EDBT 2026 Demo / reviewers in the wild / expert
David D. Clark
dblp:c/DavidDClark
· DBLP profile ↗
31ranked-venue papers
12as first author
2since 2021 · last 2025
0000-0002-2676-889XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 23 · 10 first-authorSecurity and privacy · 3 · 1 first-author · 1 since 2021Systems, architecture and hardware · 2Software engineering, systems software and programming languages · 2 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Computer networks
18 papers |
Network management and operations · 35% Network measurement and analytics · 32% Routing and switching · 14% | |
| Human-computer interaction and pervasive computing
1 paper |
Collaborative and social computing · 50% User interface design and tools · 50% | |
| Network and information security
5 papers |
Network security · 58% Web and mobile security · 40% Authentication and access control · 1% |
Topics — the 30 heaviest of 56, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Network security › routing security › interdomain routing security
BGP hijacking |
0.4 | 1 | 2019 | Profiling BGP Serial Hijackers: Capturing Persistent Misbehavior in the Global Routing Table · Internet Measurement Conference 2019 |
Network management and operations
network monitoring |
0.3 | 1 | 2018 | Advancing the Art of Internet Edge Outage Detection · Internet Measurement Conference 2018 |
Network management and operations › fault management
outage detection |
0.3 | 1 | 2018 | Advancing the Art of Internet Edge Outage Detection · Internet Measurement Conference 2018 |
Network measurement and analytics › network tomography
topology inference |
0.2 | 1 | 2016 | bdrmap: Inference of Borders Between IP Networks · Internet Measurement Conference 2016 |
Routing and switching › inter-domain routing
BGP |
0.1 | 1 | 2019 | Profiling BGP Serial Hijackers: Capturing Persistent Misbehavior in the Global Routing Table · Internet Measurement Conference 2019 |
Routing and switching › inter-domain routing
inter-domain routing security |
0.1 | 1 | 2019 | Profiling BGP Serial Hijackers: Capturing Persistent Misbehavior in the Global Routing Table · Internet Measurement Conference 2019 |
Network management and operations › fault management
fault diagnosis |
0.1 | 1 | 2018 | Advancing the Art of Internet Edge Outage Detection · Internet Measurement Conference 2018 |
Routing and switching
inter-domain routing |
0.1 | 2 | 2007 | NIRA: a new inter-domain routing architecture · IEEE/ACM Trans. Netw. 2007 DARPA interdomain addressing (panel session, title only) · SIGCOMM 1985 |
Internet architecture and protocols › network topology
autonomous system topology |
0.1 | 1 | 2016 | bdrmap: Inference of Borders Between IP Networks · Internet Measurement Conference 2016 |
Routing and switching › routing › routing design
routing architecture |
0.1 | 1 | 2007 | NIRA: a new inter-domain routing architecture · IEEE/ACM Trans. Netw. 2007 |
Network measurement and analytics
latency measurement |
0.1 | 1 | 2014 | Challenges in Inferring Internet Interdomain Congestion · Internet Measurement Conference 2014 |
Network optimization and economics
network economics |
0.1 | 1 | 2005 | Tussle in cyberspace: defining tomorrow's internet · IEEE/ACM Trans. Netw. 2005 |
Network management and operations › network automation
autonomic network management |
0.0 | 1 | 2003 | A knowledge plane for the internet · SIGCOMM 2003 |
Internet architecture and protocols › future internet architecture
knowledge plane |
0.0 | 1 | 2003 | A knowledge plane for the internet · SIGCOMM 2003 |
Network optimization and economics › resource allocation
bandwidth allocation |
0.0 | 1 | 1998 | Explicit allocation of best-effort packet delivery service · IEEE/ACM Trans. Netw. 1998 |
Internet architecture and protocols › buffer management
packet dropping |
0.0 | 1 | 1998 | Explicit allocation of best-effort packet delivery service · IEEE/ACM Trans. Netw. 1998 |
Internet architecture and protocols
quality of service |
0.0 | 1 | 1998 | Explicit allocation of best-effort packet delivery service · IEEE/ACM Trans. Netw. 1998 |
Internet architecture and protocols
traffic management |
0.0 | 1 | 1998 | Explicit allocation of best-effort packet delivery service · IEEE/ACM Trans. Netw. 1998 |
Internet architecture and protocols
network evolution |
0.0 | 1 | 2005 | Tussle in cyberspace: defining tomorrow's internet · IEEE/ACM Trans. Netw. 2005 |
Internet architecture and protocols › high-speed networks
gigabit networking |
0.0 | 1 | 1992 | An Overview of the AURORA Gigabit Testbed · INFOCOM 1992 |
Internet architecture and protocols › integrated services
integrated services packet network |
0.0 | 1 | 1992 | Supporting Real-Time Applications in an Integrated Services Packet Network: Architecture and Mechanism · SIGCOMM 1992 |
Internet architecture and protocols
packet scheduling |
0.0 | 1 | 1992 | Supporting Real-Time Applications in an Integrated Services Packet Network: Architecture and Mechanism · SIGCOMM 1992 |
Wireless networking
real-time service |
0.0 | 1 | 1992 | Supporting Real-Time Applications in an Integrated Services Packet Network: Architecture and Mechanism · SIGCOMM 1992 |
Internet of things and sensor networks › wireless sensor network
testbed |
0.0 | 1 | 1992 | An Overview of the AURORA Gigabit Testbed · INFOCOM 1992 |
Internet architecture and protocols › protocol design
application level framing |
0.0 | 1 | 1990 | Architectural Considerations for a New Generation of Protocols · SIGCOMM 1990 |
Internet architecture and protocols › protocol implementation
integrated layer processing |
0.0 | 1 | 1990 | Architectural Considerations for a New Generation of Protocols · SIGCOMM 1990 |
Internet architecture and protocols › network architecture design › layered architecture
protocol architecture |
0.0 | 1 | 1990 | Architectural Considerations for a New Generation of Protocols · SIGCOMM 1990 |
Network measurement and analytics › traffic measurement
traffic monitoring |
0.0 | 1 | 1998 | Explicit allocation of best-effort packet delivery service · IEEE/ACM Trans. Netw. 1998 |
Authentication and access control › security policy
integrity policy |
0.0 | 1 | 1987 | A Comparison of Commercial and Military Computer Security Policies · S&P 1987 |
Cryptographic primitives and cryptanalysis
message authentication codes |
0.0 | 1 | 1987 | A Comparison of Commercial and Military Computer Security Policies · S&P 1987 |
Methods — techniques the papers use, named apart from their topics
machine learning · 0.8feature engineering · 0.8time series latency probes · 0.3traceroute analysis · 0.2time sequence latency probing · 0.2round-trip delay measurement · 0.2routing protocol design · 0.1architectural analysis · 0.1cognitive systems · 0.0artificial intelligence · 0.0policy comparison · 0.0type extension · 0.0kernel complexity analysis · 0.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Graffiti: Enabling an Ecosystem of Personalized and Interoperable Social Applications
Theia Henderson, David R. Karger, David D. Clark |
UIST | 3 |
| 2022 | Jitterbug: A New Framework for Jitter-Based Congestion Inference
Esteban Carisimo, Ricky K. P. Mok, David D. Clark, K. C. Claffy |
PAM | 3 |
| 2020 | To Filter or Not to Filter: Measuring the Benefits of Registering in the RPKI Today
Cecilia Testart, Philipp Richter, Alistair King, Alberto Dainotti, David D. Clark |
PAM | 5 |
| 2019 | Profiling BGP Serial Hijackers: Capturing Persistent Misbehavior in the Global Routing TableabstractBGP hijacks remain an acute problem in today's Internet, with widespread consequences. While hijack detection systems are readily available, they typically rely on a priori prefix-ownership information and are reactive in nature. In this work, we take on a new perspective on BGP hijacking activity: we introduce and track the long-term routing behavior of serial hijackers, networks that repeatedly hijack address blocks for malicious purposes, often over the course of many months or even years. Based on a ground truth dataset that we construct by extracting information from network operator mailing lists, we illuminate the dominant routing characteristics of serial hijackers, and how they differ from legitimate networks. We then distill features that can capture these behavioral differences and train a machine learning model to automatically identify Autonomous Systems (ASes) that exhibit characteristics similar to serial hijackers. Our classifier identifies ≈ 900 ASes with similar behavior in the global IPv4 routing table. We analyze and categorize these networks, finding a wide range of indicators of malicious activity, misconfiguration, as well as benign hijacking activity. Our work presents a solid first step towards identifying and understanding this important category of networks, which can aid network operators in taking proactive measures to defend themselves against prefix hijacking and serve as input for current and future detection systems. Cecilia Testart, Philipp Richter, Alistair King, Alberto Dainotti, David D. Clark |
Internet Measurement Conference | 5 |
| 2018 | Advancing the Art of Internet Edge Outage Detection
Philipp Richter, Ramakrishna Padmanabhan, Neil Spring, Arthur W. Berger, David D. Clark |
Internet Measurement Conference | 5 |
| 2018 | Inferring persistent interdomain congestionabstractThere is significant interest in the technical and policy communities regarding the extent, scope, and consumer harm of persistent interdomain congestion. We provide empirical grounding for discussions of interdomain congestion by developing a system and method to measure congestion on thousands of interdomain links without direct access to them. We implement a system based on the Time Series Latency Probes (TSLP) technique that identifies links with evidence of recurring congestion suggestive of an under-provisioned link. We deploy our system at 86 vantage points worldwide and show that congestion inferred using our lightweight TSLP method correlates with other metrics of interconnection performance impairment. We use our method to study interdomain links of eight large U.S. broadband access providers from March 2016 to December 2017, and validate our inferences against ground-truth traffic statistics from two of the providers. For the period of time over which we gathered measurements, we did not find evidence of widespread endemic congestion on interdomain links between access ISPs and directly connected transit and content providers, although some such links exhibited recurring congestion patterns. We describe limitations, open challenges, and a path toward the use of this method for large-scale third-party monitoring of the Internet interconnection ecosystem. Amogh Dhamdhere, David D. Clark, Alexander Gamero-Garrido, Matthew J. Luckie, Ricky K. P. Mok, Gautam Akiwate, Kabir Gogia, Vaibhav Bajpai, Alex C. Snoeren, K. C. Claffy |
SIGCOMM | 2 |
| 2016 | bdrmap: Inference of Borders Between IP Networks
Matthew J. Luckie, Amogh Dhamdhere, Bradley Huffaker, David D. Clark, K. C. Claffy |
Internet Measurement Conference | 4 |
| 2014 | Challenges in Inferring Internet Interdomain CongestionabstractWe introduce and demonstrate the utility of a method to localize and quantify inter-domain congestion in the Internet. Our Time Sequence Latency Probes (TSLP) method depends on two facts: Internet traffic patterns are typically diurnal, and queues increase packet delay through a router during periods of adjacent link congestion. Repeated round trip delay measurements from a single test point to the two edges of a congested link will show sustained increased latency to the far (but not to the near) side of the link, a delay pattern that differs from the typical diurnal pattern of an uncongested link. We describe our technique and its surprising potential,carefully analyze the biggest challenge with the methodology (interdomain router-level topology inference), describe other less severe challenges, and present initial results that are sufficiently promising to motivate further attention to overcoming the challenges. Matthew J. Luckie, Amogh Dhamdhere, David D. Clark, Bradley Huffaker, K. C. Claffy |
Internet Measurement Conference | 3 |
| 2007 | NIRA: a new inter-domain routing architecture
Xiaowei Yang 0001, David D. Clark, Arthur W. Berger |
IEEE/ACM Trans. Netw. | 2 |
| 2005 | Tussle in cyberspace: defining tomorrow's internetabstractThe architecture of the Internet is based on a number of principles, including the self-describing datagram packet, the end-to-end arguments, diversity in technology and global addressing. As the Internet has moved from a research curiosity to a recognized component of mainstream society, new requirements have emerged that suggest new design principles, and perhaps suggest that we revisit some old ones. This paper explores one important reality that surrounds the Internet today: different stakeholders that are part of the Internet milieu have interests that may be adverse to each other, and these parties each vie to favor their particular interests. We call this process "the tussle". Our position is that accommodating this tussle is crucial to the evolution of the network's technical architecture. We discuss some examples of tussle, and offer some technical design principles that take it into account. David D. Clark, John Wroclawski, Karen R. Sollins, Bob Braden |
IEEE/ACM Trans. Netw. | 1 |
| 2003 | A knowledge plane for the internetabstractWe propose a new objective for network research: to build a fundamentally different sort of network that can assemble itself given high level instructions, reassemble itself as requirements change, automatically discover when something goes wrong, and automatically fix a detected problem or explain why it cannot do so.We further argue that to achieve this goal, it is not sufficient to improve incrementally on the techniques and algorithms we know today. Instead, we propose a new construct, the Knowledge Plane, a pervasive system within the network that builds and maintains high-level models of what the network is supposed to do, in order to provide services and advice to other elements of the network. The knowledge plane is novel in its reliance on the tools of AI and cognitive systems. We argue that cognitive techniques, rather than traditional algorithmic approaches, are best suited to meeting the uncertainties and complexity of our objective. David D. Clark, Craig Partridge, J. Christopher Ramming, John Wroclawski |
SIGCOMM | 1 |
| 2002 | Tussle in cyberspace: defining tomorrow's internetabstractThe architecture of the Internet is based on a number of principles, including the self-describing datagram packet, the end to end arguments, diversity in technology and global addressing. As the Internet has moved from a research curiosity to a recognized component of mainstream society, new requirements have emerged that suggest new design principles, and perhaps suggest that we revisit some old ones. This paper explores one important reality that surrounds the Internet today: different stakeholders that are part of the Internet milieu have interests that may be adverse to each other, and these parties each vie to favor their particular interests. We call this process "the tussle". Our position is that accommodating this tussle is crucial to the evolution of the network's technical architecture. We discuss some examples of tussle, and offer some technical design principles that take it into account. David D. Clark, John Wroclawski, Karen R. Sollins, Bob Braden |
SIGCOMM | 1 |
| 2001 | Rethinking the design of the Internet: the end-to-end arguments vs. the brave new worldabstractThis article looks at the Internet and the changing set of requirements for the Internet as it becomes more commercial, more oriented toward the consumer, and used for a wider set of purposes. We discuss a set of principles that have guided the design of the Internet, called the end-to-end arguments, and we conclude that there is a risk that the range of new requirements now emerging could have the consequence of compromising the Internet's original design principles. Were this to happen, the Internet might lose some of its key features, in particular its ability to support new and unanticipated applications. We link this possible outcome to a number of trends: the rise of new stakeholders in the Internet, in particular Internet service providers; new government interests; the changing motivations of a growing user base; and the tension between the demand for trustworthy overall operation and the inability to trust the behavior of individual users. Marjory S. Blumenthal, David D. Clark |
ACM Trans. Internet Techn. | 2 |
| 1998 | Explicit allocation of best-effort packet delivery serviceabstractThis paper presents the "allocated-capacity" framework for providing different levels of best-effort service in times of network congestion. The "allocated-capacity" framework-extensions to the Internet protocols and algorithms-can allocate bandwidth to different users in a controlled and predictable way during network congestion. The framework supports two complementary ways of controlling the bandwidth allocation: sender-based and receiver-based. In today's heterogeneous and commercial Internet the framework can serve as a basis for charging for usage and for more efficiently utilizing the network resources. We focus on algorithms for essential components of the framework: a differential dropping algorithm for network routers and a tagging algorithm for profile meters at the edge of the network for bulk-data transfers. We present simulation results to illustrate the effectiveness of the combined algorithms in controlling transmission control protocol (TCP) traffic to achieve certain targeted sending rates. David D. Clark, Wenjia Fang |
IEEE/ACM Trans. Netw. | 1 |
| 1993 | The AURORA Gigabit Testbed
David D. Clark, Bruce S. Davie, David J. Farber, Inder S. Gopal, Bharath K. Kadaba, W. David Sincoskie, Jonathan M. Smith, David L. Tennenhouse |
Comput. Networks ISDN Syst. | 1 |
| 1992 | An Overview of the AURORA Gigabit TestbedabstractAURORA is one of five US testbeds charged with exploring applications of, and technologies necessary for, networks operating at gigabit per second or higher bandwidths. The authors provide an overview of the goals and methodologies employed in AURORA and report preliminary results from the first year of research. AURORA is an experiment in collaboration, where government support has spurred interaction among centers of excellence in industry, academia, and government. The emphasis of the AURORA testbed is research into the supporting technologies for gigabit networking. The targets include new software architectures, network abstractions, hardware technologies, and applications. The AURORA testbed will provide a platform in which researchers can explore business and scientific applications of gigabit networks, while evolving the network architecture to meet the needs of these emerging applications.> David D. Clark, David L. Tennenhouse, David J. Farber, Jonathan M. Smith, Bruce S. Davie, W. David Sincoskie, Inder S. Gopal, Bharath K. Kadaba |
INFOCOM | 1 |
| 1992 | An Admission Control Algorithm for Predictive Real-Time Service (Extended Abstract)
Sugih Jamin, Scott Shenker, Lixia Zhang 0001, David D. Clark |
NOSSDAV | 4 |
| 1992 | Supporting Real-Time Applications in an Integrated Services Packet Network: Architecture and MechanismabstractThis paper considers the support of real-time applications in an Integrated Services Packet Network (ISPN). We first review the characteristics of real-time applications. We observe that, contrary to the popular view that real-time applications necessarily require a fixed delay bound, some real-time applications are more flexible and can adapt to current network conditions. We then propose an ISPN architecture that supports two distinct kinds of real-time service: guaranteed service, which is the traditional form of real-time service discussed in most of the literature and involves pre-computed worst-case delay bounds, and predicted service which uses the measure performance of the network in computing delay bounds. We then propose a packet scheduling mechanism that can support both of these real-time services as well as accommodate datagram traffic. We also discuss two other aspects of an overall ISPN architecture: the service interface and the admission control criteria. David D. Clark, Scott Shenker, Lixia Zhang 0001 |
SIGCOMM | 1 |
| 1991 | Observations on the Dynamics of a Congestion Control Algorithm: The Effects of Two-Way TrafficabstractWe use simulation to study the dynamics of the congestion cent rol algorithm embedded in the BSD 4.3-Tahoe TCP implementation.We investigate the simple case of a few TCP connections, originating and terminating at the same pair of hosts, using a single bottleneck link.This work is an extension of our earlier work ([16]), where one-way traffic (i.e., all of the sources are on the same host and all of the destinations are on the other host) was studied.In this paper we investigate the dynamics that results from two-way traffic (in which there are data sources on both hosts).We find that the one-way traffic clustering and loss-synchronization phenomena d~cussed in [16] persist in this new situation, albeit in a slightly modified form.In addition, there are two new phenomena not present in the earlier study:(1) ACK-compression, which is due to the interaction of data and ACK packets and gives rise to rapid fluctuations in queue length, and (2) an out-of-phase queue-synchronization mode, which keeps link utilization less than optimal even in the limit of very large buffers.These phenomena are helpful in understanding results from an earlier study of network oscillations ([19]). Lixia Zhang 0001, Scott Shenker, David D. Clark |
SIGCOMM | 3 |
| 1990 | Architectural Considerations for a New Generation of ProtocolsabstractThe current generation of protocol architectures, such as TCP/IP or the ISO suite, seem successful at meeting the demands of todays networks. However, a number of new requirements have been proposed for the networks of tomorrow, and some innovation in protocol structuring may be necessary. In this paper, we review some key requirements for tomorrow's networks, and propose some architectural principles to structure a new generation of protocols. In particular, this paper identifies two new design principles, Application Level Framing and Integrated Layer Processing. Additionally, it identifies the presentation layer as a key aspect of overall protocol performance. David D. Clark, David L. Tennenhouse |
SIGCOMM | 1 |
| 1988 | An analysis of TCP processing overheadabstractThe authors report a preliminary analysis of the processing overhead of the transport protocol TCP (Transmission Control Protocol) in which they estimate the possible performance range of the protocol. The analysis was performed by compiling a version of TCP and counting the number of the instructions in the common path. The analysis suggests that fewer than 200 instructions are required to process a TCP packet in the normal case. This number is small enough to support very high-speed transmission if it were the major overhead. The authors offer some speculations about the actual source of processing overhead in network protocols.> David D. Clark, John Romkey, Howard C. Salwen |
LCN | 1 |
| 1988 | The design philosophy of the DARPA internet protocolsabstractThe Internet protocol suite, TCP/IP, was first proposed fifteen years ago. It was developed by the Defense Advanced Research Projects Agency (DARPA), and has been used widely in military and commercial systems. While there have been papers and specifications that describe how the protocols work, it is sometimes difficult to deduce from these why the protocol is as it is. For example, the Internet protocol is based on a connectionless or datagram mode of service. The motivation for this has been greatly misunderstood. This paper attempts to capture some of the early reasoning which shaped the Internet protocols. David D. Clark |
SIGCOMM | 1 |
| 1987 | A Comparison of Commercial and Military Computer Security PoliciesabstractMost discussions of computer security focus on control of disclosure. In Particular, the U.S. Department of Defense has developed a set of criteria for computer mechanisms to provide control of classified information. However, for that core of data processing concerned with business operation and control of assets, the primary security concern is data integrity. This paper presents a policy for data integrity based on commercial data processing practices, and compares the mechanisms needed for this policy with the mechanisms needed to enforce the lattice model for information security. We argue that a lattice model is not sufficient to characterize integrity policies, and that distinct mechanisms are needed to Control disclosure and to provide integrity. David D. Clark, D. R. Wilson |
S&P | 1 |
| 1985 | DARPA interdomain addressing (panel session, title only)
Vint Cerf, David D. Clark, Douglas Comer, Larry L. Peterson, Douglas B. Terry |
SIGCOMM | 2 |
| 1985 | The Structuring of Systems Using Upcalls
David D. Clark |
SOSP | 1 |
| 1985 | The Desktop Computer as a Network ParticipantabstractA desktop personal computer can be greatly extended in usefulness by attaching it to a local area network and implementing a full set of network protocols, just as one might provide for a mainframe computer. Such protocols are a set of tools that allow the desktop computer not just to access data elsewhere, but to participate in the computing milieu much more intensely. There are two challenges to this proposal. First, a personal computer may often be disconnected from the network, so it cannot track the network state and it must be able to discover and resynchronize with that state very quickly. Second, full protocol implementations have often been large and slow, two attributes that could be fatal in a small computer. This paper reports a network implementation for the IBM Personal Computer that uses several performance-oriented design techniques with wide applicability: an upcall/downcall organization that simplifies structure; implementation layers that do not always coincide with protocol specification layers; copy minimization; and tailoring of protocol implementations with knowledge of the application that will use them. The size and scale of the resulting package of programs, now in use in our laboratory for two years, is quite reasonable for a desktop computer and the techniques developed are applicable to a wider range of network protocol designs. Jerome H. Saltzer, David D. Clark, John Romkey, Wayne Gramlich |
IEEE J. Sel. Areas Commun. | 2 |
| 1984 | End-To-End Arguments in System DesignabstractThis paper presents a design principle that helps guide placement of functions among the modules of a distributed computer system. The principle, called the end-to-end argument, suggests that functions placed at low levels of a system may be redundant or of little value when compared with the cost of providing them at that low level. Examples discussed in the paper include bit-error recovery, security using encryption, duplicate message suppression, recovery from system crashes, and delivery acknowl-edgment. Low-level mechanisms to support these functions are justified only as performance enhance-ments. Jerome H. Saltzer, David P. Reed 0001, David D. Clark |
ACM Trans. Comput. Syst. | 3 |
| 1983 | Why a Ring?
Jerome H. Saltzer, Kenneth T. Pogran, David D. Clark |
Comput. Networks | 3 |
| 1981 | End-to-End Arguments in System Design
Jerome H. Saltzer, David P. Reed 0001, David D. Clark |
ICDCS | 3 |
| 1981 | Why a ring?abstractIn a world increasingly populated with Ethernets and Ethernet-like nets a few sites continue to experiment with rings of active repeaters for local data communication. This paper explores some of the engineering problems involved in designing a ring that has no central control, and then compared the M.I.T.-designed ring with Ethernet on a variety of operational and subtle technical grounds, on each of which the ring may possess important or interesting advantages. Jerome H. Saltzer, David D. Clark, Kenneth T. Pogran |
SIGCOMM | 2 |
| 1977 | The Multics Kernel Design ProjectabstractWe describe a plan to create an auditable version of Multics. The engineering experiments of that plan are now complete. Type extension as a design discipline has been demonstrated feasible, even for the internal workings of an operating system, where many subtle intermodule dependencies were discovered and controlled. Insight was gained into several tradeoffs between kernel complexity and user semantics. The performance and size effects of this work are encouraging. We conclude that verifiable operating system kernels may someday be feasible. Michael D. Schroeder, David D. Clark, Jerome H. Saltzer |
SOSP | 2 |