EDBT 2026 Demo / reviewers in the wild / expert
Dan Williams 0001
dblp:96/2005 · also Dan John Williams
· DBLP profile ↗
31ranked-venue papers
8as first author
12since 2021 · last 2025
0000-0003-1537-0525ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 18 · 5 first-author · 7 since 2021Software engineering, systems software and programming languages · 9 · 1 first-author · 4 since 2021Security and privacy · 3 · 3 since 2021Computer networks · 2 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Extending Applications Safely and Efficiently
Yusheng Zheng, Yiwei Yang 0002, Yanpeng Hu, Xiaozheng Lai, Dan Williams 0001, Andi Quinn |
OSDI | 6 |
| 2025 | Rex: Closing the language-verifier gap with safe and usable kernel extensions
Jinghao Jia, Ruowen Qin, Milo Craun, Egor Lukiyanov, Ayush Bansal, Minh Phan, Michael V. Le, Hubertus Franke, Hani Jamjoom, Tianyin Xu, Dan Williams 0001 |
USENIX ATC | 11 |
| 2024 | SEVeriFast: Minimizing the root of trust for fast startup of SEV microVMsabstractServerless computing platforms rely on fast container initialization to provide low latency and high throughput for requests. While hardware enforced trusted execution environments (TEEs) have gained popularity, confidential computing has yet to be widely adopted by latency-sensitive platforms due to its additional initialization overhead. We investigate the application of AMD's Secure Encrypted Virtualization (SEV) to microVMs and find that current startup times for confidential VMs are prohibitively slow due to the high cost of establishing a root of trust for each new VM. Benjamin Holmes 0002, Jason Waterman, Dan Williams 0001 |
ASPLOS (2) | 3 |
| 2024 | Fast (Trapless) Kernel Probes Everywhere
Jinghao Jia, Michael V. Le, Salman Ahmed 0001, Dan Williams 0001, Hani Jamjoom, Tianyin Xu |
USENIX ATC | 4 |
| 2024 | SeaK: Rethinking the Design of a Secure Allocator for OS Kernel
Zicheng Wang 0010, Yicheng Guang, Yueqi Chen 0001, Zhenpeng Lin, Michael V. Le, Dang K. Le, Dan Williams 0001, Xinyu Xing 0001, Zhongshu Gu, Hani Jamjoom |
USENIX Security Symposium | 7 |
| 2024 | Introduction to the Special Section on USENIX ATC 2023abstractPublished version Dan Williams 0001, Julia Lawall |
ACM Trans. Storage | 1 |
| 2023 | Securing Container-based Clouds with Syscall-aware SchedulingabstractContainer-based clouds—in which containers are the basic unit of isolation—face security concerns because, unlike Virtual Machines, containers directly interface with the underlying highly privileged kernel through the wide and vulnerable system call interface. Regardless of whether a container itself requires dangerous system calls, a compromised or malicious container sharing the host (a bad neighbor) can compromise the host kernel using a vulnerable syscall, thereby compromising all other containers sharing the host. Michael V. Le, Salman Ahmed 0001, Dan Williams 0001, Hani Jamjoom |
AsiaCCS | 3 |
| 2023 | Protect the System Call, Protect (Most of) the World with BASTIONabstractSystem calls are a critical building block in many serious security attacks, such as control-flow hijacking and privilege escalation attacks. Security-sensitive system calls (e.g., execve, mprotect), especially play a major role in completing attacks. Yet, few defense efforts focus to ensure their legitimate usage, allowing attackers to maliciously leverage system calls in attacks. Christopher Jelesnianski, Mohannad Ismail, Yeongjin Jang, Dan Williams 0001, Changwoo Min |
ASPLOS (3) | 4 |
| 2023 | Kernel extension verification is untenableabstractThe emergence of verified eBPF bytecode is ushering in a new era of safe kernel extensions. In this paper, we argue that eBPF's verifier---the source of its safety guarantees---has become a liability. In addition to the well-known bugs and vulnerabilities stemming from the complexity and ad hoc nature of the in-kernel verifier, we highlight a concerning trend in which escape hatches to unsafe kernel functions (in the form of helper functions) are being introduced to bypass verifier-imposed limitations on expressiveness, unfortunately also bypassing its safety guarantees. We propose safe kernel extension frameworks using a balance of not just static but also lightweight runtime techniques. We describe a design centered around kernel extensions in safe Rust that will eliminate the need of the in-kernel verifier, improve expressiveness, allow for reduced escape hatches, and ultimately improve the safety of kernel extensions. Jinghao Jia, Raj Sahu, Adam Oswald, Dan Williams 0001, Michael V. Le, Tianyin Xu |
HotOS | 4 |
| 2022 | SecQuant: Quantifying Container System Call Exposure
Sunwoo Jang, Somin Song, Byung-Chul Tak, Sahil Suneja, Michael V. Le, Chuan Yue, Dan Williams 0001 |
ESORICS (2) | 7 |
| 2022 | KASLR in the age of MicroVMsabstractAddress space layout randomization (ASLR) is a widely used component of computer security aimed at preventing code reuse and/or data-only attacks. Modern kernels utilize kernel ASLR (KASLR) and finer-grained forms, such as functional granular KASLR (FGKASLR), but do so as part of an inefficient bootstrapping process we call bootstrap self-randomization. Meanwhile, under increasing pressure to optimize their boot times, microVM architectures such as AWS Firecracker have resorted to eliminating bootstrapping steps, particularly decompression and relocation from the guest kernel boot process, leaving them without KASLR. In this paper, we present in-monitor KASLR, in which the virtual machine monitor efficiently implements KASLR for the guest kernel by skipping the expensive kernel self-relocation steps. We prototype in-monitor KASLR and FGKASLR in the open-source Firecracker virtual machine monitor demonstrating, on a microVM configured kernel, boot times 22% and 16% faster than bootstrapped KASLR and FGKASLR methods, respectively. We also show the low overhead of in-monitor KASLR, with only 4% (2 ms) increase in boot times on average compared to a kernel without KASLR. We also discuss the implications and future opportunities for in-monitor approaches. Benjamin Holmes 0002, Jason Waterman, Dan Williams 0001 |
EuroSys | 3 |
| 2022 | Verified programs can party: optimizing kernel extensions via post-verification mergingabstractOperating system (OS) extensions are more popular than ever. For example, Linux BPF is marketed as a "superpower" that allows user programs to be downloaded into the kernel, verified to be safe and executed at kernel hook points. So, BPF extensions have high performance and are often placed at performance-critical paths for tracing and filtering. Hsuan-Chi Kuo, Kai-Hsun Chen, Yicheng Lu, Dan Williams 0001, Sibin Mohan, Tianyin Xu |
EuroSys | 4 |
| 2020 | A Linux in unikernel clothingabstractUnikernels leverage library OS architectures to run isolated workloads on the cloud. They have garnered attention in part due to their promised performance characteristics such as small image size, fast boot time, low memory footprint and application performance. However, those that aimed at generality fall short of the application compatibility, robustness and, more importantly, community that is available for Linux. In this paper, we describe and evaluate Lupine Linux, a standard Linux system that---through kernel configuration specialization and system call overhead elimination---achieves unikernel-like performance, in fact outperforming at least one reference unikernel in all of the above dimensions. At the same time, Lupine can run any application (since it is Linux) when faced with more general workloads, whereas many unikernels simply crash. We demonstrate a graceful degradation of unikernel-like performance properties. Hsuan-Chi Kuo, Dan Williams 0001, Ricardo Koller, Sibin Mohan |
EuroSys | 2 |
| 2019 | An Ounce of Prevention is Worth a Pound of Cure: Ahead-of-time Preparation for Safe High-level Container Interfaces
Ricardo Koller, Dan Williams 0001 |
HotStorage | 2 |
| 2018 | Unikernels as ProcessesabstractSystem virtualization (e.g., the virtual machine abstraction) has been established as the de facto standard form of isolation in multi-tenant clouds. More recently, unikernels have emerged as a way to reuse VM isolation while also being lightweight by eliminating the general purpose OS (e.g., Linux) from the VM. Instead, unikernels directly run the application (linked with a library OS) on the virtual hardware. In this paper, we show that unikernels do not actually require a virtual hardware abstraction, but can achieve similar levels of isolation when running as processes by leveraging existing kernel system call whitelisting mechanisms. Moreover, we show that running unikernels as processes reduces hardware requirements, enables the use of standard process debugging and management tooling, and improves the already impressive performance that unikernels exhibit. Dan Williams 0001, Ricardo Koller, Martin Lucina, Nikhil Prakash |
SoCC | 1 |
| 2017 | Will Serverless End the Dominance of Linux in the Cloud?abstractFrom the inception of the cloud, running multi-tenant workloads has put strain on the Linux kernel's abstractions. After years of having its abstractions bypassed via virtualization, the kernel has responded with a native container abstraction that is eagerly being applied in the cloud. In this paper, we point out that history is repeating itself: with the introduction of serverless computing, even the native container abstraction is ill-suited. We show that bypassing the kernel with unikernels can yield at least a factor of 6 better latency and throughput. Facing a more complex kernel than ever and a relatively undemanding computing model, we must revisit the question of whether the kernel should try to adapt, we should continue bypassing the kernel, or if it is finally time to try a new native OS for this important future cloud workload. Ricardo Koller, Dan Williams 0001 |
HotOS | 2 |
| 2017 | Multi-Hypervisor Virtual Machines: Enabling an Ecosystem of Hypervisor-level Services
Kartik Gopalan, Rohith Kugve, Hardik Bagdi, Yaohui Hu, Dan Williams 0001, Nilton Bila |
USENIX ATC | 5 |
| 2016 | Version Traveler: Fast and Memory-Efficient Version Switching in Graph Processing Systems
Xiaoen Ju, Dan Williams 0001, Hani Jamjoom, Kang G. Shin |
USENIX ATC | 2 |
| 2016 | Enabling Efficient Hypervisor-as-a-Service Clouds with Eemeral VirtualizationabstractWhen considering a hypervisor, cloud providers must balance conflicting requirements for simple, secure code bases with more complex, feature-filled offerings. This paper introduces Dichotomy, a new two-layer cloud architecture in which the roles of the hypervisor are split. The cloud provider runs a lean hyperplexor that has the sole task of multiplexing hardware and running more substantial hypervisors (called featurevisors) that implement features. Cloud users choose featurevisors from a selection of lightly-modified hypervisors potentially offered by third-parties in an "as-a-service" model for each VM. Rather than running the featurevisor directly on the hyperplexor using nested virtualization, Dichotomy uses a new virtualization technique called eemeral virtualization which efficiently (and repeatedly) transfers control of a VM between the hyperplexor and featurevisor using memory mapping techniques. Nesting overhead is only incurred when the VM is accessed by the featurevisor. We have implemented Dichotomy in KVM/QEMU and demonstrate average switching times of 80 ms, two to three orders of magnitude faster than live VM migration. We show that, for the featurevisor applications we evaluated, VMs hosted in Dichotomy deliver up to 12% better performance than those hosted on nested hypervisors, and continue to show benefit even when the featurevisor applications run as often as every 2.5~seconds. Dan Williams 0001, Yaohui Hu, Umesh Deshpande, Piush K. Sinha, Nilton Bila, Kartik Gopalan, Hani Jamjoom |
VEE | 1 |
| 2015 | Flux: multi-surface computing in AndroidabstractWith the continued proliferation of mobile devices, apps will increasingly become multi-surface, running seamlessly across multiple user devices (e.g., phone, tablet, etc.). Yet general systems support for multi-surface app is limited to (1) screencasting, which relies on a single master device's computing power and battery life or (2) cloud backing, which is unsuitable in the face of disconnected operation or untrusted cloud providers. We present an alternative approach: Flux, an Android-based system that enables any app to become multi-surface through app migration. Flux overcomes device heterogeneity and residual dependencies through two key mechanisms. Selective Record/Adaptive Replay records just those device-agnostic app calls that lead to the generation of app-specific device-dependent state in system services and replays them on the target. Checkpoint/Restore in Android (CRIA) transitions an app into a state in which device-specific information can be safely discarded before checkpointing and restoring the app. Our implementation of Flux can migrate many popular, unmodified Android apps---including those with extensive device interactions like 3D accelerated graphics---across heterogeneous devices and is fast enough for interactive use. Alexander Van't Hof, Hani Jamjoom, Jason Nieh, Dan Williams 0001 |
EuroSys | 4 |
| 2014 | TideWatch: Fingerprinting the cyclicality of big data workloadsabstractIntrinsic to “big data” processing workloads (e.g., iterative MapReduce, Pregel, etc.) are cyclical resource utilization patterns that are highly synchronized across different resource types as well as the workers in a cluster. In Infrastructure as a Service settings, cloud providers do not exploit this characteristic to better manage VMs because they view VMs as “black boxes.” We present TideWatch, a system that automatically identifies cyclicality and similarity in running VMs. TideWatch predicts period lengths of most VMs in Hadoop workloads within 9% of actual iteration boundaries and successfully classifies up to 95% of running VMs as participating in the appropriate Hadoop cluster. Furthermore, we show how TideWatch can be used to improve the timing of VM migrations, reducing both migration time and network impact by over 50% when compared to a random approach. Dan Williams 0001, Shuai Zheng 0002, Xiangliang Zhang 0001, Hani Jamjoom |
INFOCOM | 1 |
| 2013 | Pico replication: a high availability framework for middleboxesabstractMiddleboxes are being rearchitected to be service oriented, composable, extensible, and elastic. Yet system-level support for high availability (HA) continues to introduce significant performance overhead. In this paper, we propose Pico Replication (PR), a system-level framework for middleboxes that exploits their flow-centric structure to achieve low overhead, fully customizable HA. Unlike generic (virtual machine level) techniques, PR operates at the flow level. Individual flows can be checkpointed at very high frequencies while the middlebox continues to process other flows. Furthermore, each flow can have its own checkpoint frequency, output buffer and target for backup, enabling rich and diverse policies that balance---per-flow---performance and utilization. PR leverages OpenFlow to provide near instant flow-level failure recovery, by dynamically rerouting a flow's packets to its replication target. We have implemented PR and a flow-based HA policy. In controlled experiments, PR sustains checkpoint frequencies of 1000Hz, an order of magnitude improvement over current VM replication solutions. As a result, PR drastically reduces the overhead on end-to-end latency from 280% to 15.5% and throughput overhead from 99.5% to 3.2%. Shriram Rajagopalan, Dan Williams 0001, Hani Jamjoom |
SoCC | 2 |
| 2013 | Mizan: a system for dynamic load balancing in large-scale graph processingabstractPregel [23] was recently introduced as a scalable graph mining system that can provide significant performance improvements over traditional MapReduce implementations. Existing implementations focus primarily on graph partitioning as a preprocessing step to balance computation across compute nodes. In this paper, we examine the runtime characteristics of a Pregel system. We show that graph partitioning alone is insufficient for minimizing end-to-end computation. Especially where data is very large or the runtime behavior of the algorithm is unknown, an adaptive approach is needed. To this end, we introduce Mizan, a Pregel system that achieves efficient load balancing to better adapt to changes in computing needs. Unlike known implementations of Pregel, Mizan does not assume any a priori knowledge of the structure of the graph or behavior of the algorithm. Instead, it monitors the runtime characteristics of the system. Mizan then performs efficient fine-grained vertex migration to balance computation and communication. We have fully implemented Mizan; using extensive evaluation we show that---especially for highly-dynamic workloads---Mizan provides up to 84% improvement over techniques leveraging static graph pre-partitioning. Zuhair Khayyat, Karim Awara, Amani AlOnazi, Hani Jamjoom, Dan Williams 0001, Panos Kalnis |
EuroSys | 5 |
| 2013 | Escape Capsule: Explicit State Is Robust and Scalable
Shriram Rajagopalan, Dan Williams 0001, Hani Jamjoom, Andy Warfield |
HotOS | 2 |
| 2013 | Split/Merge: System Support for Elastic Execution in Virtual Middleboxes
Shriram Rajagopalan, Dan Williams 0001, Hani Jamjoom, Andy Warfield |
NSDI | 2 |
| 2012 | The Xen-Blanket: virtualize once, run everywhereabstractCurrent Infrastructure as a Service (IaaS) clouds operate in isolation from each other. Slight variations in the virtual machine (VM) abstractions or underlying hypervisor services prevent unified access and control across clouds. While standardization efforts aim to address these issues, they will take years to be agreed upon and adopted, if ever. Instead of standardization, which is by definition provider-centric, we advocate a user-centric approach that gives users an unprecedented level of control over the virtualization layer. We introduce the Xen-Blanket, a thin, immediately deployable virtualization layer that can homogenize today's diverse cloud infrastructures. We have deployed the Xen-Blanket across Amazon's EC2, an enterprise cloud, and a private setup at Cornell University. We show that a user-centric approach to homogenize clouds can achieve similar performance to a paravirtualized environment while enabling previously impossible tasks like cross-provider live migration. The Xen-Blanket also allows users to exploit resource management opportunities like oversubscription, and ultimately can reduce costs for users. Dan Williams 0001, Hani Jamjoom, Hakim Weatherspoon |
EuroSys | 1 |
| 2011 | Logical attestation: an authorization architecture for trustworthy computingabstractThis paper describes the design and implementation of a new operating system authorization architecture to support trustworthy computing. Called logical attestation, this architecture provides a sound framework for reasoning about run time behavior of applications. Logical attestation is based on attributable, unforgeable statements about program properties, expressed in a logic. These statements are suitable for mechanical processing, proof construction, and verification; they can serve as credentials, support authorization based on expressive authorization policies, and enable remote principals to trust software components without restricting the local user's choice of binary implementations. Emin Gün Sirer, Willem de Bruijn, Patrick Reynolds, Alan Shieh, Kevin Walsh 0001, Dan Williams 0001, Fred B. Schneider |
SOSP | 6 |
| 2011 | Overdriver: handling memory overload in an oversubscribed cloudabstractWith the intense competition between cloud providers, oversubscription is increasingly important to maintain profitability. Oversubscribing physical resources is not without consequences: it increases the likelihood of overload. Memory overload is particularly damaging. Contrary to traditional views, we analyze current data center logs and realistic Web workloads to show that overload is largely transient: up to 88.1% of overloads last for less than 2 minutes. Regarding overload as a continuum that includes both transient and sustained overloads of various durations points us to consider mitigation approaches also as a continuum, complete with tradeoffs with respect to application performance and data center overhead. In particular, heavyweight techniques, like VM migration, are better suited to sustained overloads, whereas lightweight approaches, like network memory, are better suited to transient overloads. We present Overdriver, a system that adaptively takes advantage of these tradeoffs, mitigating all overloads within 8% of well-provisioned performance. Furthermore, under reasonable oversubscription ratios, where transient overload constitutes the vast majority of overloads, Overdriver requires 15% of the excess space and generates a factor of four less network traffic than a migration-only approach. Dan Williams 0001, Hani Jamjoom, Yew-Huey Liu, Hakim Weatherspoon |
VEE | 1 |
| 2008 | Device Driver Safety Through a Reference Validation Mechanism
Dan Williams 0001, Patrick Reynolds, Kevin Walsh 0001, Emin Gün Sirer, Fred B. Schneider |
OSDI | 1 |
| 2005 | Nexus: a new operating system for trustworthy computingabstractTamper-proof coprocessors for secure computing are poised to become a standard hardware feature on future computers. Such hardware provides the primitives necessary to support trustworthy computing applications, that is, applications that can provide strong guarantees about their run time behavior. Alan Shieh, Dan Williams 0001, Emin Gün Sirer, Fred B. Schneider |
SOSP | 2 |
| 2004 | Optimal Parameter Selection for Efficient Memory Integrity Verification Using Merkle Hash TreesabstractA secure, tamperproof execution environment is critical for trustworthy network computing. Newly emerging hardware, such as those developed as part of the TCPA and Palladium initiatives, enables operating systems to implement such an environment through Merkle hash trees. We examine the selection of optimal parameters, namely blocksize and tree depth, for Merkle hash trees based on the size of the memory region to be protected and the number of memory updates between updates of the hash tree. We analytically derive an expression for the cost of updating the hash tree, show that there is an optimal blocksize for the leaves of a Merkle tree for a given file size and update interval that minimizes the cost of update operations, and describe a general method by which the parameters of such a tree can be determined optimally. Dan Williams 0001, Emin Gün Sirer |
NCA | 1 |