Peter Druschel

dblp:d/PDruschel · DBLP profile ↗
← Back
86ranked-venue papers
9as first author
4since 2021 · last 2025
0000-0002-7239-1114ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 30 · 2 first-authorSoftware engineering, systems software and programming languages · 22 · 3 first-authorSystems, architecture and hardware · 20 · 3 first-author · 1 since 2021Security and privacy · 12 · 3 since 2021Artificial intelligence and machine learning · 2Databases, data management, data science and information retrieval · 2 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2025 CoVault: Secure, Scalable Analytics of Personal Data
Roberta De Viti, Isaac Sheff, Noemi Glaeser, Baltasar Dinis, Rodrigo Rodrigues 0001, Bobby Bhattacharjee, Anwar Hithnawi, Deepak Garg 0001, Peter Druschel
USENIX Security Symposium9
2023 Groundhog: Efficient Request Isolation in FaaS
abstract
Security is a core responsibility for Function-as-a-Service (FaaS) providers. The prevailing approach isolates concurrent executions of functions in separate containers. However, successive invocations of the same function commonly reuse the runtime state of a previous invocation in order to avoid container cold-start delays. Although efficient, this container reuse has security implications for functions that are invoked on behalf of differently privileged users or administrative domains: bugs in a function's implementation --- or a third-party library/runtime it depends on --- may leak private data from one invocation of the function to a subsequent one.
Mohamed Alzayat, Jonathan Mace, Peter Druschel, Deepak Garg 0001
EuroSys3
2023 RR: A Fault Model for Efficient TEE Replication
Baltasar Dinis, Peter Druschel, Rodrigo Rodrigues 0001
NDSS2
2022 Pacer: Comprehensive Network Side-Channel Mitigation in the Cloud
Aastha Mehta, Mohamed Alzayat, Roberta De Viti, Björn B. Brandenburg, Peter Druschel, Deepak Garg 0001
USENIX Security Symposium5
2020 Finding Safety in Numbers with Secure Allegation Escrows
Venkat Arun, Aniket Kate, Deepak Garg 0001, Peter Druschel, Bobby Bhattacharjee
NDSS4
2019 Composing Abstractions using the null-Kernel
abstract
research-article Open Access Share on Composing Abstractions using the null-Kernel Authors: James Litton University of Maryland, Max Planck Institute for Software Systems University of Maryland, Max Planck Institute for Software SystemsView Profile , Deepak Garg Max Planck Institute for Software Systems Max Planck Institute for Software SystemsView Profile , Peter Druschel Max Planck Institute for Software Systems Max Planck Institute for Software SystemsView Profile , Bobby Bhattacharjee University of Maryland University of MarylandView Profile Authors Info & Claims HotOS '19: Proceedings of the Workshop on Hot Topics in Operating SystemsMay 2019 Pages 1–6https://doi.org/10.1145/3317550.3321450Published:13 May 2019Publication History 1citation1,283DownloadsMetricsTotal Citations1Total Downloads1,283Last 12 Months200Last 6 weeks13 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteeReaderPDF
James Litton, Deepak Garg 0001, Peter Druschel, Bobby Bhattacharjee
HotOS3
2019 enClosure: Group Communication via Encounter Closures
abstract
New applications enabled by personal smart devices and the Internet-of-Things (IoT) require communication in the context of periods of spatial co-location. Examples of this encounter-based communication (EbC) include social exchange among individuals who shared an experience, and interaction among personal and IoT devices that provide location-based services. Existing EbC systems are limited to communication among participants that share a direct encounter. This paper is inspired by two insights: (1) encounters also enable group communication among devices connected by paths in the encounter graph that is contextual, spontaneous, secure, and does not require users to reveal identifying or linkable information; and (2) addressing communication partners using encounter closures subject to causal, spatial, and temporal constraints enables powerful new forms of group communication. We present the design of enClosure, a service providing group communication based on encounter closures for mobile and IoT applications, and a prototype implementation for Android and the Microsoft Embedded Social Cloud platform. Using real-world traces, we show that enClosure provides a privacy-preserving, secure platform for a wide range of group communication applications ranging from connecting attendees of a large event and virtual guest books to disseminating health risk warnings, lost-and-found, and tracing missing persons.
Lillian Tsai, Roberta De Viti, Matthew Lentz, Stefan Saroiu, Bobby Bhattacharjee, Peter Druschel
MobiSys6
2019 enClosure: Group Communication via Encounter Closures
abstract
New applications enabled by personal smart devices and the Internet-of-Things (IoT) require communication in the context of an encounter (a period of spatial co-location). However, existing encounter-based communication (EbC) systems are limited to communication among participants that share a direct encounter. This work is inspired by two insights: (1) encounters also enable group communication among devices connected by paths in the encounter graph that is contextual, spontaneous, secure, and privacy-preserving; and (2) addressing communication partners using encounter closures subject to causal, spatial, and temporal constraints enables powerful new forms of group communication. We present the design of enClosure, a service providing group communication based on encounter closures for mobile and IoT applications, and a prototype implementation for Android and the Microsoft Embedded Social Cloud platform. Using real-world traces, we show that enClosure provides a privacy-preserving, secure platform for a wide range of group communication applications ranging from connecting attendees of a large event to disseminating health risk warnings and tracing missing persons.
Lillian Tsai, Roberta De Viti, Matthew Lentz, Stefan Saroiu, Bobby Bhattacharjee, Peter Druschel
MobiSys6
2019 ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK)
Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O. Duarte, Michael Sammler, Peter Druschel, Deepak Garg 0001
USENIX Security Symposium5
2018 Sonoloc: Scalable positioning of commodity mobile devices
abstract
We present Sonoloc, a mobile app and system that allows a set of co-located commodity smart devices to determine their relative positions without local infrastructure. Sonoloc enables users to address each other based on their relative positions at events like meetings, talks, or conferences. This capability can, for instance, aid spontaneous communication among users based on their relative position (e.g., in a given section of a room, at the same table, or in a given seat), facilitate interaction between speaker and audience in a lecture hall, and enable the distribution of materials, crowdsensing, and feedback collection based on users' location. Sonoloc can position any number of devices within acoustic range with a constant number of chirps emitted by a self-organized subset of devices. Our experimental evaluation shows that the system can locate up to hundreds of devices with an accuracy of tens of centimeters using up to 15 audio chirps emitted by dynamically selected devices, in actual rooms and despite substantial background noise.
Viktor Erdélyi, Trung-Kien Le 0002, Bobby Bhattacharjee, Peter Druschel, Nobutaka Ono
MobiSys4
2018 SeCloak: ARM Trustzone-based Mobile Peripheral Control
abstract
Reliable on-off control of peripherals on smart devices is a key to security and privacy in many scenarios. Journalists want to reliably turn off radios to protect their sources during investigative reporting. Users wish to ensure cameras and microphones are reliably off during private meetings. In this paper, we present SeCloak, an ARM TrustZone-based solution that ensures reliable on-off control of peripherals even when the platform software is compromised. We design a secure kernel that co-exists with software running on mobile devices (e.g., Android and Linux) without requiring any code modifications. An Android prototype demonstrates that mobile peripherals like radios, cameras, and microphones can be controlled reliably with a very small trusted computing base and with minimal performance overhead.
Matthew Lentz, Rijurekha Sen, Peter Druschel, Bobby Bhattacharjee
MobiSys3
2017 Qapla: Policy compliance for database-backed systems
Aastha Mehta, Eslam Elnikety, Katura Harvey, Deepak Garg 0001, Peter Druschel
USENIX Security Symposium5
2016 I-Pic: A Platform for Privacy-Compliant Image Capture
abstract
The ubiquity of portable mobile devices equipped with built-in cameras have led to a transformation in how and when digital images are captured, shared, and archived. Photographs and videos from social gatherings, public events, and even crime scenes are commonplace online. While the spontaneity afforded by these devices have led to new personal and creative outlets, privacy concerns of bystanders (and indeed, in some cases, unwilling subjects) have remained largely unaddressed. We present I-Pic, a trusted software platform that integrates digital capture with user-defined privacy. In I-Pic, users choose alevel of privacy (e.g., image capture allowed or not) based upon social context (e.g., out in public vs. with friends vs. at workplace). Privacy choices of nearby users are advertised via short-range radio, and I-Pic-compliant capture platforms generate edited media to conform to privacy choices of image subjects. I-Pic uses secure multiparty computation to ensure that users' visual features and privacy choices are not revealed publicly, regardless of whether they are the subjects of an image capture. Just as importantly, I-Pic preserves the ease-of-use and spontaneous nature of capture and sharing between trusted users. Our evaluation of I-Pic shows that a practical, energy-efficient system that conforms to the privacy choices of many users within a scene can be built and deployed using current hardware.
Paarijaat Aditya, Rijurekha Sen, Peter Druschel, Seong Joon Oh, Rodrigo Benenson, Mario Fritz, Bernt Schiele, Bobby Bhattacharjee, Tong Tong Wu
MobiSys3
2016 Privacy Capsules: Preventing Information Leaks by Mobile Apps
abstract
Preventing the leakage of user information via untrusted third-party apps is a key challenge in mobile privacy. We propose and evaluate privacy capsules (PCs), a platform execution model for mobile apps that prevents the flow of private information to untrusted parties by design. With PCs, apps execute in two sequential phases. In the unsealed phase, the app has no access to sensitive input but full access to untrusted network resources. In the sealed state, the untrusted app has access to sensitive input, but can no longer communicate with untrusted resources. Privacy capsules are implemented by the mobile platform, are language independent, and require few changes to apps. Using a prototype PC implementation in Android, we show that PCs have low performance and energy overhead, and are suitable for a large class of apps.
Raul Herbster, Scott DellaTorre, Peter Druschel, Bobby Bhattacharjee
MobiSys3
2016 Light-Weight Contexts: An OS Abstraction for Safety and Performance
James Litton, Anjo Vahldiek-Oberwagner, Eslam Elnikety, Deepak Garg 0001, Bobby Bhattacharjee, Peter Druschel
OSDI6
2016 Thoth: Comprehensive Policy Compliance in Data Retrieval Systems
Eslam Elnikety, Aastha Mehta, Anjo Vahldiek-Oberwagner, Deepak Garg 0001, Peter Druschel
USENIX Security Symposium5
2015 Oblivion: Mitigating Privacy Leaks by Controlling the Discoverability of Online Information
Milivoj Simeonovski, Fabian Bendun, Muhammad Rizwan Asghar, Michael Backes 0001, Ninja Marnau, Peter Druschel
ACNS6
2015 Guardat: enforcing data policies at the storage layer
abstract
In today's data processing systems, both the policies protecting stored data and the mechanisms for their enforcement are spread over many software components and configuration files, increasing the risk of policy violation due to bugs, vulnerabilities and misconfigurations. Guardat addresses this problem. Users, developers and administrators specify file protection policies declaratively, concisely and separate from code, and Guardat enforces these policies by mediating I/O in the storage layer. Policy enforcement relies only on the integrity of the Guardat controller and any external policy dependencies. The semantic gap between the storage layer enforcement and per-file policies is bridged using cryptographic attestations from Guardat. We present the design and prototype implementation of Guardat, enforce example policies in a Web server, and show experimentally that its overhead is low.
Anjo Vahldiek-Oberwagner, Eslam Elnikety, Aastha Mehta, Deepak Garg 0001, Peter Druschel, Rodrigo Rodrigues 0001, Johannes Gehrke, Ansley Post
EuroSys5
2015 Herd: A Scalable, Traffic Analysis Resistant Anonymity Network for VoIP Systems
abstract
Effectively anonymizing Voice-over-IP (VoIP) calls requires a scalable anonymity network that is resilient to traffic analysis and has sufficiently low delay for high-quality voice calls. The popular Tor anonymity network, for instance, is not designed for the former and cannot typically achieve the latter. In this paper, we present the design, implementation, and experimental evaluation of Herd, an anonymity network where a set of dedicated, fully interconnected cloud-based proxies yield suitably low-delay circuits, while untrusted superpeers add scalability. Herd provides caller/callee anonymity among the clients within a trust zone (e.g., jurisdiction) and under a strong adversarial model. Simulations based on a trace of 370 million mobile phone calls among 10.8 million users indicate that Herd achieves anonymity among millions of clients with low bandwidth requirements, and that superpeers decrease the bandwidth and CPU requirements of the trusted infrastructure by an order of magnitude. Finally, experiments using a prototype deployment on Amazon EC2 show that Herd has a delay low enough for high-quality calls in most cases.
Stevens Le Blond, David R. Choffnes, William Caldwell, Peter Druschel, Nicholas Merritt
SIGCOMM4
2014 BackRef: Accountability in Anonymous Communication Networks
Michael Backes 0001, Jeremy Clark, Aniket Kate, Milivoj Simeonovski, Peter Druschel
ACNS5
2014 EnCore: private, context-based communication for mobile social apps
abstract
Mobile social apps provide sharing and networking opportunities based on a user's location, activity, and set of nearby users. A platform for these apps must meet a wide range of communication needs while ensuring users' control over their privacy. In this paper, we introduce EnCore, a mobile platform that builds on secure encounters between pairs of devices as a foundation for privacy-preserving communication. An encounter occurs whenever two devices are within Bluetooth radio range of each other, and generates a unique encounter ID and associated shared key. EnCore detects nearby users and resources, bootstraps named communication abstractions called events for groups of proximal users, and enables communication and sharing among event participants, while relying on existing network, storage and online social network services. At the same time, EnCore puts users in control of their privacy and the confidentiality of the information they share. Using an Android implementation of EnCore and an app for event-based communication and sharing, we evaluate EnCore's utility using a live testbed deployment with 35 users.
Paarijaat Aditya, Viktor Erdélyi, Matthew Lentz, Elaine Shi, Bobby Bhattacharjee, Peter Druschel
MobiSys6
2014 SDDR: Light-Weight, Secure Mobile Encounters
Matthew Lentz, Viktor Erdélyi, Paarijaat Aditya, Elaine Shi, Peter Druschel, Bobby Bhattacharjee
USENIX Security Symposium5
2013 Peer-assisted content distribution in Akamai netsession
abstract
Content distribution systems have traditionally adopted one of two architectures: infrastructure-based content delivery networks (CDNs), in which clients download content from dedicated, centrally managed servers, and peer-to-peer CDNs, in which clients download content from each other. The advantages and disadvantages of each architecture have been studied in great detail. Recently, hybrid, or 'peer-assisted', CDNs have emerged, which combine elements from both architectures. The properties of such systems, however, are not as well understood.
Mingchen Zhao, Paarijaat Aditya, Ang Chen 0001, Yin Lin, Andreas Haeberlen, Peter Druschel, Bruce M. Maggs, Bill Wishon, Miroslav Ponec
Internet Measurement Conference6
2013 Towards efficient traffic-analysis resistant anonymity networks
abstract
Existing IP anonymity systems tend to sacrifice one of low latency, high bandwidth, or resistance to traffic-analysis. High-latency mix-nets like Mixminion batch messages to resist traffic-analysis at the expense of low latency. Onion routing schemes like Tor deliver low latency and high bandwidth, but are not designed to withstand traffic analysis. Designs based on DC-nets or broadcast channels resist traffic analysis and provide low latency, but are limited to low bandwidth communication.
Stevens Le Blond, David R. Choffnes, Wenxuan Zhou 0003, Peter Druschel, Hitesh Ballani, Paul Francis
SIGCOMM4
2012 Defending against large-scale crawls in online social networks
abstract
Thwarting large-scale crawls of user profiles in online social networks (OSNs) like Facebook and Renren is in the interest of both the users and the operators of these sites. OSN users wish to maintain control over their personal information, and OSN operators wish to protect their business assets and reputation. Existing rate-limiting techniques are ineffective against crawlers with many accounts, be they fake accounts (also known as Sybils) or compromised accounts of real users obtained on the black market.
Mainack Mondal, Bimal Viswanath, Allen Clement, Peter Druschel, Krishna P. Gummadi, Alan Mislove, Ansley Post
CoNEXT4
2012 Accountability and Trust in Cooperative Information Systems
abstract
Summary form only given. Cooperation and trust play an increasingly important role in today's information systems. For instance, peer-to-peer systems like BitTorrent, Sopcast and Skype are powered by resource contributions from participating users, federated systems like the Internet have to respect the interests, policies and laws of participating organizations and countries; in the Cloud, users entrust their data and computation to third-part infrastructure. In this talk, we consider accountability as a way to facilitate transparency and trust in cooperative systems. We look at practical techniques to account for the integrity of distributed, cooperative computations, and look at some of the difficulties and open problems in accountability.
Peter Druschel
ICDE1
2012 Reliable Client Accounting for P2P-Infrastructure Hybrids
Paarijaat Aditya, Mingchen Zhao, Yin Lin, Andreas Haeberlen, Peter Druschel, Bruce M. Maggs, Bill Wishon
NSDI5
2011 Limiting large-scale crawls of social networking sites
abstract
Online social networking sites (OSNs) like Facebook and Orkut contain personal data of millions of users. Many OSNs view this data as a valuable asset that is at the core of their business model. Both OSN users and OSNs have strong incentives to restrict large scale crawls of this data. OSN users want to protect their privacy and OSNs their business interest. Traditional defenses against crawlers involve rate- limiting browsing activity per user account. These defense schemes, however, are vulnerable to Sybil attacks, where a crawler creates a large number of fake user accounts. In this paper, we propose Genie, a system that can be deployed by OSN operators to defend against Sybil crawlers. Genie is based on a simple yet powerful insight: the social network itself can be leveraged to defend against Sybil crawlers. We first present Genie's design and then discuss how Genie can limit crawlers while allowing browsing of user profiles by normal users.
Mainack Mondal, Bimal Viswanath, Allen Clement, Peter Druschel, Krishna P. Gummadi, Alan Mislove, Ansley Post
SIGCOMM4
2011 Autonomous Storage Management for Personal Devices with PodBase
Ansley Post, Juan Navarro, Petr Kuznetsov, Peter Druschel
USENIX ATC4
2010 Accountable Virtual Machines
Andreas Haeberlen, Paarijaat Aditya, Rodrigo Rodrigues 0001, Peter Druschel
OSDI4
2010 You are who you know: inferring user profiles in online social networks
abstract
Online social networks are now a popular way for users to connect, express themselves, and share content. Users in today's online social networks often post a profile, consisting of attributes like geographic location, interests, and schools attended. Such profile information is used on the sites as a basis for grouping users, for sharing content, and for suggesting users who may benefit from interaction. However, in practice, not all users provide these attributes.
Alan Mislove, Bimal Viswanath, Krishna P. Gummadi, Peter Druschel
WSDM4
2010 Measurement-based analysis, modeling, and synthesis of the internet delay space
Bo Zhang 0073, T. S. Eugene Ng, Animesh Nandi, Rudolf H. Riedi, Peter Druschel
IEEE/ACM Trans. Netw.5
2009 CSAR: A Practical and Provable Technique to Make Randomized Systems Accountable
Michael Backes 0001, Peter Druschel, Andreas Haeberlen, Dominique Unruh
NDSS2
2009 NetReview: Detecting When Interdomain Routing Goes Wrong
Andreas Haeberlen, Ioannis C. Avramopoulos, Jennifer Rexford, Peter Druschel
NSDI4
2008 Ostra: Leveraging Trust to Thwart Unwanted Communication
Alan Mislove, Ansley Post, Peter Druschel, Krishna P. Gummadi
NSDI3
2008 BFT Protocols Under Fire
Atul Singh, Tathagata Das, Petros Maniatis, Peter Druschel, Timothy Roscoe
NSDI4
2008 Accountability for distributed systems
abstract
Social expectations play an important role in distributed systems that span multiple administrative domains. For instance, participants in peer-to-peer systems are expected to contribute resources for the common good; members of federated systems are expected to adhere to best practices and fulfil contractual obligations; and providers of hosting services are expected to respect the confidentiality and integrity of customers' data and computation. In society, *accountability* is widely used to incentivize and reward good performance, to expose failures and unwanted behavior, and to build trust among competing individuals and organizations. In this talk, I'll suggest that accountability is also a powerful tool in the design of distributed systems. Accountability allows good nodes to prove their past compliance and ensures that (intended or unintended) deviations by any node from the expected behavior are detectable. Accountability complements fault tolerance techniques and offers an alternative to these techniques in systems that provide best-effort service.
Peter Druschel
PODC1
2008 Safari: A self-organizing, hierarchical architecture for scalable ad hoc networking
Shu Du, Ahamed Khan, Santashil PalChaudhuri, Ansley Post, Amit Kumar Saha, Peter Druschel, David B. Johnson 0001, Rudolf H. Riedi
Ad Hoc Networks6
2007 Measurement and analysis of online social networks
abstract
Online social networking sites like Orkut, YouTube, and Flickr are among the most popular sites on the Internet. Users of these sites form a social network, which provides a powerful means of sharing, organizing, and finding content and contacts. The popularity of these sites provides an opportunity to study the characteristics of online social network graphs at large scale. Understanding these graphs is important, both to improve current systems and to design new applications of online social networks.
Alan Mislove, Massimiliano Marcon, Krishna P. Gummadi, Peter Druschel, Bobby Bhattacharjee
Internet Measurement Conference4
2007 SAAR: A Shared Control Plane for Overlay Multicast
Animesh Nandi, Aditya Ganjam, Peter Druschel, T. S. Eugene Ng, Ion Stoica, Hui Zhang 0001, Bobby Bhattacharjee
NSDI3
2007 PeerReview: practical accountability for distributed systems
abstract
We describe PeerReview, a system that provides accountability in distributed systems. PeerReview ensures that Byzantine faults whose effects are observed by a correct node are eventually detected and irrefutably linked to a faulty node. At the same time, PeerReview ensures that a correct node can always defend itself against false accusations. These guarantees are particularly important for systems that span multiple administrative domains, which may not trust each other.PeerReview works by maintaining a secure record of the messages sent and received by each node. The record isused to automatically detect when a node's behavior deviates from that of a given reference implementation, thus exposing faulty nodes. PeerReview is widely applicable: it only requires that a correct node's actions are deterministic, that nodes can sign messages, and that each node is periodically checked by a correct node. We demonstrate that PeerReview is practical by applying it to three different types of distributed systems: a network filesystem, a peer-to-peer system, and an overlay multicast system.
Andreas Haeberlen, Petr Kuznetsov, Peter Druschel
SOSP3
2006 Experiences in building and operating ePOST, a reliable peer-to-peer application
abstract
Peer-to-peer (p2p) technology can potentially be used to build highly reliable applications without a single point of failure. However, most of the existing applications, such as file sharing or web caching, have only moderate reliability demands. Without a challenging proving ground, it remains unclear whether the full potential of p2p systems can be realized.To provide such a proving ground, we have designed, deployed and operated a p2p-based email system. We chose email because users depend on it for their daily work and therefore place high demands on the availability and reliability of the service, as well as the durability, integrity, authenticity and privacy of their email. Our system, ePOST, has been actively used by a small group of participants for over two years.In this paper, we report the problems and pitfalls we encountered in this process. We were able to address some of them by applying known principles of system design, while others turned out to be novel and fundamental, requiring us to devise new solutions. Our findings can be used to guide the design of future reliable p2p systems and provide interesting new directions for future research.
Alan Mislove, Ansley Post, Andreas Haeberlen, Peter Druschel
EuroSys4
2006 Using queries for distributed monitoring and forensics
abstract
Distributed systems are hard to build, profile, debug, and test. Monitoring a distributed system - to detect and analyze bugs, test for regressions, identify fault-tolerance problems or security compromises - can be difficult and error-prone. In this paper we argue that declarative development of distributed systems is well suited to tackle these tasks. We present an application logging, monitoring, and debugging facility that we have built on top of the P2 system, comprising an introspection model, an execution tracing component, and a distributed query processor. We use this facility to demonstrate a range of on-line distributed diagnosis tools that range from simple, local state assertions to sophisticated global property detectors on consistent snapshots. These tools are small, simple, and can be deployed piecemeal on-line at any point during a system's life cycle. Our evaluation suggests that the overhead of our approach to improving and monitoring running distributed systems continuously is well in tune with its benefits.
Atul Singh, Petros Maniatis, Timothy Roscoe, Peter Druschel
EuroSys4
2006 Exploiting Social Networks for Internet Search
Alan Mislove, Krishna P. Gummadi, Peter Druschel
HotNets3
2006 Keynote The Renaissance of Decentralized Systems
abstract
Provides an abstract of the keynote presentation and a brief professional biography of the presenter. The complete presentation was not made available for publication as part of the conference proceedings.
Peter Druschel
HPDC1
2006 Measurement based analysis, modeling, and synthesis of the internet delay space
abstract
Understanding the characteristics of the Internet delay space (i.e., the all-pairs set of static round-trip propagation delays among edge networks in the Internet) is important for the design of global-scale distributed systems. For instance, algorithms used in overlay networks are often sensitive to violations of the triangle inequality and to the growth properties within the Internet delay space. Since designers of distributed systems often rely on simulation and emulation to study design alternatives, they need a realistic model of the Internet delay space.Our analysis shows that existing models do not adequately capture important properties of the Internet delay space. In this paper, we analyze measured delays among thousands of Internet edge networks and identify key properties that are important for distributed system design. Furthermore, we derive a simple model of the Internet delay space based on our analytical findings. This model preserves the relevant metrics far better than existing models, allows for a compact representation, and can be used to synthesize delay data for simulations and emulations at a scale where direct measurement and storage are impractical.
Bo Zhang 0073, T. S. Eugene Ng, Animesh Nandi, Rudolf H. Riedi, Peter Druschel
Internet Measurement Conference5
2006 Eclipse Attacks on Overlay Networks: Threats and Defenses
abstract
Abstract — Overlay networks are widely used to deploy functionality at edge nodes without changing network routers. Each node in an overlay network maintains connections with a number of peers, forming a graph upon which a distributed application or service is implemented. In an “Eclipse ” attack, a set of malicious, colluding overlay nodes arranges for a correct node to peer only with members of the coalition. If successful, the attacker can mediate most or all communication to and from the victim. Furthermore, by supplying biased neighbor information during normal overlay maintenance, a modest number of malicious nodes can eclipse a large number of correct victim nodes. This paper studies the impact of Eclipse attacks on structured overlays and shows the limitations of known defenses. We then present the design, implementation, and evaluation of a new defense, in which nodes anonymously audit each other’s connectivity. The key observation is that a node that mounts an Eclipse attack must have a higher than average node degree. We show that enforcing a node degree limit by auditing is an effective defense against Eclipse attacks. Furthermore, unlike most existing defenses, our defense leaves flexibility in the selection of neighboring nodes, thus permitting important overlay optimizations like proximity neighbor selection (PNS). I.
Atul Singh, Tsuen-Wan Ngan, Peter Druschel, Dan S. Wallach
INFOCOM3
2006 Performance analysis of TLS Web servers
abstract
TLS is the protocol of choice for securing today's e-commerce and online transactions but adding TLS to a Web server imposes a significant overhead relative to an insecure Web server on the same platform. We perform a comprehensive study of the performance costs of TLS. Our methodology is to profile TLS Web servers with trace-driven workloads, replace individual components inside TLS with no-ops, and measure the observed increase in server throughput. We estimate the relative costs of each TLS processing stage, identifying the areas for which future optimizations would be worthwhile. Our results show that while the RSA operations represent the largest performance cost in TLS Web servers, they do not solely account for TLS overhead. RSA accelerators are effective for e-commerce site workloads since they experience low TLS session reuse. Accelerators appear to be less effective for sites where all the requests are handled by a TLS server because they have a higher session reuse rate. In this case, investing in a faster CPU might provide a greater boost in performance. Our experiments show that having a second CPU is at least as useful as an RSA accelerator. Our results seem to suggest that, as CPUs become faster, the cryptographic costs of TLS will become dwarfed by the CPU costs of the nonsecurity aspects of a Web server. Optimizations aimed at general purpose Web servers should continue to be a focus of research and would benefit secure Web servers as well.
Cristian Coarfa, Peter Druschel, Dan S. Wallach
ACM Trans. Comput. Syst.2
2005 Falling Off the Cliff: When Systems Go Nonlinear
Yvonne Coady, Russ Cox, John DeTreville, Peter Druschel, Joseph L. Hellerstein, Andrew Hume, Kimberly Keeton, Christopher Small 0001, Lex Stein, Andy Warfield
HotOS4
2005 Scrivener: Providing Incentives in Cooperative Content Distribution Systems
Animesh Nandi, Tsuen-Wan Ngan, Atul Singh, Peter Druschel, Dan S. Wallach
Middleware4
2005 Glacier: Highly Durable, Decentralized Storage Despite Massive Correlated Failures
Andreas Haeberlen, Alan Mislove, Peter Druschel
NSDI3
2003 POST: A Secure, Resilient, Cooperative Messaging System
Alan Mislove, Ansley Post, Charles Reis, Paul Willmann, Peter Druschel, Dan S. Wallach, Xavier Bonnaire, Pierre Sens 0001, Jean-Michel Busca, Luciana Arantes
HotOS5
2003 SplitStream: high-bandwidth multicast in cooperative environments
abstract
In tree-based multicast systems, a relatively small number of interior nodes carry the load of forwarding multicast messages. This works well when the interior nodes are highly-available, dedicated infrastructure routers but it poses a problem for application-level multicast in peer-to-peer systems. SplitStream addresses this problem by striping the content across a forest of interior-node-disjoint multicast trees that distributes the forwarding load among all participating peers. For example, it is possible to construct efficient SplitStream forests in which each peer contributes only as much forwarding bandwidth as it receives. Furthermore, with appropriate content encodings, SplitStream is highly robust to failures because a node failure causes the loss of a single stripe on average. We present the design and implementation of SplitStream and show experimental results obtained on an Internet testbed and via large-scale network simulation. The results show that SplitStream distributes the forwarding load among all peers and can accommodate peers with different bandwidth capacities while imposing low overhead for forest construction and maintenance.
Miguel Castro 0001, Peter Druschel, Anne-Marie Kermarrec, Animesh Nandi, Antony I. T. Rowstron, Atul Singh
SOSP2
2002 Design and Scalability of NLS, a Scalable Naming and Location Service
abstract
This paper sketches the design of NLS, a scalable naming and location service, and presents an analysis and evaluation of its scalability. NLS resolves textual names to a nearby instance of a set of replicated objects associated with that name, and is designed to scale to the dimensions of a world-wide service. Applications include resolving Web URIs (uniform resource identifiers) to the nearest cached or replicated objects that provide the associated content. The key design goals of NLS are scalability, performance, availability and ease of administration. NLS is based on a dynamically configured, distributed search tree, with a fat-tree based topology at the global layer and spanning trees at the local layer. Analysis and preliminary empirical results obtained with a prototype implementation indicate that the system scales as expected.
Y. Charlie Hu, Daniel Rodney, Peter Druschel
INFOCOM3
2002 Performance Analysis of TLS Web Servers
Cristian Coarfa, Peter Druschel, Dan S. Wallach
NDSS2
2002 Secure Routing for Structured Peer-to-Peer Overlay Networks
Miguel Castro 0001, Peter Druschel, Ayalvadi J. Ganesh, Antony I. T. Rowstron, Dan S. Wallach
OSDI2
2002 Practical, Transparent Operating System Support for Superpages
Juan Navarro, Sitaram Iyer, Peter Druschel, Alan L. Cox
OSDI3
2002 Squirrel: a decentralized peer-to-peer web cache
abstract
This paper presents a decentralized, peer-to-peer web cache called Squirrel. The key idea is to enable web browsers on desktop machines to share their local caches, to form an efficient and scalable web cache, without the need for dedicated hardware and the associated administrative cost. We propose and evaluate decentralized web caching algorithms for Squirrel, and discover that it exhibits performance comparable to a centralized web cache in terms of hit ratio, bandwidth usage and latency. It also achieves the benefits of decentralization, such as being scalable, self-organizing and resilient to node failures, while imposing low overhead on the participating nodes.
Sitaram Iyer, Antony I. T. Rowstron, Peter Druschel
PODC3
2002 Scribe: a large-scale and decentralized application-level multicast infrastructure
abstract
This paper presents Scribe, a scalable application-level multicast infrastructure. Scribe supports large numbers of groups, with a potentially large number of members per group. Scribe is built on top of Pastry, a generic peer-to-peer object location and routing substrate overlayed on the Internet, and leverages Pastry's reliability, self-organization, and locality properties. Pastry is used to create and manage groups and to build efficient multicast trees for the dissemination of messages to each group. Scribe provides best-effort reliability guarantees, and we outline how an application can extend Scribe to provide stronger reliability. Simulation results, based on a realistic network topology model, show that Scribe scales across a wide range of groups and group sizes. Also, it balances the load on the nodes while achieving acceptable delay and link stress when compared with Internet protocol multicast.
Miguel Castro 0001, Peter Druschel, Anne-Marie Kermarrec, Antony I. T. Rowstron
IEEE J. Sel. Areas Commun.2
2001 Topic 09: Distributed Systems and Algorithms
Bertil Folliot, Giovanni Chiola, Peter Druschel, Anne-Marie Kermarrec
Euro-Par3
2001 PAST: A large-scale, persistent peer-to-peer storage utility
abstract
This paper sketches the design of PAST, a large-scale, Internet-based, global storage utility that provides scalability, high availability, persistence and security. PAST is a peer-to-peer Internet application and is entirely self-organizing. PAST nodes serve as access points for clients, participate in the routing of client requests, and contribute storage to the system. Nodes are not trusted, they may join the system at any time and may silently leave the system without warning. Yet, the system is able to provide strong assurances, efficient storage access, load balancing and scalability. Among the most interesting aspects of PAST's design are (1) the Pastry location and routing scheme, which reliably and efficiently routes client requests among the PAST nodes, has good network locality properties and automatically resolves node failures and node additions; (2) the use of randomization to ensure diversity in the set of nodes that store a file's replicas and to provide load balancing; and (3) the optional use of smartcards, which are held by each PAST user and issued by a third party called a broker The smartcards support a quota system that balances supply and demand of storage in the system.
Peter Druschel, Antony I. T. Rowstron
HotOS1
2001 Pastry: Scalable, Decentralized Object Location, and Routing for Large-Scale Peer-to-Peer Systems
Antony I. T. Rowstron, Peter Druschel
Middleware2
2001 The IceCube approach to the reconciliation of divergent replicas
abstract
We describe a novel approach to log-based reconciliation called IceCube. It is general and is parameterised by application and object semantics. IceCube considers more flexible orderings and is designed to ease the burden of reconciliation on the application programmers. IceCube captures the static and dynamic reconciliation constraints between all pairs of actions, proposes schedules that satisfy the static constraints, and validates them against the dynamic constraints.
Anne-Marie Kermarrec, Antony I. T. Rowstron, Marc Shapiro 0001, Peter Druschel
PODC4
2001 Anticipatory scheduling: A disk scheduling framework to overcome deceptive idleness in synchronous I/O
abstract
Disk schedulers in current operating systems are generally work-conserving, i.e., they schedule a request as soon as the previous request has finished. Such schedulers often require multiple outstanding requests from each process to meet system-level goals of performance and quality of service. Unfortunately, many common applications issue disk read requests in a synchronous manner, interspersing successive requests with short periods of computation. The scheduler chooses the next request too early; this induces deceptive idleness, a condition where the scheduler incorrectly assumes that the last request issuing process has no further requests, and becomes forced to switch to a request from another process.We propose the anticipatory disk scheduling framework to solve this problem in a simple, general and transparent way, based on the non-work-conserving scheduling discipline. Our FreeBSD implementation is observed to yield large benefits on a range of microbenchmarks and real workloads. The Apache webserver delivers between 29% and 71% more throughput on a disk-intensive workload. The Andrew filesystem benchmark runs faster by 8%, due to a speedup of 54% in its read-intensive phase. Variants of the TPC-B database benchmark exhibit improvements between 2% and 60%. Proportional-share schedulers are seen to achieve their contracts accurately and efficiently.
Sitaram Iyer, Peter Druschel
SOSP2
2001 Storage Management and Caching in PAST, A Large-scale, Persistent Peer-to-peer Storage Utility
abstract
This paper presents and evaluates the storage management and caching in PAST, a large-scale peer-to-peer persistent storage utility. PAST is based on a self-organizing, Internet-based overlay network of storage nodes that cooperatively route file queries, store multiple replicas of files, and cache additional copies of popular files.In the PAST system, storage nodes and files are each assigned uniformly distributed identifiers, and replicas of a file are stored at nodes whose identifier matches most closely the file's identifier. This statistical assignment of files to storage nodes approximately balances the number of files stored on each node. However, non-uniform storage node capacities and file sizes require more explicit storage load balancing to permit graceful behavior under high global storage utilization; likewise, non-uniform popularity of files requires caching to minimize fetch distance and to balance the query load.We present and evaluate PAST, with an emphasis on its storage management and caching system. Extensive trace-driven experiments show that the system minimizes fetch distance, that it balances the query load for popular files, and that it displays graceful degradation of performance as the global storage utilization increases beyond 95%.
Antony I. T. Rowstron, Peter Druschel
SOSP2
2000 Cluster reserves: a mechanism for resource management in cluster-based network servers
abstract
In network (e.g., Web) servers, it is often desirable to isolate the performance of different classes of requests from each other. That is, one seeks to achieve that a certain minimal proportion of server resources are available for a class of requests, independent of the load imposed by other requests. Recent work demonstrates how to achieve this performance isolation in servers consisting of a single, centralized node; however, achieving performance isolation in a distributed, cluster based server remains a problem.
Mohit Aron, Peter Druschel, Willy Zwaenepoel
SIGMETRICS2
2000 Scalable Content-aware Request Distribution in Cluster-based Network Servers
Mohit Aron, Darren Sanders, Peter Druschel, Willy Zwaenepoel
USENIX ATC, General Track3
2000 Soft timers: efficient microsecond software timer support for network processing
abstract
This paper proposes and evaluates soft timers, a new operating system facility that allows the efficient scheduling of software events at agranularity down to tens of microseconds. Soft timers can be used to avoid interrupts and reduce context switches associated with network processing, without sacrificing low communication delays. More specifically, soft timers enable transport protocols like TCP to efficiently perform rate-based clocking of packet transmissions. Experiments indicate that soft timers allow a server to employ rate-based clocking with little CPU overhead (2-6%) at high aggregate bandwidths. Soft timers can also be used to perform network polling, which eliminates network interrupts and increases the memory access locality of the network subsystem without sacrificing delay. Experiments show that this technique can improve the throughput of a Web server by up to 25%.
Mohit Aron, Peter Druschel
ACM Trans. Comput. Syst.2
2000 IO-Lite: a unified I/O buffering and caching system
abstract
This article presents the design, implementation, and evaluation of IO -Lite, a unified I/O buffering and caching system for general-purpose operating systems. IO-Lite unifiesallbuffering and caching in the system, to the extent permitted by the hardware. In particular, it allows applications, the interprocess communication system, the file system, the file cache, and the network subsystem to safely and concurrently share a single physical copy of the data. Protection and security are maintained through a combination of access control and read-only sharing. IO-Lite eliminates all copying and multiple buffering of I/O data, and enables various cross-subsystem optimizations. Experiments with a Web server show performance improvements between 40 and 80% on real workloads as a result of IO-Lite.
Vivek S. Pai, Peter Druschel, Willy Zwaenepoel
ACM Trans. Comput. Syst.2
1999 A New Approach to Routing with Dynamic Metrics
abstract
We present a new routing algorithm to compute paths within a network using dynamic link metrics. Dynamic link metrics are cost metrics that depend on a link's dynamic state, e.g., the congestion on the link. Our algorithm is destination-initiated: a destination initiates a global path computation to itself using dynamic link metrics. All other destinations that do not initiate this dynamic metric computation use paths that are calculated and maintained by a traditional routing algorithm using static link metrics. Analysis of Internet packet traces show that a high percentage of network traffic is destined for a small number of networks. Because our algorithm is destination-initiated, it achieves maximum performance at minimum cost when it only computes dynamic metric paths to these selected "hot" destination networks. This selective approach to route recomputation reduces many of the problems (principally route oscillations) associated with calculating all routes simultaneously. We compare the routing efficiency and end to-end performance of our algorithm against those of traditional algorithms using dynamic link metrics. The results of our experiments show that our algorithm can provide higher network performance at a significantly lower routing cost under conditions that arise in real networks. The effectiveness of the algorithm stems from the independent, time-staggered recomputation of important paths using dynamic metrics, allowing for splits in congested traffic that cannot be made by traditional routing algorithms.
Johnny Chen, Peter Druschel, Devika Subramanian
INFOCOM2
1999 Resource Containers: A New Facility for Resource Management in Server Systems
Gaurav Banga, Peter Druschel, Jeffrey C. Mogul
OSDI2
1999 IO-Lite: A Unified I/O Buffering and Caching System
Vivek S. Pai, Peter Druschel, Willy Zwaenepoel
OSDI2
1999 Soft timers: efficient microsecond software timer support for network processing
abstract
This paper proposes and evaluates soft timers, a new operating system facility that allows the efficient scheduling of software events at a granularity down to tens of microseconds. Soft timers can be used to avoid interrupts and reduce context switches associated with network processing without sacrificing low communication delays.More specifically, soft timers enable transport protocols like TCP to efficiently perform rate-based clocking of packet transmissions. Experiments show that rate-based clocking can improve HTTP response time over connections with high bandwidth-delay products by up to 89% and that soft timers allow a server to employ rate-based clocking with little CPU overhead (2-6%) at high aggregate bandwidths.Soft timers can also be used to perform network polling, which eliminates network interrupts and increases the memory access locality of the network subsystem without sacrificing delay. Experiments show that this technique can improve the throughput of a Web server by up to 25%.
Mohit Aron, Peter Druschel
SOSP2
1999 Efficient Support for P-HTTP in Cluster-Based Web Servers
Mohit Aron, Peter Druschel, Willy Zwaenepoel
USENIX ATC, General Track2
1999 A Scalable and Explicit Event Delivery Mechanism for UNIX
Gaurav Banga, Jeffrey C. Mogul, Peter Druschel
USENIX ATC, General Track3
1999 Flash: An efficient and portable Web server
Vivek S. Pai, Peter Druschel, Willy Zwaenepoel
USENIX ATC, General Track2
1999 Measuring the Capacity of a Web Server Under Realistic Loads
Gaurav Banga, Peter Druschel
World Wide Web2
1998 Locality-Aware Request Distribution in Cluster-based Network Servers
abstract
We consider cluster-based network servers in which a front-end directs incoming requests to one of a number of back-ends. Specifically, we consider content-based request distribution: the front-end uses the content requested, in addition to information about the load on the back-end nodes, to choose which back-end will handle this request. Content-based request distribution can improve locality in the back-ends' main memory caches, increase secondary storage scalability by partitioning the server's database, and provide the ability to employ back-end nodes that are specialized for certain types of requests.As a specific policy for content-based request distribution, we introduce a simple, practical strategy for locality-aware request distribution (LARD). With LARD, the front-end distributes incoming requests in a manner that achieves high locality in the back-ends' main memory caches as well as load balancing. Locality is increased by dynamically subdividing the server's working set over the back-ends. Trace-based simulation results and measurements on a prototype implementation demonstrate substantial performance improvements over state-of-the-art approaches that use only load information to distribute requests. On workloads with working sets that do not fit in a single server node's main memory cache, the achieved throughput exceeds that of the state-of-the-art approach by a factor of two to four.With content-based distribution, incoming requests must be handed off to a back-end in a manner transparent to the client, after the front-end has inspected the content of the request. To this end, we introduce an efficient TCP handoflprotocol that can hand off an established TCP connection in a client-transparent manner.
Vivek S. Pai, Mohit Aron, Gaurav Banga, Michael Svendsen, Peter Druschel, Willy Zwaenepoel, Erich M. Nahum
ASPLOS5
1998 An Efficient Multipath Forwarding Method
abstract
We motivate and formally define dynamic multipath routing and present the problem of packet forwarding in the multipath routing context. We demonstrate that for multipath sets that are suffix matched, forwarding can be efficiently implemented with (1) a per packet overhead of a small, fixed-length path identifier, and (2) router space overhead linear in K, the number of alternate paths between a source and a destination. We derive multipath forwarding schemes for suffix matched path sets computed by both de-centralized (link-state) and distributed (distance-vector) routing algorithms. We also prove that (1) distributed multipath routing algorithms compute suffix matched multipath sets, and (2) for the criterion of ranked k-shortest paths, decentralized routing algorithms also yield suffix matched multipath sets.
Johnny Chen, Peter Druschel, Devika Subramanian
INFOCOM2
1997 Ants and Reinforcement Learning: A Case Study in Routing in Dynamic Networks
Devika Subramanian, Peter Druschel, Johnny Chen
IJCAI (2)2
1996 Lazy Receiver Processing (LRP): A Network Subsystem Architecture for Server Systems
abstract
No abstract available.
Peter Druschel, Gaurav Banga
OSDI1
1996 Implementing Atomic Sequences on Uniprocessors Using Rollforward
abstract
This article presents a software-only solution to the synchronization problem for uniprocessors. The idea is to execute atomic sequences without any hardware protection, and in the rare case of pre-emption, to roll the sequence forward to the end, thereby preserving atomicity. One of the proposed implementations protects atomic sequences without any memory-accesses. This is significant as it enables execution at CPU-speeds, rather than memory-speeds. The benefit of this method increases with the frequency at which atomic sequences are executed. It therefore encourages the building of systems with fine-grained synchronization. This has the additional advantage of reducing average latency. Experiments demonstrate that this technique has the potential to outperform even the best hardware mechanisms. The main contribution of this article is to discuss operating-system related issues of rollforward and to demonstrate its practicality, both in terms of flexibility and performance.
David Mosberger, Peter Druschel, Larry L. Peterson
Softw. Pract. Exp.2
1994 Experiences with a High-Speed Network Adaptor: A Software Perspective
abstract
This paper describes our experiences, from a software perspective, with the OSIRIS network adaptor. It first identifies the problems we encountered while programming OSIRIS and optimizing network performance, and outlines how we either addressed them in the software, or had to modify the hardware. It then describes the opportunities provided by OSIRIS that we were able to exploit in the host operating system (OS); opportunities that suggested techniques for making the OS more effective in delivering network data to application programs. The most novel of these techniques, called application device channels, gives application programs running in user space direct access to the adaptor. The paper concludes with the lessons drawn from this work, which we believe will benefit the designers of future network adaptors.
Peter Druschel, Larry L. Peterson, Bruce S. Davie
SIGCOMM1
1993 Fbufs: A High-Bandwidth Cross-Domain Transfer Facility
abstract
We have designed and implemented a new operating system facility for I/O buffer management and data transferacross protection domain boundaries on shared memory machines. This facility, called fast buffers (fbufs), combines virtual page remapping with shared virtual memory, and exploits locality in I/O traffic to achieve high throughput without compromising protection, security, or modularity. goal is to help deliver the high bandwidth afforded by emerging high-speed networks to user-level processes, both in monolithic and microkernel-based operating systems.This paper outlines the requirements for a cross-domain transfer facility, describes the design of the fbuf mechanism that meets these requirements, and experimentally quantifies the impact of fbufs on network performance.
Peter Druschel, Larry L. Peterson
SOSP1
1992 Beyond Micro-Kernel Design: Decoupling Modularlty and Protection in Lipto
abstract
It is argued that a modular operating system architecture should provide support for modularity independent of protection domains. Given such support, modules and interfaces can be designed according to sound software engineering principles, without concern for cross-domain invocation costs. The partitioning of modules into domains and across machines becomes a matter of configuration, rather than design. Current micro-kernel-based architectures do not sufficiently address this issue since their communication mechanisms are designed for the nonlocal, i.e., cross-domain, case. An architecture that provides location-transparent binding and access of modules optimized for the local case, thereby decoupling the orthogonal concepts of modularity and protection, is proposed.>
Peter Druschel, Larry L. Peterson, Norman C. Hutchinson
ICDCS1
1992 Analysis of I/O Subsystem Design for Multimedia Workstations
Peter Druschel, Mark B. Abbott, Michael A. Pagels, Larry L. Peterson
NOSSDAV1