&P 2006 |
Cloud and datacenter computing › virtualization
virtual machine monitor |
0.0 | 1 | 2006 | SubVirt: Implementing malware with virtual machines · S&P 2006 |
Operating systems › system security › operating system security
access control |
0.0 | 1 | 2005 | A Black-Box Tracing Technique to Identify Causes of Least-Privilege Incompatibilities · NDSS 2005 |
Methods — techniques the papers use, named apart from their topics
virtualization · 0.2proof-of-concept implementation · 0.2context-based detection · 0.1black-box tracing · 0.1automated web patrol · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2018 | Right-Sizing Server Capacity Headroom for Global Online ServicesabstractWe present a capacity planning case study showing a significant opportunity for improving the utilization of a large, low-latency, highly available online service containing 100K+ servers spanning 9 geographic regions. Analyzing 30 PB of traces over 90 days we devised a new iterative black-box capacity planning model using the discovered relationships between workload, utilization, and quality. We verified the model on 1,000s of servers showing capacity reductions between 20% and 40% with effectively no impact on workload latency, availability, or the capacity required for disaster recovery. These results are confirmed experimentally by shrinking production server pools to cause the remaining servers to run at higher utilization, and using data from real-world large scale unplanned failures. Finally, we show examples of using our model for offline regression analysis to detect critical issues before their deployment. Chad Verbowski, Ed Thayer, Paolo Costa, Hugh Leather, Björn Franke |
ICDCS | 1 |
| 2011 | Context-based Online Configuration-Error Detection
Yinglian Xie, Rina Panigrahy, Chad Verbowski, Arunvijay Kumar |
USENIX ATC | 4 |
| 2006 | System Administration: Drowning in Management Complexity
Chad Verbowski |
LISA | 1 |
| 2006 | LiveOps: Systems Management as a Service
Chad Verbowski, Juhan Lee, Roussi Roussev, Yi-Min Wang |
LISA | 1 |
| 2006 | Automated Web Patrol with Strider HoneyMonkeys: Finding Web Sites That Exploit Browser Vulnerabilities
Yi-Min Wang, Doug Beck, Xuxian Jiang, Roussi Roussev, Chad Verbowski, Samuel T. King |
NDSS | 5 |
| 2006 | Flight Data Recorder: Monitoring Persistent-State Interactions to Improve Systems Management
Chad Verbowski, Emre Kiciman, Arunvijay Kumar, Brad Daniels, Shan Lu 0001, Juhan Lee, Yi-Min Wang, Roussi Roussev |
OSDI | 1 |
| 2006 | SubVirt: Implementing malware with virtual machinesabstractAttackers and defenders of computer systems both strive to gain complete control over the system. To maximize their control, both attackers and defenders have migrated to low-level, operating system code. In this paper, we assume the perspective of the attacker, who is trying to run malicious software and avoid detection. By assuming this perspective, we hope to help defenders understand and defend against the threat posed by a new class of rootkits. We evaluate a new type of malicious software that gains qualitatively more control over a system. This new type of malware, which we call a virtual-machine based rootkit (VMBR), installs a virtual-machine monitor underneath an existing operating system and hoists the original operating system into a virtual machine. Virtual-machine based rootkits are hard to detect and remove because their state cannot be accessed by software running in the target system. Further, VMBRs support general-purpose malicious services by allowing such services to run in a separate operating system that is protected from the target system. We evaluate this new threat by implementing two proof-of-concept VMBRs. We use our proof-of-concept VMBRs to subvert Windows XP and Linux target systems, and we implement four example malicious services using the VMBR platform. Last, we use what we learn from our proof-of-concept VMBRs to explore ways to defend against this new threat. We discuss possible ways to detect and prevent VMBRs, and we implement a defense strategy suitable for protecting systems against this threat Samuel T. King, Peter M. Chen, Yi-Min Wang, Chad Verbowski, Helen J. Wang, Jacob R. Lorch |
S&P | 4 |
| 2005 | Detecting Stealth Software with Strider GhostBusterabstractStealth malware programs that silently infect enterprise and consumer machines are becoming a major threat to the future of the Internet. Resource hiding is a powerful stealth technique commonly used by malware to evade detection by computer users and anti-malware scanners. In this paper, we focus on a subclass of malware, termed "ghostware", which hide files, configuration settings, processes, and loaded modules from the operating system's query and enumeration application programming interfaces (APIs). Instead of targeting individual stealth implementations, we describe a systematic framework for detecting multiple types of hidden resources by leveraging the hiding behavior as a detection mechanism. Specifically, we adopt a cross-view diff-based approach to ghostware detection by comparing a high-level infected scan with a low-level clean scan and alternatively comparing an inside-the-box infected scan with an outside-the-box clean scan. We describe the design and implementation of the Strider GhostBuster tool and demonstrate its efficiency and effectiveness in detecting resources hidden by real-world malware such as rootkits, Trojans, and key-loggers. Yi-Min Wang, Doug Beck, Binh Vo, Roussi Roussev, Chad Verbowski |
DSN | 5 |
| 2005 | A Black-Box Tracing Technique to Identify Causes of Least-Privilege Incompatibilities
John Dunagan, Chad Verbowski, Yi-Min Wang |
NDSS | 3 |
| 2004 | Experience Talk: FDR: A Flight Data Recorder Using Black-BoxAnalysis of Persistent State Changes for Managing Change and Configuration
Chad Verbowski, John Dunagan, Brad Daniels, Yi-Min Wang |
LISA | 1 |
| 2004 | Gatekeeper: Monitoring Auto-Start Extensibility Points (ASEPs) for Spyware Management
Yi-Min Wang, Roussi Roussev, Chad Verbowski, Aaron Johnson 0001, Yennun Huang, Sy-Yen Kuo |
LISA | 3 |
| 2004 | Strider: a black-box, state-based approach to change and configuration management and support
Yi-Min Wang, Chad Verbowski, John Dunagan, Helen J. Wang, Chun Yuan 0004, Zheng Zhang 0001 |
Sci. Comput. Program. | 2 |
| 2003 | Persistent-State Checkpoint Comparison for Troubleshooting Configuration Failuresabstract© 2003 IEEE. Personal use of this material is permitted. However, permission to reprint/republish this material for advertising or promotional purposes or for creating new collective works for resale or redistribution to servers or lists, or to reuse any copyrighted component of this work in other works must be obtained from the IEEE. Yi-Min Wang, Chad Verbowski, Daniel R. Simon |
DSN | 2 |
| 2003 | STRIDER: A Black-box, State-based Approach to Change and Configuration Management and Support
Yi-Min Wang, Chad Verbowski, John Dunagan, Helen J. Wang, Chun Yuan 0004, Zheng Zhang 0001 |
LISA | 2 |