EDBT 2026 Demo / reviewers in the wild / expert
Alan M. Dunn
dblp:98/9256
· DBLP profile ↗
10ranked-venue papers
2as first author
0since 2021 · last 2016
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 5Software engineering, systems software and programming languages · 5 · 1 first-authorSecurity and privacy · 3 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
8 papers |
Systems and software security · 34% Authentication and access control · 33% Privacy and data protection · 13% | |
| Software engineering, system software, and programming languages
5 papers |
Operating systems · 81% Concurrent programming · 19% |
Topics — the 21 heaviest of 22, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security › trusted computing
trusted execution |
0.4 | 2 | 2016 | Sego: Pervasive Trusted Metadata for Efficiently Verified Untrusted System Services · ASPLOS 2016 InkTag: secure applications on an untrusted operating system · ASPLOS 2013 |
Authentication and access control
access control |
0.4 | 2 | 2014 | Application-Defined Decentralized Access Control · USENIX ATC 2014 Enabling Fine-Grained Permissions for Augmented Reality Applications with Recognizers · USENIX Security Symposium 2013 |
Authentication and access control › access control › distributed access control
decentralized access control |
0.2 | 1 | 2014 | Application-Defined Decentralized Access Control · USENIX ATC 2014 |
Privacy and data protection
anonymity |
0.2 | 1 | 2013 | Anon-Pass: Practical Anonymous Subscriptions · IEEE Symposium on Security and Privacy 2013 |
Authentication and access control
anonymous authentication |
0.2 | 1 | 2013 | Anon-Pass: Practical Anonymous Subscriptions · IEEE Symposium on Security and Privacy 2013 |
Privacy and data protection › anonymity
unlinkability |
0.2 | 1 | 2013 | Anon-Pass: Practical Anonymous Subscriptions · IEEE Symposium on Security and Privacy 2013 |
Systems and software security › operating system security
untrusted operating system |
0.2 | 1 | 2013 | InkTag: secure applications on an untrusted operating system · ASPLOS 2013 |
Operating systems › virtualization
hypervisor |
0.2 | 1 | 2013 | InkTag: secure applications on an untrusted operating system · ASPLOS 2013 |
Operating systems
virtualization |
0.2 | 1 | 2013 | InkTag: secure applications on an untrusted operating system · ASPLOS 2013 |
Concurrent programming
concurrency control |
0.1 | 1 | 2012 | Improving server applications with system transactions · EuroSys 2012 |
Systems and software security › operating system security
kernel integrity |
0.1 | 1 | 2011 | Ensuring operating system kernel integrity with OSck · ASPLOS 2011 |
Malware analysis
malware detection evasion |
0.1 | 1 | 2011 | Cloaking Malware with the Trusted Platform Module · USENIX Security Symposium 2011 |
Systems and software security
operating system security |
0.1 | 1 | 2011 | Ensuring operating system kernel integrity with OSck · ASPLOS 2011 |
Malware analysis
rootkit detection |
0.1 | 1 | 2011 | Ensuring operating system kernel integrity with OSck · ASPLOS 2011 |
Hardware security and side channels
trusted execution environments |
0.1 | 1 | 2011 | Cloaking Malware with the Trusted Platform Module · USENIX Security Symposium 2011 |
Hardware security and side channels › trusted execution environments
trusted platform module |
0.1 | 1 | 2011 | Cloaking Malware with the Trusted Platform Module · USENIX Security Symposium 2011 |
Operating systems › resource management › storage management › file systems
file system verification |
0.1 | 1 | 2016 | Sego: Pervasive Trusted Metadata for Efficiently Verified Untrusted System Services · ASPLOS 2016 |
Virtual and augmented reality › augmented reality
augmented reality applications |
0.0 | 1 | 2013 | Enabling Fine-Grained Permissions for Augmented Reality Applications with Recognizers · USENIX Security Symposium 2013 |
Authentication and access control › access control models
attribute-based access control |
0.0 | 1 | 2013 | InkTag: secure applications on an untrusted operating system · ASPLOS 2013 |
Authentication and access control › user authentication
credential-based authentication |
0.0 | 1 | 2013 | Anon-Pass: Practical Anonymous Subscriptions · IEEE Symposium on Security and Privacy 2013 |
Operating systems › resource management › memory management
memory protection |
0.0 | 1 | 2012 | Eternal Sunshine of the Spotless Machine: Protecting Privacy with Ephemeral Channels · OSDI 2012 |
Methods — techniques the papers use, named apart from their topics
hypervisor-based isolation · 0.5fault injection · 0.5paraverification · 0.3type inference · 0.2concurrent integrity checking · 0.2system transactions · 0.1cloaking · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2016 | Sego: Pervasive Trusted Metadata for Efficiently Verified Untrusted System ServicesabstractSego is a hypervisor-based system that gives strong privacy and integrity guarantees to trusted applications, even when the guest operating system is compromised or hostile. Sego verifies operating system services, like the file system, instead of replacing them. By associating trusted metadata with user data across all system devices, Sego verifies system services more efficiently than previous systems, especially services that depend on data contents. We extensively evaluate Sego's performance on real workloads and implement a kernel fault injector to validate Sego's file system-agnostic crash consistency and recovery protocol. Youngjin Kwon, Alan M. Dunn, Michael Z. Lee, Owen S. Hofmann, Yuanzhong Xu, Emmett Witchel |
ASPLOS | 2 |
| 2014 | Application-Defined Decentralized Access Control
Yuanzhong Xu, Alan M. Dunn, Owen S. Hofmann, Michael Z. Lee, Syed Akbar Mehdi, Emmett Witchel |
USENIX ATC | 2 |
| 2013 | InkTag: secure applications on an untrusted operating systemabstractInkTag is a virtualization-based architecture that gives strong safety guarantees to high-assurance processes even in the presence of a malicious operating system. InkTag advances the state of the art in untrusted operating systems in both the design of its hypervisor and in the ability to run useful applications without trusting the operating system. We introduce paraverification, a technique that simplifies the InkTag hypervisor by forcing the untrusted operating system to participate in its own verification. Attribute-based access control allows trusted applications to create decentralized access control policies. InkTag is also the first system of its kind to ensure consistency between secure data and metadata, ensuring recoverability in the face of system crashes. Owen S. Hofmann, Sangman Kim, Alan M. Dunn, Michael Z. Lee, Emmett Witchel |
ASPLOS | 3 |
| 2013 | Operating System Support for Augmented Reality Applications
Loris D'Antoni, Alan M. Dunn, Suman Jana, Tadayoshi Kohno, Benjamin Livshits, David Molnar, Alexander Moshchuk, Eyal Ofek, Franziska Roesner, T. Scott Saponas, Margus Veanes, Helen J. Wang |
HotOS | 2 |
| 2013 | Anon-Pass: Practical Anonymous SubscriptionsabstractWe present the design, security proof, and implementation of an anonymous subscription service. Users register for the service by providing some form of identity, which might or might not be linked to a real-world identity such as a credit card, a web login, or a public key. A user logs on to the system by presenting a credential derived from information received at registration. Each credential allows only a single login in any authentication window, or epoch. Logins are anonymous in the sense that the service cannot distinguish which user is logging in any better than random guessing. This implies unlinkability of a user across different logins. We find that a central tension in an anonymous subscription service is the service provider's desire for a long epoch (to reduce server-side computation) versus users' desire for a short epoch (so they can repeatedly "re-anonymize" their sessions). We balance this tension by having short epochs, but adding an efficient operation for clients who do not need unlinkability to cheaply re-authenticate themselves for the next time period. We measure performance of a research prototype of our protocol that allows an independent service to offer anonymous access to existing services. We implement a music service, an Android-based subway-pass application, and a web proxy, and show that adding anonymity adds minimal client latency and only requires 33 KB of server memory per active user. Michael Z. Lee, Alan M. Dunn, Brent Waters, Emmett Witchel, Jonathan Katz |
IEEE Symposium on Security and Privacy | 2 |
| 2013 | Enabling Fine-Grained Permissions for Augmented Reality Applications with Recognizers
Suman Jana, David Molnar, Alexander Moshchuk, Alan M. Dunn, Benjamin Livshits, Helen J. Wang, Eyal Ofek |
USENIX Security Symposium | 4 |
| 2012 | Improving server applications with system transactionsabstractServer applications must process requests as quickly as possible. Because some requests depend on earlier requests, there is often a tension between increasing throughput and maintaining the proper semantics for dependent requests. Operating system transactions make it easier to write reliable, high-throughput server applications because they allow the application to execute non-interfering requests in parallel, even if the requests operate on OS state, such as file data. Sangman Kim, Michael Z. Lee, Alan M. Dunn, Owen S. Hofmann, Emmett Witchel, Donald E. Porter |
EuroSys | 3 |
| 2012 | Eternal Sunshine of the Spotless Machine: Protecting Privacy with Ephemeral Channels
Alan M. Dunn, Michael Z. Lee, Suman Jana, Sangman Kim, Mark Silberstein, Yuanzhong Xu, Vitaly Shmatikov, Emmett Witchel |
OSDI | 1 |
| 2011 | Ensuring operating system kernel integrity with OSckabstractKernel rootkits that modify operating system state to avoid detection are a dangerous threat to system security. This paper presents OSck, a system that discovers kernel rootkits by detecting malicious modifications to operating system data. OSck integrates and extends existing techniques for detecting rootkits, and verifies safety properties for large portions of the kernel heap with minimal overhead. We deduce type information for verification by analyzing unmodified kernel source code and in-memory kernel data structures.High-performance integrity checks that execute concurrently with a running operating system create data races, and we demonstrate a deterministic solution for ensuring kernel memory is in a consistent state. We introduce two new classes of kernel rootkits that are undetectable by current systems, motivating the need for the OSck API that allows kernel developers to conveniently specify arbitrary integrity properties. Owen S. Hofmann, Alan M. Dunn, Sangman Kim, Indrajit Roy 0001, Emmett Witchel |
ASPLOS | 2 |
| 2011 | Cloaking Malware with the Trusted Platform Module
Alan M. Dunn, Owen S. Hofmann, Brent Waters, Emmett Witchel |
USENIX Security Symposium | 1 |