Owen S. Hofmann

dblp:80/77 · DBLP profile ↗
← Back
14ranked-venue papers
3as first author
0since 2021 · last 2016
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 9 · 3 first-authorSystems, architecture and hardware · 8 · 3 first-authorSecurity and privacy · 2

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
6 papers
Systems and software security · 44% Authentication and access control · 23% Malware analysis · 13%
Software engineering, system software, and programming languages
9 papers
Operating systems · 51% Concurrent programming · 49%
Computer architecture, parallel and distributed computing, and storage systems
7 papers
Cloud and datacenter computing · 36% Parallel and multicore computing · 34% Distributed systems · 13%

Topics — the 30 heaviest of 33, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security › trusted computing
trusted execution
0.422016
Sego: Pervasive Trusted Metadata for Efficiently Verified Untrusted System Services · ASPLOS 2016
InkTag: secure applications on an untrusted operating system · ASPLOS 2013
Concurrent programming
concurrency control
0.222012
Improving server applications with system transactions · EuroSys 2012
Operating systems transactions · SOSP 2009
Authentication and access control
access control
0.212014
Application-Defined Decentralized Access Control · USENIX ATC 2014
Authentication and access control › access control › distributed access control
decentralized access control
0.212014
Application-Defined Decentralized Access Control · USENIX ATC 2014
Concurrent programming
transactional memory
0.222010
Is transactional programming actually easier? · PPoPP 2010
TxLinux: using and managing hardware transactional memory in an operating system · SOSP 2007
Concurrent programming › transactional memory
hardware transactional memory
0.222009
Maximum benefit from a minimal HTM · ASPLOS 2009
TxLinux: using and managing hardware transactional memory in an operating system · SOSP 2007
Operating systems › kernel › kernel design
kernel synchronization
0.222009
Maximum benefit from a minimal HTM · ASPLOS 2009
MetaTM//TxLinux: transactional memory for an operating system · ISCA 2007
Concurrent programming
synchronization
0.222009
Maximum benefit from a minimal HTM · ASPLOS 2009
TxLinux: using and managing hardware transactional memory in an operating system · SOSP 2007
Systems and software security › operating system security
untrusted operating system
0.212013
InkTag: secure applications on an untrusted operating system · ASPLOS 2013
Operating systems › virtualization
hypervisor
0.212013
InkTag: secure applications on an untrusted operating system · ASPLOS 2013
Operating systems
virtualization
0.212013
InkTag: secure applications on an untrusted operating system · ASPLOS 2013
Cloud and datacenter computing
datacenter storage
0.112012
Flat Datacenter Storage · OSDI 2012
Systems and software security › operating system security
kernel integrity
0.112011
Ensuring operating system kernel integrity with OSck · ASPLOS 2011
Malware analysis
malware detection evasion
0.112011
Cloaking Malware with the Trusted Platform Module · USENIX Security Symposium 2011
Systems and software security
operating system security
0.112011
Ensuring operating system kernel integrity with OSck · ASPLOS 2011
Malware analysis
rootkit detection
0.112011
Ensuring operating system kernel integrity with OSck · ASPLOS 2011
Hardware security and side channels
trusted execution environments
0.112011
Cloaking Malware with the Trusted Platform Module · USENIX Security Symposium 2011
Hardware security and side channels › trusted execution environments
trusted platform module
0.112011
Cloaking Malware with the Trusted Platform Module · USENIX Security Symposium 2011
Network security
anonymity networks
0.112010
Defeating Vanish with Low-Cost Sybil Attacks Against Large DHTs · NDSS 2010
Parallel and multicore computing
transactional memory
0.122009
MetaTM//TxLinux: transactional memory for an operating system · ISCA 2007
Maximum benefit from a minimal HTM · ASPLOS 2009
Concurrent programming
atomicity
0.112009
Operating systems transactions · SOSP 2009
Operating systems › resource management › storage management › file systems
file system verification
0.112016
Sego: Pervasive Trusted Metadata for Efficiently Verified Untrusted System Services · ASPLOS 2016
Operating systems › resource management › process management
CPU scheduling
0.112007
TxLinux: using and managing hardware transactional memory in an operating system · SOSP 2007
Parallel and multicore computing › transactional memory
hardware transactional memory
0.112007
MetaTM//TxLinux: transactional memory for an operating system · ISCA 2007
Authentication and access control › access control models
attribute-based access control
0.012013
InkTag: secure applications on an untrusted operating system · ASPLOS 2013
Cloud and datacenter computing › cluster resource management and scheduling
cluster resource management
0.012012
Flat Datacenter Storage · OSDI 2012
Processor architecture and microarchitecture
chip multiprocessor
0.012010
Is transactional programming actually easier? · PPoPP 2010
Distributed systems › peer-to-peer systems
distributed hash table
0.012010
Defeating Vanish with Low-Cost Sybil Attacks Against Large DHTs · NDSS 2010
Distributed systems › distributed system security
sybil attacks
0.012010
Defeating Vanish with Low-Cost Sybil Attacks Against Large DHTs · NDSS 2010
Storage systems
crash consistency
0.012009
Operating systems transactions · SOSP 2009

Methods — techniques the papers use, named apart from their topics

hypervisor-based isolation · 0.5fault injection · 0.5paraverification · 0.3type inference · 0.2concurrent integrity checking · 0.2user study · 0.2ACID transactions · 0.2system transactions · 0.1flat datacenter storage · 0.1cloaking · 0.1cooperative transactional spinlocks · 0.1
YearPublicationVenuePosition
2016 Sego: Pervasive Trusted Metadata for Efficiently Verified Untrusted System Services
abstract
Sego is a hypervisor-based system that gives strong privacy and integrity guarantees to trusted applications, even when the guest operating system is compromised or hostile. Sego verifies operating system services, like the file system, instead of replacing them. By associating trusted metadata with user data across all system devices, Sego verifies system services more efficiently than previous systems, especially services that depend on data contents. We extensively evaluate Sego's performance on real workloads and implement a kernel fault injector to validate Sego's file system-agnostic crash consistency and recovery protocol.
Youngjin Kwon, Alan M. Dunn, Michael Z. Lee, Owen S. Hofmann, Yuanzhong Xu, Emmett Witchel
ASPLOS4
2014 Application-Defined Decentralized Access Control
Yuanzhong Xu, Alan M. Dunn, Owen S. Hofmann, Michael Z. Lee, Syed Akbar Mehdi, Emmett Witchel
USENIX ATC3
2013 InkTag: secure applications on an untrusted operating system
abstract
InkTag is a virtualization-based architecture that gives strong safety guarantees to high-assurance processes even in the presence of a malicious operating system. InkTag advances the state of the art in untrusted operating systems in both the design of its hypervisor and in the ability to run useful applications without trusting the operating system. We introduce paraverification, a technique that simplifies the InkTag hypervisor by forcing the untrusted operating system to participate in its own verification. Attribute-based access control allows trusted applications to create decentralized access control policies. InkTag is also the first system of its kind to ensure consistency between secure data and metadata, ensuring recoverability in the face of system crashes.
Owen S. Hofmann, Sangman Kim, Alan M. Dunn, Michael Z. Lee, Emmett Witchel
ASPLOS1
2012 Improving server applications with system transactions
abstract
Server applications must process requests as quickly as possible. Because some requests depend on earlier requests, there is often a tension between increasing throughput and maintaining the proper semantics for dependent requests. Operating system transactions make it easier to write reliable, high-throughput server applications because they allow the application to execute non-interfering requests in parallel, even if the requests operate on OS state, such as file data.
Sangman Kim, Michael Z. Lee, Alan M. Dunn, Owen S. Hofmann, Emmett Witchel, Donald E. Porter
EuroSys4
2012 Flat Datacenter Storage
Ed Nightingale, Jeremy Elson, Jinliang Fan, Owen S. Hofmann, Jon Howell, Yutaka Suzue
OSDI4
2011 Ensuring operating system kernel integrity with OSck
abstract
Kernel rootkits that modify operating system state to avoid detection are a dangerous threat to system security. This paper presents OSck, a system that discovers kernel rootkits by detecting malicious modifications to operating system data. OSck integrates and extends existing techniques for detecting rootkits, and verifies safety properties for large portions of the kernel heap with minimal overhead. We deduce type information for verification by analyzing unmodified kernel source code and in-memory kernel data structures.High-performance integrity checks that execute concurrently with a running operating system create data races, and we demonstrate a deterministic solution for ensuring kernel memory is in a consistent state. We introduce two new classes of kernel rootkits that are undetectable by current systems, motivating the need for the OSck API that allows kernel developers to conveniently specify arbitrary integrity properties.
Owen S. Hofmann, Alan M. Dunn, Sangman Kim, Indrajit Roy 0001, Emmett Witchel
ASPLOS1
2011 Cloaking Malware with the Trusted Platform Module
Alan M. Dunn, Owen S. Hofmann, Brent Waters, Emmett Witchel
USENIX Security Symposium2
2010 Defeating Vanish with Low-Cost Sybil Attacks Against Large DHTs
Scott Wolchok, Owen S. Hofmann, Nadia Heninger, Edward W. Felten, J. Alex Halderman, Christopher J. Rossbach, Brent Waters, Emmett Witchel
NDSS2
2010 Is transactional programming actually easier?
abstract
Chip multi-processors (CMPs) have become ubiquitous, while tools that ease concurrent programming have not. The promise of increased performance for all applications through ever more parallel hardware requires good tools for concurrent programming, especially for average programmers. Transactional memory (TM) has enjoyed recent interest as a tool that can help programmers program concurrently.
Christopher J. Rossbach, Owen S. Hofmann, Emmett Witchel
PPoPP2
2009 Maximum benefit from a minimal HTM
abstract
A minimal, bounded hardware transactional memory implementation significantly improves synchronization performance when used in an operating system kernel. We add HTM to Linux 2.4, a kernel with a simple, coarse-grained synchronization structure. The transactional Linux 2.4 kernel can improve performance of user programs by as much as 40% over the non-transactional 2.4 kernel. It closes 68% of the performance gap with the Linux 2.6 kernel, which has had significant engineering effort applied to improve scalability.
Owen S. Hofmann, Christopher J. Rossbach, Emmett Witchel
ASPLOS1
2009 Operating systems transactions
abstract
Applications must be able to synchronize accesses to operating system resources in order to ensure correctness in the face of concurrency and system failures. System transactions allow the programmer to specify updates to heterogeneous system resources with the OS guaranteeing atomicity, consistency, isolation, and durability (ACID). System transactions efficiently and cleanly solve persistent concurrency problems that are difficult to address with other techniques. For example, system transactions eliminate security vulnerabilities in the file system that are caused by time-of-check-to-time-of-use (TOCTTOU) race conditions. System transactions enable an unsuccessful software installation to roll back without disturbing concurrent, independent updates to the file system.
Donald E. Porter, Owen S. Hofmann, Christopher J. Rossbach, Alexander Benn, Emmett Witchel
SOSP2
2007 Is the Optimism in Optimistic Concurrency Warranted?
Donald E. Porter, Owen S. Hofmann, Emmett Witchel
HotOS2
2007 MetaTM//TxLinux: transactional memory for an operating system
abstract
This paper quantifies the effect of architectural design decisions onthe performance of TxLinux. TxLinux is a Linux kernel modifiedto use transactions in place of locking primitives in several key subsystems.We run TxLinux on MetaTM, which is a new hardwaretransaction memory (HTM) model.MetaTM contains features that enable efficient and correct interrupthandling for an x86-like architecture. Live stack overwrites can corrupt non-transactional stack memory and requires a smallchange to the transaction register checkpoint hardware to ensurecorrect operation of the operating system. We also propose stack based early release to reduce spurious conflicts on stack memorybetween kernel code and interrupt handlers.We use MetaTM to examine the performance sensitivity of individualarchitectural features. For TxLinux we find that Polka and SizeMatters are effective contention management policies, someform of backoff on transaction contention is vital for performance,and stalling on a transaction conflict reduces transaction restartrates, but does not improve performance. Transaction write setsare small, and performance is insensitive to transaction abort costsbut sensitive to commit costs.
Hany E. Ramadan, Christopher J. Rossbach, Donald E. Porter, Owen S. Hofmann, Bhandari Aditya, Emmett Witchel
ISCA4
2007 TxLinux: using and managing hardware transactional memory in an operating system
abstract
TxLinux is a variant of Linux that is the first operating system to use hardware transactional memory (HTM) as a synchronization primitive, and the first to manage HTM in the scheduler. This paper describes and measures TxLinux and discusses two innovations in detail: cooperation between locks and transactions, and theintegration of transactions with the OS scheduler. Mixing locks and transactions requires a new primitive, cooperative transactional spinlocks (cxspinlocks) that allow locks and transactions to protect the same data while maintaining the advantages of both synchronization primitives. Cxspinlocks allow the system to attemptexecution of critical regions with transactions and automatically roll back to use locking if the region performs I/O. Integrating the scheduler with HTM eliminates priority inversion. On a series ofreal-world benchmarks TxLinux has similar performance to Linux, exposing concurrency with as many as 32 concurrent threads on 32 CPUs in the same critical region.
Christopher J. Rossbach, Owen S. Hofmann, Donald E. Porter, Hany E. Ramadan, Bhandari Aditya, Emmett Witchel
SOSP2