EDBT 2026 Demo / reviewers in the wild / expert
Owen S. Hofmann
dblp:80/77
· DBLP profile ↗
14ranked-venue papers
3as first author
0since 2021 · last 2016
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 9 · 3 first-authorSystems, architecture and hardware · 8 · 3 first-authorSecurity and privacy · 2
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
6 papers |
Systems and software security · 44% Authentication and access control · 23% Malware analysis · 13% | |
| Software engineering, system software, and programming languages
9 papers |
Operating systems · 51% Concurrent programming · 49% | |
| Computer architecture, parallel and distributed computing, and storage systems
7 papers |
Cloud and datacenter computing · 36% Parallel and multicore computing · 34% Distributed systems · 13% |
Topics — the 30 heaviest of 33, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security › trusted computing
trusted execution |
0.4 | 2 | 2016 | Sego: Pervasive Trusted Metadata for Efficiently Verified Untrusted System Services · ASPLOS 2016 InkTag: secure applications on an untrusted operating system · ASPLOS 2013 |
Concurrent programming
concurrency control |
0.2 | 2 | 2012 | Improving server applications with system transactions · EuroSys 2012 Operating systems transactions · SOSP 2009 |
Authentication and access control
access control |
0.2 | 1 | 2014 | Application-Defined Decentralized Access Control · USENIX ATC 2014 |
Authentication and access control › access control › distributed access control
decentralized access control |
0.2 | 1 | 2014 | Application-Defined Decentralized Access Control · USENIX ATC 2014 |
Concurrent programming
transactional memory |
0.2 | 2 | 2010 | Is transactional programming actually easier? · PPoPP 2010 TxLinux: using and managing hardware transactional memory in an operating system · SOSP 2007 |
Concurrent programming › transactional memory
hardware transactional memory |
0.2 | 2 | 2009 | Maximum benefit from a minimal HTM · ASPLOS 2009 TxLinux: using and managing hardware transactional memory in an operating system · SOSP 2007 |
Operating systems › kernel › kernel design
kernel synchronization |
0.2 | 2 | 2009 | Maximum benefit from a minimal HTM · ASPLOS 2009 MetaTM//TxLinux: transactional memory for an operating system · ISCA 2007 |
Concurrent programming
synchronization |
0.2 | 2 | 2009 | Maximum benefit from a minimal HTM · ASPLOS 2009 TxLinux: using and managing hardware transactional memory in an operating system · SOSP 2007 |
Systems and software security › operating system security
untrusted operating system |
0.2 | 1 | 2013 | InkTag: secure applications on an untrusted operating system · ASPLOS 2013 |
Operating systems › virtualization
hypervisor |
0.2 | 1 | 2013 | InkTag: secure applications on an untrusted operating system · ASPLOS 2013 |
Operating systems
virtualization |
0.2 | 1 | 2013 | InkTag: secure applications on an untrusted operating system · ASPLOS 2013 |
Cloud and datacenter computing
datacenter storage |
0.1 | 1 | 2012 | Flat Datacenter Storage · OSDI 2012 |
Systems and software security › operating system security
kernel integrity |
0.1 | 1 | 2011 | Ensuring operating system kernel integrity with OSck · ASPLOS 2011 |
Malware analysis
malware detection evasion |
0.1 | 1 | 2011 | Cloaking Malware with the Trusted Platform Module · USENIX Security Symposium 2011 |
Systems and software security
operating system security |
0.1 | 1 | 2011 | Ensuring operating system kernel integrity with OSck · ASPLOS 2011 |
Malware analysis
rootkit detection |
0.1 | 1 | 2011 | Ensuring operating system kernel integrity with OSck · ASPLOS 2011 |
Hardware security and side channels
trusted execution environments |
0.1 | 1 | 2011 | Cloaking Malware with the Trusted Platform Module · USENIX Security Symposium 2011 |
Hardware security and side channels › trusted execution environments
trusted platform module |
0.1 | 1 | 2011 | Cloaking Malware with the Trusted Platform Module · USENIX Security Symposium 2011 |
Network security
anonymity networks |
0.1 | 1 | 2010 | Defeating Vanish with Low-Cost Sybil Attacks Against Large DHTs · NDSS 2010 |
Parallel and multicore computing
transactional memory |
0.1 | 2 | 2009 | MetaTM//TxLinux: transactional memory for an operating system · ISCA 2007 Maximum benefit from a minimal HTM · ASPLOS 2009 |
Concurrent programming
atomicity |
0.1 | 1 | 2009 | Operating systems transactions · SOSP 2009 |
Operating systems › resource management › storage management › file systems
file system verification |
0.1 | 1 | 2016 | Sego: Pervasive Trusted Metadata for Efficiently Verified Untrusted System Services · ASPLOS 2016 |
Operating systems › resource management › process management
CPU scheduling |
0.1 | 1 | 2007 | TxLinux: using and managing hardware transactional memory in an operating system · SOSP 2007 |
Parallel and multicore computing › transactional memory
hardware transactional memory |
0.1 | 1 | 2007 | MetaTM//TxLinux: transactional memory for an operating system · ISCA 2007 |
Authentication and access control › access control models
attribute-based access control |
0.0 | 1 | 2013 | InkTag: secure applications on an untrusted operating system · ASPLOS 2013 |
Cloud and datacenter computing › cluster resource management and scheduling
cluster resource management |
0.0 | 1 | 2012 | Flat Datacenter Storage · OSDI 2012 |
Processor architecture and microarchitecture
chip multiprocessor |
0.0 | 1 | 2010 | Is transactional programming actually easier? · PPoPP 2010 |
Distributed systems › peer-to-peer systems
distributed hash table |
0.0 | 1 | 2010 | Defeating Vanish with Low-Cost Sybil Attacks Against Large DHTs · NDSS 2010 |
Distributed systems › distributed system security
sybil attacks |
0.0 | 1 | 2010 | Defeating Vanish with Low-Cost Sybil Attacks Against Large DHTs · NDSS 2010 |
Storage systems
crash consistency |
0.0 | 1 | 2009 | Operating systems transactions · SOSP 2009 |
Methods — techniques the papers use, named apart from their topics
hypervisor-based isolation · 0.5fault injection · 0.5paraverification · 0.3type inference · 0.2concurrent integrity checking · 0.2user study · 0.2ACID transactions · 0.2system transactions · 0.1flat datacenter storage · 0.1cloaking · 0.1cooperative transactional spinlocks · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2016 | Sego: Pervasive Trusted Metadata for Efficiently Verified Untrusted System ServicesabstractSego is a hypervisor-based system that gives strong privacy and integrity guarantees to trusted applications, even when the guest operating system is compromised or hostile. Sego verifies operating system services, like the file system, instead of replacing them. By associating trusted metadata with user data across all system devices, Sego verifies system services more efficiently than previous systems, especially services that depend on data contents. We extensively evaluate Sego's performance on real workloads and implement a kernel fault injector to validate Sego's file system-agnostic crash consistency and recovery protocol. Youngjin Kwon, Alan M. Dunn, Michael Z. Lee, Owen S. Hofmann, Yuanzhong Xu, Emmett Witchel |
ASPLOS | 4 |
| 2014 | Application-Defined Decentralized Access Control
Yuanzhong Xu, Alan M. Dunn, Owen S. Hofmann, Michael Z. Lee, Syed Akbar Mehdi, Emmett Witchel |
USENIX ATC | 3 |
| 2013 | InkTag: secure applications on an untrusted operating systemabstractInkTag is a virtualization-based architecture that gives strong safety guarantees to high-assurance processes even in the presence of a malicious operating system. InkTag advances the state of the art in untrusted operating systems in both the design of its hypervisor and in the ability to run useful applications without trusting the operating system. We introduce paraverification, a technique that simplifies the InkTag hypervisor by forcing the untrusted operating system to participate in its own verification. Attribute-based access control allows trusted applications to create decentralized access control policies. InkTag is also the first system of its kind to ensure consistency between secure data and metadata, ensuring recoverability in the face of system crashes. Owen S. Hofmann, Sangman Kim, Alan M. Dunn, Michael Z. Lee, Emmett Witchel |
ASPLOS | 1 |
| 2012 | Improving server applications with system transactionsabstractServer applications must process requests as quickly as possible. Because some requests depend on earlier requests, there is often a tension between increasing throughput and maintaining the proper semantics for dependent requests. Operating system transactions make it easier to write reliable, high-throughput server applications because they allow the application to execute non-interfering requests in parallel, even if the requests operate on OS state, such as file data. Sangman Kim, Michael Z. Lee, Alan M. Dunn, Owen S. Hofmann, Emmett Witchel, Donald E. Porter |
EuroSys | 4 |
| 2012 | Flat Datacenter Storage
Ed Nightingale, Jeremy Elson, Jinliang Fan, Owen S. Hofmann, Jon Howell, Yutaka Suzue |
OSDI | 4 |
| 2011 | Ensuring operating system kernel integrity with OSckabstractKernel rootkits that modify operating system state to avoid detection are a dangerous threat to system security. This paper presents OSck, a system that discovers kernel rootkits by detecting malicious modifications to operating system data. OSck integrates and extends existing techniques for detecting rootkits, and verifies safety properties for large portions of the kernel heap with minimal overhead. We deduce type information for verification by analyzing unmodified kernel source code and in-memory kernel data structures.High-performance integrity checks that execute concurrently with a running operating system create data races, and we demonstrate a deterministic solution for ensuring kernel memory is in a consistent state. We introduce two new classes of kernel rootkits that are undetectable by current systems, motivating the need for the OSck API that allows kernel developers to conveniently specify arbitrary integrity properties. Owen S. Hofmann, Alan M. Dunn, Sangman Kim, Indrajit Roy 0001, Emmett Witchel |
ASPLOS | 1 |
| 2011 | Cloaking Malware with the Trusted Platform Module
Alan M. Dunn, Owen S. Hofmann, Brent Waters, Emmett Witchel |
USENIX Security Symposium | 2 |
| 2010 | Defeating Vanish with Low-Cost Sybil Attacks Against Large DHTs
Scott Wolchok, Owen S. Hofmann, Nadia Heninger, Edward W. Felten, J. Alex Halderman, Christopher J. Rossbach, Brent Waters, Emmett Witchel |
NDSS | 2 |
| 2010 | Is transactional programming actually easier?abstractChip multi-processors (CMPs) have become ubiquitous, while tools that ease concurrent programming have not. The promise of increased performance for all applications through ever more parallel hardware requires good tools for concurrent programming, especially for average programmers. Transactional memory (TM) has enjoyed recent interest as a tool that can help programmers program concurrently. Christopher J. Rossbach, Owen S. Hofmann, Emmett Witchel |
PPoPP | 2 |
| 2009 | Maximum benefit from a minimal HTMabstractA minimal, bounded hardware transactional memory implementation significantly improves synchronization performance when used in an operating system kernel. We add HTM to Linux 2.4, a kernel with a simple, coarse-grained synchronization structure. The transactional Linux 2.4 kernel can improve performance of user programs by as much as 40% over the non-transactional 2.4 kernel. It closes 68% of the performance gap with the Linux 2.6 kernel, which has had significant engineering effort applied to improve scalability. Owen S. Hofmann, Christopher J. Rossbach, Emmett Witchel |
ASPLOS | 1 |
| 2009 | Operating systems transactionsabstractApplications must be able to synchronize accesses to operating system resources in order to ensure correctness in the face of concurrency and system failures. System transactions allow the programmer to specify updates to heterogeneous system resources with the OS guaranteeing atomicity, consistency, isolation, and durability (ACID). System transactions efficiently and cleanly solve persistent concurrency problems that are difficult to address with other techniques. For example, system transactions eliminate security vulnerabilities in the file system that are caused by time-of-check-to-time-of-use (TOCTTOU) race conditions. System transactions enable an unsuccessful software installation to roll back without disturbing concurrent, independent updates to the file system. Donald E. Porter, Owen S. Hofmann, Christopher J. Rossbach, Alexander Benn, Emmett Witchel |
SOSP | 2 |
| 2007 | Is the Optimism in Optimistic Concurrency Warranted?
Donald E. Porter, Owen S. Hofmann, Emmett Witchel |
HotOS | 2 |
| 2007 | MetaTM//TxLinux: transactional memory for an operating systemabstractThis paper quantifies the effect of architectural design decisions onthe performance of TxLinux. TxLinux is a Linux kernel modifiedto use transactions in place of locking primitives in several key subsystems.We run TxLinux on MetaTM, which is a new hardwaretransaction memory (HTM) model.MetaTM contains features that enable efficient and correct interrupthandling for an x86-like architecture. Live stack overwrites can corrupt non-transactional stack memory and requires a smallchange to the transaction register checkpoint hardware to ensurecorrect operation of the operating system. We also propose stack based early release to reduce spurious conflicts on stack memorybetween kernel code and interrupt handlers.We use MetaTM to examine the performance sensitivity of individualarchitectural features. For TxLinux we find that Polka and SizeMatters are effective contention management policies, someform of backoff on transaction contention is vital for performance,and stalling on a transaction conflict reduces transaction restartrates, but does not improve performance. Transaction write setsare small, and performance is insensitive to transaction abort costsbut sensitive to commit costs. Hany E. Ramadan, Christopher J. Rossbach, Donald E. Porter, Owen S. Hofmann, Bhandari Aditya, Emmett Witchel |
ISCA | 4 |
| 2007 | TxLinux: using and managing hardware transactional memory in an operating systemabstractTxLinux is a variant of Linux that is the first operating system to use hardware transactional memory (HTM) as a synchronization primitive, and the first to manage HTM in the scheduler. This paper describes and measures TxLinux and discusses two innovations in detail: cooperation between locks and transactions, and theintegration of transactions with the OS scheduler. Mixing locks and transactions requires a new primitive, cooperative transactional spinlocks (cxspinlocks) that allow locks and transactions to protect the same data while maintaining the advantages of both synchronization primitives. Cxspinlocks allow the system to attemptexecution of critical regions with transactions and automatically roll back to use locking if the region performs I/O. Integrating the scheduler with HTM eliminates priority inversion. On a series ofreal-world benchmarks TxLinux has similar performance to Linux, exposing concurrency with as many as 32 concurrent threads on 32 CPUs in the same critical region. Christopher J. Rossbach, Owen S. Hofmann, Donald E. Porter, Hany E. Ramadan, Bhandari Aditya, Emmett Witchel |
SOSP | 2 |