Willem de Bruijn

dblp:86/4441 · DBLP profile ↗
← Back
10ranked-venue papers
6as first author
1since 2021 · last 2023
0009-0007-8501-7379ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 4 · 2 first-author · 1 since 2021Software engineering, systems software and programming languages · 3 · 1 first-authorSystems, architecture and hardware · 1 · 1 first-authorSecurity and privacy · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer networks
4 papers
Network measurement and analytics · 85% Datacenter networks · 13% Internet architecture and protocols · 3%
Software engineering, system software, and programming languages
5 papers
Operating systems · 100%
Network and information security
2 papers
Systems and software security · 41% Hardware security and side channels · 41% Authentication and access control · 12%

Topics — the 11 heaviest of 15, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network measurement and analytics
passive measurement
0.712023
Fathom: Understanding Datacenter Application Network Performance · SIGCOMM 2023
Operating systems › i/o
i/o subsystem
0.222011
Application-Tailored I/O with Streamline · ACM Trans. Comput. Syst. 2011
Beltway Buffers: Avoiding the OS Traffic Jam · INFOCOM 2008
Hardware security and side channels › trusted execution environments
remote attestation
0.112011
Logical attestation: an authorization architecture for trustworthy computing · SOSP 2011
Systems and software security
trusted computing
0.112011
Logical attestation: an authorization architecture for trustworthy computing · SOSP 2011
Operating systems › i/o › i/o subsystem
zero-copy i/o
0.112008
Beltway Buffers: Avoiding the OS Traffic Jam · INFOCOM 2008
Operating systems
network stack
0.112005
OS support for multi-gigabit networking · SOSP 2005
Operating systems › network stack
packet filtering
0.012004
FFPF: Fairly Fast Packet Filters · OSDI 2004
Authentication and access control
access control policy
0.012011
Logical attestation: an authorization architecture for trustworthy computing · SOSP 2011
Storage systems › file systems
file system i/o
0.012011
Application-Tailored I/O with Streamline · ACM Trans. Comput. Syst. 2011
Internet architecture and protocols
high-speed networks
0.012005
OS support for multi-gigabit networking · SOSP 2005
Network security › intrusion detection and prevention
intrusion detection
0.012005
OS support for multi-gigabit networking · SOSP 2005

Methods — techniques the papers use, named apart from their topics

kernel instrumentation · 0.7RPC stack instrumentation · 0.7runtime path optimization · 0.2proof construction · 0.2logic-based attestation · 0.2memory-mapped i/o · 0.2POSIX file interface · 0.2
YearPublicationVenuePosition
2023 Fathom: Understanding Datacenter Application Network Performance
abstract
We describe our experience with Fathom, a system for identifying the network performance bottlenecks of any service running in the Google fleet. Fathom passively samples RPCs, the principal unit of work for services. It segments the overall latency into host and network components with kernel and RPC stack instrumentation. It records these detailed latency metrics, along with detailed transport connection state, for every sampled RPC. This lets us determine if the completion is constrained by the client, network or server. To scale while enabling analysis, we also aggregate samples into distributions that retain multi-dimensional breakdowns. This provides us with a macroscopic view of individual services. Fathom runs globally in our datacenters for all production traffic, where it monitors billions of TCP connections 24x7. For five years Fathom has been our primary tool for troubleshooting service network issues and assessing network infrastructure changes. We present case studies to show how it has helped us improve our production services.
Mubashir Adnan Qureshi, Junhua Yan, Yuchung Cheng, Soheil Hassas Yeganeh, Yousuk Seung, Neal Cardwell, Willem de Bruijn, Van Jacobson, Jasleen Kaur 0001, David Wetherall, Amin Vahdat
SIGCOMM7
2011 Logical attestation: an authorization architecture for trustworthy computing
abstract
This paper describes the design and implementation of a new operating system authorization architecture to support trustworthy computing. Called logical attestation, this architecture provides a sound framework for reasoning about run time behavior of applications. Logical attestation is based on attributable, unforgeable statements about program properties, expressed in a logic. These statements are suitable for mechanical processing, proof construction, and verification; they can serve as credentials, support authorization based on expressive authorization policies, and enable remote principals to trust software components without restricting the local user's choice of binary implementations.
Emin Gün Sirer, Willem de Bruijn, Patrick Reynolds, Alan Shieh, Kevin Walsh 0001, Dan Williams 0001, Fred B. Schneider
SOSP2
2011 Application-Tailored I/O with Streamline
abstract
Streamline is a stream-based OS communication subsystem that spans from peripheral hardware to userspace processes. It improves performance of I/O-bound applications (such as webservers and streaming media applications) by constructing tailor-made I/O paths through the operating system for each application at runtime. Path optimization removes unnecessary copying, context switching and cache replacement and integrates specialized hardware. Streamline automates optimization and only presents users a clear, concise job control language based on Unix pipelines. For backward compatibility Streamline also presents well known files, pipes and sockets abstractions. Observed throughput improvement over Linux 2.6.24 for networking applications is up to 30-fold, but two-fold is more typical.
Willem de Bruijn, Herbert Bos, Henri E. Bal
ACM Trans. Comput. Syst.1
2008 Beltway Buffers: Avoiding the OS Traffic Jam
abstract
Beltway buffers are operating system I/O paths optimised for high-throughput network applications. The key architectural feature of Beltway buffers is that all I/O takes place in long-lived, allocation-free, shared ringbuffers. Advantages of this design are (1) improved throughput through system-wide copy, context-switch and allocation avoidance and judicious use of the data cache, (2) transparent integration of peripheral hardware and (3) simplicity and familiarity due to comprehensive use of the POSIX file interface for accessing streams.
Willem de Bruijn, Herbert Bos
INFOCOM1
2006 SafeCard: A Gigabit IPS on the Network Card
Willem de Bruijn, Asia Slowinska, Kees van Reeuwijk, Tomás Hrubý, Herbert Bos
RAID1
2005 FPL-3: Towards Language Support for Distributed Packet Processing
Mihai-Lucian Cristea, Willem de Bruijn, Herbert Bos
NETWORKING2
2005 OS support for multi-gigabit networking
abstract
Multi-gigabit speeds are reaching the periphery of the network, where both hard- and software are unprepared for these high rates. With wider pipes available, network uses are also diversifying: time-constrained streaming media, low-latency telephony and high-throughput bulk transfers have to contend for the same overloaded resources on the host. To top it off, a heightened awareness of the need for security is making host-side firewalling and intrusion detection commonplace.
Willem de Bruijn, Herbert Bos
SOSP1
2005 Robust Distributed Systems Achieving Self-Management through Inference
abstract
Self-management has often been proposed as a means to reduce the growing complexity of administration in distributed systems. We argue that this can be achieved through aggressive automation of management tasks. To reach a high level of automation, we propose to take an inference-based approach: codify best practices so that they can be reasoned about and adapted at runtime. Concerns specific to distributed systems are dealt with by the innate support for knowledge sharing. We introduce the methodology along with a reference architecture. The method's validity is tested by applying a preliminary implementation to a handful of practical problems.
Willem de Bruijn, Herbert Bos, Henri E. Bal
WOWMOM1
2004 Splash: SNMP Plus a Lightweight API for SNAP Handling
abstract
We describe a drop-in replacement for net-snmp, known as 'Splash' (SNMP Plus a Lightweight API for SNAP Handling), which adds support for efficient mobile agents to the standard SNMP agent. Experiments show that the SNAP (Safe and Nimble Active Packets) mobile agent engine is comparable in speed to SNMP, even for the simple polling scenarios for which SNMP is optimized, yet also provides flexibility that allows it to outperform SNMP in more complex scenarios. Splash allows network operators to select the monitoring paradigm (polling with SNMP, or a mobile agent approach) most appropriate for a given situation.
Willem de Bruijn, Jon T. Moore, Herbert Bos
NOMS (1)1
2004 FFPF: Fairly Fast Packet Filters
Herbert Bos, Willem de Bruijn, Mihai-Lucian Cristea, Georgios Portokalidis
OSDI2