Jonathan M. Smith

dblp:s/JonathanMSmith · DBLP profile ↗
← Back
63ranked-venue papers
7as first author
3since 2021 · last 2026
0000-0003-3309-6603ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 26 · 1 first-author · 1 since 2021Security and privacy · 18 · 1 first-author · 1 since 2021Systems, architecture and hardware · 9 · 2 first-author · 1 since 2021Software engineering, systems software and programming languages · 9 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer networks
19 papers
Software-defined and programmable networks · 37% Network measurement and analytics · 32% Routing and switching · 15%
Network and information security
15 papers
Systems and software security · 74% Network security · 14% Hardware security and side channels · 8%
Computer architecture, parallel and distributed computing, and storage systems
14 papers
Distributed systems · 28% Cloud and datacenter computing · 25% Embedded and real-time systems · 17%
Software engineering, system software, and programming languages
4 papers
Operating systems · 56% Software maintenance and evolution · 28% Empirical software engineering · 17%

Topics — the 30 heaviest of 84, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Software-defined and programmable networks
programmable data plane
0.822020
DeepMatch: practical deep packet inspection in the data plane using network processors · CoNEXT 2020
Turboflow: information rich flow record generation on commodity switches · EuroSys 2018
Network measurement and analytics › network tomography
topology inference
0.732018
Pushing the Boundaries with bdrmapIT: Mapping Router Ownership at Internet Scale · Internet Measurement Conference 2018
MAP-IT: Multipass Accurate Passive Inferences from Traceroute · Internet Measurement Conference 2016
Networkmd: topology inference and failure diagnosis in the last mile · Internet Measurement Conference 2007
Routing and switching
inter-domain routing
0.622018
Pushing the Boundaries with bdrmapIT: Mapping Router Ownership at Internet Scale · Internet Measurement Conference 2018
MAP-IT: Multipass Accurate Passive Inferences from Traceroute · Internet Measurement Conference 2016
Software-defined and programmable networks › programmable data plane
deep packet inspection
0.412020
DeepMatch: practical deep packet inspection in the data plane using network processors · CoNEXT 2020
Software-defined and programmable networks › programmable data plane › deep packet inspection
regular expression matching
0.412020
DeepMatch: practical deep packet inspection in the data plane using network processors · CoNEXT 2020
Systems and software security
memory safety
0.422015
Architectural Support for Software-Defined Metadata Processing · ASPLOS 2015
Low-fat pointers: compact encoding and efficient gate-level implementation of fat pointers for spatial safety and capability-based security · CCS 2013
Cloud and datacenter computing
scale-out
0.412019
Ignis: scaling distribution-oblivious systems with light-touch distribution · PLDI 2019
Internet architecture and protocols › network topology
autonomous system topology
0.312018
Pushing the Boundaries with bdrmapIT: Mapping Router Ownership at Internet Scale · Internet Measurement Conference 2018
Network measurement and analytics
network telemetry
0.312018
Turboflow: information rich flow record generation on commodity switches · EuroSys 2018
Operating systems › system security › operating system security › protection mechanism › isolation
process isolation
0.312018
BreakApp: Automated, Flexible Application Compartmentalization · NDSS 2018
Network measurement and analytics › topology measurement
router-level topology
0.212016
MAP-IT: Multipass Accurate Passive Inferences from Traceroute · Internet Measurement Conference 2016
Software-defined and programmable networks › openflow
openflow extension
0.212015
POSTER: OFX: Enabling OpenFlow Extensions for Switch-Level Security Applications · CCS 2015
Systems and software security › memory safety
control-flow integrity
0.212015
Architectural Support for Software-Defined Metadata Processing · ASPLOS 2015
Systems and software security › memory safety
spatial and temporal memory safety
0.212015
Architectural Support for Software-Defined Metadata Processing · ASPLOS 2015
Embedded and real-time systems › runtime monitoring
runtime verification
0.212015
SPECS: A Lightweight Runtime Mechanism for Protecting Software from Security-Critical Processor Bugs · ASPLOS 2015
Systems and software security
vulnerability analysis
0.212014
Moving Targets: Security and Rapid-Release in Firefox · CCS 2014
Routing and switching › inter-domain routing
BGP
0.222018
Pushing the Boundaries with bdrmapIT: Mapping Router Ownership at Internet Scale · Internet Measurement Conference 2018
MAP-IT: Multipass Accurate Passive Inferences from Traceroute · Internet Measurement Conference 2016
Systems and software security › memory safety
spatial memory safety
0.212013
Low-fat pointers: compact encoding and efficient gate-level implementation of fat pointers for spatial safety and capability-based security · CCS 2013
Network security › intrusion detection and prevention
intrusion detection
0.112020
DeepMatch: practical deep packet inspection in the data plane using network processors · CoNEXT 2020
Internet architecture and protocols
overlay networks
0.112008
MOSAIC: unified declarative platform for dynamic overlay composition · CoNEXT 2008
Network management and operations › fault management
failure localization
0.112007
Networkmd: topology inference and failure diagnosis in the last mile · Internet Measurement Conference 2007
Network management and operations › fault management
fault diagnosis
0.112007
Networkmd: topology inference and failure diagnosis in the last mile · Internet Measurement Conference 2007
Routing and switching
geographic routing
0.112007
S4: Small State and Small Stretch Routing Protocol for Large Wireless Sensor Networks · NSDI 2007
Routing and switching
routing protocol
0.112007
S4: Small State and Small Stretch Routing Protocol for Large Wireless Sensor Networks · NSDI 2007
Internet of things and sensor networks
wireless sensor network
0.112007
S4: Small State and Small Stretch Routing Protocol for Large Wireless Sensor Networks · NSDI 2007
Systems and software security › trusted computing
trusted execution
0.112015
Architectural Support for Software-Defined Metadata Processing · ASPLOS 2015
Network measurement and analytics
distance estimation
0.112006
IDES: An Internet Distance Estimation Service for Large Networks · IEEE J. Sel. Areas Commun. 2006
Network performance modeling › performance prediction
latency prediction
0.112006
IDES: An Internet Distance Estimation Service for Large Networks · IEEE J. Sel. Areas Commun. 2006
Empirical software engineering
mining software repositories
0.112014
Moving Targets: Security and Rapid-Release in Firefox · CCS 2014
Empirical software engineering › mining software repositories › vulnerability analysis
vulnerability data analysis
0.112014
Moving Targets: Security and Rapid-Release in Firefox · CCS 2014

Methods — techniques the papers use, named apart from their topics

network processor · 0.9SmartNIC · 0.9automated program partitioning · 0.7taint tracking · 0.4software module offloading · 0.4microarchitectural optimization · 0.4dynamic verification · 0.4ISA-level state verification · 0.4light distribution recipes · 0.4automated transformation · 0.4quantitative correlation analysis · 0.4traceroute analysis · 0.3programmable switch pipeline decomposition · 0.3heterogeneous processor optimization · 0.3gate-level implementation · 0.3alias resolution · 0.3traceroute · 0.2passive inference · 0.2
YearPublicationVenuePosition
2026 R2d2: Robotized Reconfigurable Network for Disaggregated Datacenters
Linus Y. Wong, Justin R. Yu, Zhilei Zheng, Jonathan M. Smith, André DeHon
ISCA5
2021 μSCOPE: A Methodology for Analyzing Least-Privilege Compartmentalization in Large Software Artifacts
abstract
By prioritizing simplicity and portability, least-privilege engineering has been an afterthought in OS design, resulting in monolithic kernels where any exploit leads to total compromise. μSCOPE (“microscope”) addresses this problem by automatically identifying opportunities for least-privilege separation. μSCOPE replaces expert-driven, semi-automated analysis with a general methodology for exploring a continuum of security vs. performance design points by adopting a quantitative and systematic approach to privilege analysis. We apply the μSCOPE methodology to the Linux kernel by (1) instrumenting the entire kernel to gain comprehensive, fine-grained memory access and call activity; (2) mapping these accesses to semantic information; and (3) conducting separability analysis on the kernel using both quantitative privilege and overhead metrics. We discover opportunities for orders of magnitude privilege reduction while predicting relatively low overheads—at 15% mediation overhead, overprivilege in Linux can be reduced up to 99.8%—suggesting fine-grained privilege separation is feasible and laying the groundwork for accelerating real privilege separation.
Nick Roessler, Lucas Atayde, Imani Palmer, Derrick Paul McKee, Jai Pandey, Vasileios P. Kemerlis, Mathias Payer, Adam Bates 0001, Jonathan M. Smith, André DeHon, Nathan Dautenhahn
RAID9
2021 Software Packet-Level Network Analytics at Cloud Scale
abstract
As networks grow in speed, scale, and complexity, operating them reliably requires continuous monitoring and increasingly sophisticated analytics. Because of these requirements, the platforms that support analytics in cloud-scale networks face demands for both higher throughput (to keep up with high packet rates) and increased generality and programmability (to cover a wider range of applications). Recent proposals have worked toward these goals by offloading analytics application logic to line-rate programmable data plane hardware, as scaling existing software analytics platforms is prohibitively expensive. The rigid design and constrained resources of data plane devices, however, fundamentally limit the types of analysis and the number of tasks that can run concurrently. In this article, we demonstrate that generality need not be sacrificed for high performance. Rather than offloading entire analytics applications to hardware, the core idea of our work is to offload only critical preprocessing tasks that are shared among applications (e.g., load balancing) to a line-rate hardware frontend while optimizing the core analytics software to exploit properties of network analytics workloads. Based on this design, we present Jetstream, a hybrid platform for network analytics that can run custom software-based analytics pipelines at throughputs of up to 250 million packets per second on a 16-core commodity server. Jetstream makes sophisticated, network-wide packet analytics feasible without compromising on generality or performance.
Oliver Michel, John Sonchack, Greg Cusack, Maziyar Nazari, Eric Keller, Jonathan M. Smith
IEEE Trans. Netw. Serv. Manag.6
2020 DeepMatch: practical deep packet inspection in the data plane using network processors
abstract
Restricting data plane processing to packet headers precludes analysis of payloads to improve routing and security decisions. DeepMatch delivers line-rate regular expression matching on payloads using Network Processors (NPs). It further supports packet reordering to match patterns in flows that cross packet boundaries. Our evaluation shows that an implementation of DeepMatch, on a 40 Gbps Netronome NFP-6000 SmartNIC, achieves up to line rate for streams of unrelated packets and up to 20 Gbps when searches span multiple packets within a flow. In contrast with prior work, this throughput is data-independent and adds no burstiness. DeepMatch opens new opportunities for programmable data planes.
Joel Hypolite, John Sonchack, Shlomo Hershkop, Nathan Dautenhahn, André DeHon, Jonathan M. Smith
CoNEXT6
2019 TMC: Pay-as-you-Go Distributed Communication
abstract
We revisit the gap between what distributed systems need from the transport layer and what protocols in wide deployment provide. Such a gap complicates the implementation of distributed systems and impacts their performance. We introduce Tunable Multicast Communication (TMC), an abstraction that allows developers to easily specialize communication channels in distributed systems. TMC is presented as a deployable and extensible user-space library that exposes high-level tunable guarantees. TMC has the potential of improving the performance of distributed applications with minimal-to-zero development and deployment effort.
Henri Maxime Demoulin, Nikos Vasilakis, John Sonchack, Isaac Pedisich, Vincent Liu 0001, Boon Thau Loo, Linh T. X. Phan, Jonathan M. Smith, Irene Zhang
APNet8
2019 Ignis: scaling distribution-oblivious systems with light-touch distribution
abstract
Distributed systems offer notable benefits over their centralized counterparts. Reaping these benefits, however, requires burdensome developer effort to identify and rewrite bottlenecked components. Light-touch distribution is a new approach that converts a legacy system into a distributed one using automated transformations. Transformations operate at the boundaries of bottlenecked modules and are parametrizable by light distribution recipes that guide the intended semantics of the resulting distribution. Transformations and recipes operate at runtime, adapting to load by scaling out only saturated components. Our Ignis prototype shows substantial speedups, attractive elasticity characteristics, and memory gains over full replication, achieved by small and backward-compatible code changes.
Nikos Vasilakis, Ben Karel, Yash Palkhiwala, John Sonchack, André DeHon, Jonathan M. Smith
PLDI6
2018 Turboflow: information rich flow record generation on commodity switches
abstract
Fine-grained traffic flow records enable many powerful applications, especially in combination with telemetry systems that supports high coverage, i.e., of every link and at all times. Current solutions, however, make undesirable trade-offs between infrastructure cost and information richness. Switches that generate flow records, e.g., NetFlow switches, are a low cost solution but current designs sacrifice information richness, e.g., by sampling. Information rich alternatives rely heavily on servers, which increases cost to the point that they are impractical for high coverage. In this paper, we present the design, implementation, and evaluation of TurboFlow, a flow record generator for programmable switches that does not compromise on either cost or information richness. TurboFlow produces fine- grained and unsampled flow records with custom features entirely at the switch without relying on any support from external servers. This is a challenge given high traffic rates and the limitations of switch hardware. To overcome, we decompose the flow record generation algorithm and optimize it for the heterogeneous processors in programmable switches. We show that with this design, TurboFlow can support multi-terabit workloads on readily available commodity switches to enable information rich monitoring with high coverage.
John Sonchack, Adam J. Aviv, Eric Keller, Jonathan M. Smith
EuroSys4
2018 Pushing the Boundaries with bdrmapIT: Mapping Router Ownership at Internet Scale
Alexander Marder, Matthew J. Luckie, Amogh Dhamdhere, Bradley Huffaker, K. C. Claffy, Jonathan M. Smith
Internet Measurement Conference6
2018 BreakApp: Automated, Flexible Application Compartmentalization
Nikos Vasilakis, Ben Karel, Nick Roessler, Nathan Dautenhahn, André DeHon, Jonathan M. Smith
NDSS6
2018 Scaling Hardware Accelerated Network Monitoring to Concurrent and Dynamic Queries With *Flow
John Sonchack, Oliver Michel, Adam J. Aviv, Eric Keller, Jonathan M. Smith
USENIX ATC5
2017 Towards Fine-grained, Automated Application Compartmentalization
abstract
The rise of language-specific, third-party packages simplifies application development. However, relying on untrusted code poses a threat to security and reliability.
Nikos Vasilakis, Ben Karel, Nick Roessler, Nathan Dautenhahn, André DeHon, Jonathan M. Smith
PLOS@SOSP6
2016 Timing-based reconnaissance and defense in software-defined networks
John Sonchack, Anurag Dubey, Adam J. Aviv, Jonathan M. Smith, Eric Keller
ACSAC4
2016 MAP-IT: Multipass Accurate Passive Inferences from Traceroute
Alexander Marder, Jonathan M. Smith
Internet Measurement Conference2
2016 Enabling Practical Software-defined Networking Security Applications with OFX
John Sonchack, Jonathan M. Smith, Adam J. Aviv, Eric Keller
NDSS2
2015 Architectural Support for Software-Defined Metadata Processing
abstract
Optimized hardware for propagating and checking software-programmable metadata tags can achieve low runtime overhead. We generalize prior work on hardware tagging by considering a generic architecture that supports software-defined policies over metadata of arbitrary size and complexity; we introduce several novel microarchitectural optimizations that keep the overhead of this rich processing low. Our model thus achieves the efficiency of previous hardware-based approaches with the flexibility of the software-based ones. We demonstrate this by using it to enforce four diverse safety and security policies---spatial and temporal memory safety, taint tracking, control-flow integrity, and code and data separation---plus a composite policy that enforces all of them simultaneously. Experiments on SPEC CPU2006 benchmarks with a PUMP-enhanced RISC processor show modest impact on runtime (typically under 10%) and power ceiling (less than 10%), in return for some increase in energy usage (typically under 60%) and area for on-chip memory structures (110%).
Udit Dhawan, Catalin Hritcu, Raphael Rubin, Nikos Vasilakis, Silviu Chiricescu, Jonathan M. Smith, Thomas F. Knight Jr., Benjamin C. Pierce, André DeHon
ASPLOS6
2015 SPECS: A Lightweight Runtime Mechanism for Protecting Software from Security-Critical Processor Bugs
abstract
Processor implementation errata remain a problem, and worse, a subset of these bugs are security-critical. We classified 7 years of errata from recent commercial processors to understand the magnitude and severity of this problem, and found that of 301 errata analyzed, 28 are security-critical. We propose the SECURITY-CRITICAL PROCESSOR ER- RATA CATCHING SYSTEM (SPECS) as a low-overhead solution to this problem. SPECS employs a dynamic verification strategy that is made lightweight by limiting protection to only security-critical processor state. As a proof-of- concept, we implement a hardware prototype of SPECS in an open source processor. Using this prototype, we evaluate SPECS against a set of 14 bugs inspired by the types of security-critical errata we discovered in the classification phase. The evaluation shows that SPECS is 86% effective as a defense when deployed using only ISA-level state; incurs less than 5% area and power overhead; and has no software run-time overhead.
Matthew Hicks, Cynthia Sturton, Samuel T. King, Jonathan M. Smith
ASPLOS4
2015 POSTER: OFX: Enabling OpenFlow Extensions for Switch-Level Security Applications
abstract
Network Security applications that run on Software Defined Networks (SDNs) often need to analyze and process traffic in advanced ways. Existing approaches to adding such functionality to SDNs suffer from either poor performance, or poor deployability. In this paper, we propose and benchmark OFX: an OpenFlow extension framework that provides a better tradeoff between performance and deployability for SDN security applications by allowing them to dynamically install software modules onto network switches.
John Sonchack, Adam J. Aviv, Eric Keller, Jonathan M. Smith
CCS4
2015 From Lone Dwarfs to Giant Superclusters: Rethinking Operating System Abstractions for the Cloud
Nikos Vasilakis, Ben Karel, Jonathan M. Smith
HotOS3
2015 Cross-domain collaboration for improved IDS rule set selection
John Sonchack, Adam J. Aviv, Jonathan M. Smith
J. Inf. Secur. Appl.3
2014 Moving Targets: Security and Rapid-Release in Firefox
abstract
Software engineering practices strongly affect the security of the code produced. The increasingly popular Rapid Release Cycle (RRC) development methodology and easy network software distribution have enabled rapid feature introduction. RRC's defining characteristic of frequent software revisions would seem to conflict with traditional software engineering wisdom regarding code maturity, reliability and reuse, as well as security. Our investigation of the consequences of rapid release comprises a quantitative, data-driven study of the impact of rapid-release methodology on the security of the Mozilla Firefox browser. We correlate reported vulnerabilities in multiple rapid release versions of Firefox code against those in corresponding extended release versions of the same system; using a common software base with different release cycles eliminates many causes other than RRC for the observables. Surprisingly, the resulting data show that Firefox RRC does not result in higher vulnerability rates and, further, that it is exactly the unfamiliar, newly released software (the "moving targets") that requires time to exploit. These provocative results suggest that a rethinking of the consequences of software engineering practices for security may be warranted.
Sandy Clark, Michael Collis, Matt Blaze, Jonathan M. Smith
CCS4
2014 RotoRouter: Router support for endpoint-authorized decentralized traffic filtering to prevent DoS attacks
abstract
RotoRouter addresses Denial-of-Service (DoS) attacks on networks with a novel protocol and router implementation. Sets of RotoRouters cooperate in detecting and filtering out invalid network traffic before it reaches network endpoints; a new router-enforceable connection protocol queries destination endpoints to authorize traffic flows and uses per-packet digital signatures to distinguish allowed from disallowed connections. A RotoRouter prototype was implemented on a four-port 1000BASE-T NetFPGA-10G platform and supports 1024 simultaneous active connections using 74 BRAMs (less than one quarter of the available NetFPGA-10G BRAMs). It is able to sustain 800 Mbps per port throughputs for 1500B packets with less than 0.3/its latency, even during a DoS attack. With additional logic and memory resources, the required validation and switching operations scale to port speeds in excess of 10 Gbps and links with more than 10,000 active flows.
Albert Kwon, Perk Lun Lim, Jonathan M. Smith, André DeHon
FPT5
2014 Privacy-aware message exchanges for HumaNets
Adam J. Aviv, Matt Blaze, Micah Sherr, Jonathan M. Smith
Comput. Commun.4
2013 Low-fat pointers: compact encoding and efficient gate-level implementation of fat pointers for spatial safety and capability-based security
abstract
Referencing outside the bounds of an array or buffer is a common source of bugs and security vulnerabilities in today's software. We can enforce spatial safety and eliminate these violations by inseparably associating bounds with every pointer (fat pointer) and checking these bounds on every memory access. By further adding hardware-managed tags to the pointer, we make them unforgeable. This, in turn, allows the pointers to be used as capabilities to facilitate fine-grained access control and fast security domain crossing. Dedicated checking hardware runs in parallel with the processor's normal datapath so that the checks do not slow down processor operation (0% runtime overhead). To achieve the safety of fat pointers without increasing program state, we compactly encode approximate base and bound pointers along with exact address pointers for a 46b address space into one 64-bit word with a worst-case memory overhead of 3%. We develop gate-level implementations of the logic for updating and validating these compact fat pointers and show that the hardware requirements are low and the critical paths for common operations are smaller than processor ALU operations. Specifically, we show that the fat-pointer check and update operations can run in a 4 ns clock cycle on a Virtex 6 (40nm) implementation while only using 1100 6-LUTs or about the area of a double-precision, floating-point adder.
Albert Kwon, Udit Dhawan, Jonathan M. Smith, Thomas F. Knight Jr., André DeHon
CCS3
2012 Practicality of accelerometer side channels on smartphones
abstract
Modern smartphones are equipped with a plethora of sensors that enable a wide range of interactions, but some of these sensors can be employed as a side channel to surreptitiously learn about user input. In this paper, we show that the accelerometer sensor can also be employed as a high-bandwidth side channel; particularly, we demonstrate how to use the accelerometer sensor to learn user tap- and gesture-based input as required to unlock smartphones using a PIN/password or Android's graphical password pattern. Using data collected from a diverse group of 24 users in controlled (while sitting) and uncontrolled (while walking) settings, we develop sample rate independent features for accelerometer readings based on signal processing and polynomial fitting techniques. In controlled settings, our prediction model can on average classify the PIN entered 43% of the time and pattern 73% of the time within 5 attempts when selecting from a test set of 50 PINs and 50 patterns. In uncontrolled settings, while users are walking, our model can still classify 20% of the PINs and 40% of the patterns within 5 attempts. We additionally explore the possibility of constructing an accelerometer-reading-to-input dictionary and find that such dictionaries would be greatly challenged by movement-noise and cross-user training.
Adam J. Aviv, Benjamin Sapp, Matt Blaze, Jonathan M. Smith
ACSAC4
2012 Privacy-Aware Message Exchanges for Geographically Routed Human Movement Networks
Adam J. Aviv, Micah Sherr, Matt Blaze, Jonathan M. Smith
ESORICS4
2012 MOSAIC: Declarative platform for dynamic overlay composition
Yun Mao, Boon Thau Loo, Zachary G. Ives, Jonathan M. Smith
Comput. Networks4
2011 Preliminary design of the SAFE platform
abstract
Safe is a clean-slate design for a secure host architecture. It integrates advances in programming languages, operating systems, and hardware and incorporates formal methods at every step. Though the project is still at an early stage, we have assembled a set of basic architectural choices that we believe will yield a high-assurance system. We sketch the current state of the design and discuss several of these choices.
André DeHon, Ben Karel, Thomas F. Knight Jr., Gregory Malecha, Benoît Montagu, Robin Morisset, J. Gregory Morrisett, Benjamin C. Pierce, Randy Pollack, Sumit Ray, Olin Shivers, Jonathan M. Smith, Greg Sullivan
PLOS@SOSP12
2010 Familiarity breeds contempt: the honeymoon effect and the role of legacy code in zero-day vulnerabilities
abstract
Work on security vulnerabilities in software has primarily focused on three points in the software life-cycle: (1) finding and removing software defects, (2) patching or hardening software after vulnerabilities have been discovered, and (3) measuring the rate of vulnerability exploitation. This paper examines an earlier period in the software vulnerability life-cycle, starting from the release date of a version through to the disclosure of the fourth vulnerability, with a particular focus on the time from release until the very first disclosed vulnerability.Analysis of software vulnerability data, including up to a decade of data for several versions of the most popular operating systems, server applications and user applications (both open and closed source), shows that properties extrinsic to the software play a much greater role in the rate of vulnerability discovery than do intrinsic properties such as software quality. This leads us to the observation that (at least in the first phase of a product's existence), software vulnerabilities have different properties from software defects.We show that the length of the period after the release of a software product (or version) and before the discovery of the first vulnerability (the 'Honeymoon' period) is primarily a function of familiarity with the system. In addition, we demonstrate that legacy code resulting from code re-use is a major contributor to both the rate of vulnerability discovery and the numbers of vulnerabilities found; this has significant implications for software engineering principles and practice.
Sandy Clark, Stefan Frei, Matt Blaze, Jonathan M. Smith
ACSAC4
2010 Overcoming an Untrusted Computing Base: Detecting and Removing Malicious Hardware Automatically
abstract
The computer systems security arms race between attackers and defenders has largely taken place in the domain of software systems, but as hardware complexity and design processes have evolved, novel and potent hardware-based security threats are now possible. This paper presents a hybrid hardware/software approach to defending against malicious hardware. We propose BlueChip, a defensive strategy that has both a design-time component and a runtime component. During the design verification phase, BlueChip invokes a new technique, unused circuit identification (UCI), to identify suspicious circuitry-those circuits not used or otherwise activated by any of the design verification tests. BlueChip removes the suspicious circuitry and replaces it with exception generation hardware. The exception handler software is responsible for providing forward progress by emulating the effect of the exception generating instruction in software, effectively providing a detour around suspicious hardware. In our experiments, BlueChip is able to prevent all hardware attacks we evaluate while incurring a small runtime overhead.
Matthew Hicks, Murph Finnicum, Samuel T. King, Milo M. K. Martin, Jonathan M. Smith
IEEE Symposium on Security and Privacy5
2010 Evading Cellular Data Monitoring with Human Movement Networks
Adam J. Aviv, Micah Sherr, Matt Blaze, Jonathan M. Smith
HotSec4
2009 Networking hardware: what drives innovation?
Jack Brassil, Jonathan M. Smith, Flavio Bonomi, Keren Bergman, Paul Congdon, Ivan Seskar, Steve Muir
ANCS2
2009 Guest editorial network infrastructure configuration
abstract
The nine papers in this special issue focus on network infrastructure configuration and some of the problems encountered in the areas of specification, diagnosis, repair, synthesis, and anonymization.
Paul Anderson 0003, Carl A. Gunter, Charles R. Kalmanek, Sanjai Narain, Jonathan M. Smith, Rajesh Talpade, Geoffrey G. Xie
IEEE J. Sel. Areas Commun.5
2008 MOSAIC: unified declarative platform for dynamic overlay composition
abstract
Overlay networks create new networking services across nodes that communicate using pre-existing networks. MOSAIC is a unified declarative platform for constructing new overlay networks from multiple existing overlays, each possessing a subset of the desired new network's characteristics. MOSAIC overlays are specified using Mozlog, a new declarative language for expressing overlay properties independently from their particular implementation or underlying network.
Yun Mao, Boon Thau Loo, Zachary G. Ives, Jonathan M. Smith
CoNEXT4
2007 Networkmd: topology inference and failure diagnosis in the last mile
abstract
Health monitoring, automated failure localization and diagnosis have all become critical to service providers of large distribution networks (e.g., digital cable and fiber-to-the-home), due to the increases in scale and complexity of their offered services. Existing automated failure diagnosis solutions typically assume complete knowledge of network topology, which in practice is rarely available. The solution presented in this paper - Network Management and Diagnosis (NetworkMD) - is an automated failure diagnosis system that can infer failure groups based on historical failure data, and optionally geographical information. The inferred failure groups mirror missing topologies, and can be used to localize failures, diagnose root causes of problems, and detect misconfiguration in known topologies. NetworkMD uses an unsupervised learning algorithm based on non-negative matrix factorization (NMF) to infer failure groups. Using cable network as the primary example, we demonstrate the effectiveness of NetworkMD in both simulated settings and real environment using data collected from a commercial network serving hundreds of thousands of customers via thousands of intermediate network devices.
Yun Mao, Hani Jamjoom, Shu Tao, Jonathan M. Smith
Internet Measurement Conference4
2007 S4: Small State and Small Stretch Routing Protocol for Large Wireless Sensor Networks
Yun Mao, Lili Qiu, Simon S. Lam, Jonathan M. Smith
NSDI5
2007 Requirements for scalable access control and security management architectures
abstract
Maximizing local autonomy by delegating functionality to end nodes when possible (the end-to-end design principle) has led to a scalable Internet. Scalability and the capacity for distributed control have unfortunately not extended well to resource access-control policies and mechanisms. Yet management of security is becoming an increasingly challenging problem in no small part due to scaling up of measures such as number of users, protocols, applications, network elements, topological constraints, and functionality expectations. In this article, we discuss scalability challenges for traditional access-control mechanisms at the architectural level and present a set of fundamental requirements for authorization services in large-scale networks. We show why existing mechanisms fail to meet these requirements and investigate the current design options for a scalable access-control architecture. We argue that the key design options to achieve scalability are the choice of the representation of access control policy, the distribution mechanism for policy, and the choice of the access-rights revocation scheme. Although these ideas have been considered in the past, current access-control systems in use continue to use simpler but restrictive architectural models. With this article, we hope to influence the design of future access-control systems towards more decentralized and scalable mechanisms.
Angelos D. Keromytis, Jonathan M. Smith
ACM Trans. Internet Techn.2
2006 Flexible network monitoring with FLAME
Kostas G. Anagnostakis, Michael B. Greenwald, Sotiris Ioannidis, Jonathan M. Smith
Comput. Networks5
2006 IDES: An Internet Distance Estimation Service for Large Networks
abstract
The responsiveness of networked applications is limited by communications delays, making network distance an important parameter in optimizing the choice of communications peers. Since accurate global snapshots are difficult and expensive to gather and maintain, it is desirable to use sampling techniques in the Internet to predict unknown network distances from a set of partially observed measurements. This paper makes three contributions. First, we present a model for representing and predicting distances in large-scale networks by matrix factorization which can model suboptimal and asymmetric routing policies, an improvement on previous approaches. Second, we describe two algorithms-singular value decomposition and non-negative matrix factorization-for representing a matrix of network distances as the product of two smaller matrices. Third, based on our model and algorithms, we have designed and implemented a scalable system-Internet Distance Estimation Service (IDES)-that predicts large numbers of network distances from limited samples of Internet measurements. Extensive simulations on real-world data sets show that IDES leads to more accurate, efficient and robust predictions of latencies in large-scale networks than existing approaches
Yun Mao, Lawrence K. Saul, Jonathan M. Smith
IEEE J. Sel. Areas Commun.3
2005 An operating system architecture for network processors
abstract
Network devices have become significantly more complex in recent years, with the most sophisticated current devices incorporating one or more general-purpose CPUs as part of their hardware. The need for such processing capability is motivated by the desire to move greater amounts of functionality, of ever-increasing complexity, from the host CPU to the network device itself. A significant challenge in doing so is managing the complexity of the software running on the network device.We believe that the complexity of this software has reached the point where it is now on a par with many general-purpose systems, and thus requires the same management infrastructure--an operating system for network processors.In this paper we describe an architecture for such an OS, presenting the features most relevant to network processors and describing similarities to and differences from a general-purpose OS. We present a prototype implementation using an SMP system as a virtual network processor, and show how our prototype was used to evaluate a novel user-space interface to a network device.
Steve Muir, Jonathan M. Smith
ANCS2
2005 DHARMA: distributed home agent for robust mobile access
abstract
Mobile wireless devices have intermittent connectivity, sometimes intentional. This is a problem for conventional Mobile IP, beyond its well-known routing inefficiencies and deployment issues. DHARMA selects a location-optimized instance from a distributed set of home agents to minimize routing overheads; set management and optimization are done using the PlanetLab overlay network. DHARMA's session support overcomes both transitions between home agent instances and intermittent connectivity. Cross-layer information sharing between the session layer and the overlay network are used to exploit multiple wireless links when available. The DHARMA prototype supports intermittently connected legacy TCP applications in a variety of scenarios and is largely portable across host operating systems. Experiments with DHARMA deployed on more than 200 PlanetLab nodes demonstrate routing performance consistently better than that for best-case Mobile IP.
Yun Mao, Björn Knutsson, Honghui Lu, Jonathan M. Smith
INFOCOM4
2004 Active Networking: One View of the Past, Present, and Future
abstract
All distributed computing systems face the architectural question of the location (and nature) of programmability in the telecommunications networks, computers, and other peripheral devices comprising them. The perspective of this paper is that network elements should be as programmable as possible, to enable the most flexible distributed computing systems. There has been a persistent confluence among operating systems, programming languages, networking and distributed systems. We demonstrate how these interactions led to what is called "active networking," and in the spirit of "vox audita peril, littera scripta manel" (the spoken word perishes, but the written word remains), include an account of how it was made to happen. Lessons are drawn both from the broader research agenda, and the specific goals pursued in the SwitchWare project. We speculate on likely futures for active networking.
Jonathan M. Smith, Scott Nettles
IEEE Trans. Syst. Man Cybern. Part C1
2003 Balancing performance and flexibility with hardware support for network architectures
abstract
The goals of performance and flexibility are often at odds in the design of network systems. The tension is common enough to justify an architectural solution, rather than a set of context-specific solutions. The Programmable Protocol Processing Pipeline (P4) design uses programmable hardware to selectively accelerate protocol processing functions. A set of field-programmable gate arrays (FPGAs) and an associated library of network processing modules implemented in hardware are augmented with software support for function selection and composition, and applied to processing-intensive portions of a user-programmable protocol stack. The system is sufficiently flexible to support protocol stacks that are dynamically altered in reaction to changing network conditions or user needs.The P4 can be transparently inserted into a conventional protocol architecture, such as that of TCP/IP. This experimental demonstration shows that the P4's programmability can be used to significantly improve the performance of TCP/IP under operating conditions where the protocol would perform poorly without augmentation. Generalizing from these experiments, the P4 is shown to have many applications as an open platform for implementing adaptive and programmable networks, and has illustrated new security issues that arise in FPGA-based architectures.The P4 and closely-related systems, such as network processors, are attractive architectural solutions to balancing performance and flexibility.
Ilija Hadzic, Jonathan M. Smith
ACM Trans. Comput. Syst.2
2003 A secure PLAN
abstract
Active networks, being programmable, promise greater flexibility than current networks. Programmability, however, may introduce safety and security risks. This correspondence describes the design and implementation of a security architecture for the active network PLANet. Security is obtained with a two-level architecture that combines a functionally restricted packet language, PLAN, with an environment of general-purpose service routines governed by trust management. In particular, a technique is used which expands or contracts a packet's service environment based on its level of privilege, termed namespace-based security. The design and implementation of an active-network firewall and virtual private network is used as an application of the security architecture. Measurements of the system show that the addition of the firewall imposes an approximately 34% latency overhead and as little as a 6.7% space overhead to incoming packets.
Michael Hicks 0001, Angelos D. Keromytis, Jonathan M. Smith
IEEE Trans. Syst. Man Cybern. Part C3
2002 Efficient packet monitoring for network management
abstract
Network monitoring is a vital part of modern network infrastructure management. Existing techniques either present a restricted view of network behavior and state, or do not efficiently scale to higher network speeds and heavier monitoring workloads. We present a novel architecture for programmable packet-level network monitoring that addresses these shortcomings. Our approach allows users to customize the monitoring function at the lowest possible level of abstraction to suit a wide range of monitoring needs: we use operating system mechanisms that result in a programming environment providing a high degree of flexibility, retaining fine-grained control over security, and minimizing the associated performance overheads. We present an implementation of this architecture as well as a set of experimental applications.
Kostas G. Anagnostakis, Sotiris Ioannidis, Stefan Miltchev, Michael B. Greenwald, Jonathan M. Smith, John Ioannidis
NOMS5
2000 Implementing a distributed firewall
abstract
Conventional rewalls rely on topology restrictions and controlled network entry points to enforce traÆc ltering.Furthermore, a rewall cannot lter traÆc it does not see, so, eectively, e v eryone on the protected side is trusted.While this model has worked well for small to medium size networks, networking trends such as increased connectivity, higher line speeds, extranets, and telecommuting threaten to make it obsolete.To address the shortcomings of traditional rewalls, the concept of a \distributed rewall" has been proposed.In this scheme, security policy is still centrally de ned, but enforcement is left up to the individual endpoints.IPsec may be used to distribute credentials that express parts of the overall network policy.Alternately, these credentials may be obtained through out-of-band means.In this paper, we present the design and implementation of a distributed rewall using the KeyNote trust management system to specify, distribute, and resolve policy, and OpenBSD, an open source UNIX operating system.
Sotiris Ioannidis, Angelos D. Keromytis, Steven M. Bellovin, Jonathan M. Smith
CCS4
1999 EROS: a fast capability system
abstract
EROS is a capability-based operating system for commodity processors which uses a single level storage model. The single level store's persistence is transparent to applications. The performance consequences of support for transparent persistence and capability-based architectures are generally believed to be negative. Surprisingly, the basic operations of EROS (such as IPC) are generally comparable in cost to similar operations in conventional systems. This is demonstrated with a set of microbenchmark measurements of semantically similar operations in Linux.The EROS system achieves its performance by coupling well-chosen abstract objects with caching techniques for those objects. The objects (processes, nodes, and pages) are well-supported by conventional hardware, reducing the overhead of capabilities. Software-managed caching techniques for these objects reduce the cost of persistence. The resulting performance suggests that composing protected subsystems may be less costly than commonly believed.
Jonathan S. Shapiro, Jonathan M. Smith, David J. Farber
SOSP2
1998 Automated Recovery in a Secure Bootstrap Process
William A. Arbaugh, Angelos D. Keromytis, David J. Farber, Jonathan M. Smith
NDSS4
1998 Protocol boosters
abstract
This paper describes a new methodology for protocol design, using incremental construction of the protocol from elements called "protocol boosters" on an as-needed basis. Protocol boosters allow: (1) dynamic protocol customization to heterogeneous environments and (2) rapid protocol evolution. Unlike alternative adaptation approaches, such as link layer, conversion, and termination protocols, protocol boosters are both robust (end-to-end protocol messages are not modified) and efficient (do not replicate the functionality of the end-to-end protocol). We give examples of error and congestion control boosters, and give initial results from booster implementations.
David C. Feldmeier, Tony McAuley, Jonathan M. Smith, Deborah S. Bakin, William S. Marcus, Thomas Raleigh
IEEE J. Sel. Areas Commun.3
1997 Active Bridging
abstract
Active networks accelerate network evolution by permitting the network infrastructure to be programmable, on a per-user, per-packet, or other basis. This programmability must be balanced against the safety and security needs inherent in shared resources.This paper describes the design, implementation, and performance of a new type of network element, an Active Bridge. The active bridge can be reprogrammed "on the fly", with loadable modules called switchlets. To demonstrate the use of the active property, we incrementally extend what is initially a programmable buffered repeater with switchlets into a self-learning bridge, and then a bridge supporting spanning tree algorithms. To demonstrate the agility that active networking gives, we show how it is possible to upgrade a network from an "old" protocol to a "new" protocol on-the-fly. Moreover, we are able to take advantage of information unavailable to the implementors of either protocol to validate the new protocol and fall back to the old protocol if an error is detected. This shows that the Active Bridge can protect itself from some algorithmic failures in loadable modules.Our approach to safety and security favors static checking and prevention over dynamic checks when possible. We rely on strong type checking in the Caml language for the loadable module infrastructure, and achieve respectable performance. The prototype implementation on a Pentium-based HP Netserver LS running Linux with 100 Mbps Ethernet LANS achieves ttcp throughput of 16 Mbps between two PCs running Linux, compared with 76 Mbps unbridged. Measured frame rates are in the neighborhood of 1800 frames per second.
D. Scott Alexander, Marianne Shaw, Scott Nettles, Jonathan M. Smith
SIGCOMM4
1997 A Secure and Reliable Bootstrap Architecture
abstract
In a computer system, the integrity of lower layers is typically treated as axiomatic by higher layers. Under the presumption that the hardware comprising the machine (the lowest layer) is valid, the integrity of a layer can be guaranteed if and only if: (1) the integrity of the lower layers is checked and (2) transitions to higher layers occur only after integrity checks on them are complete. The resulting integrity "chain" inductively guarantees system integrity. When these conditions are not met, as they typically are not in the bootstrapping (initialization) of a computer system, no integrity guarantees can be made, yet these guarantees are increasingly important to diverse applications such as Internet commerce, security systems and "active networks". In this paper, we describe the AEGIS architecture for initializing a computer system. It validates integrity at each layer transition in the bootstrap process. AEGIS also includes a recovery process for integrity check failures, and we show how this results in robust systems.
William A. Arbaugh, David J. Farber, Jonathan M. Smith
S&P3
1996 Design, Implementation, and Experiences of the OMEGA End-Point Architecture
abstract
The OMEGA architecture provides end-to-end quality-of-service (QoS) guarantees for distributed applications. QoS parameters are translated between application and network requirements by the QoS broker, thus integrating media and network QoS management into a single entity. Admission control uses a schedulability test derived from application requirements. A novel task priority and precedence-based scheme is used to represent complex application requirements and ensure correct feasible schedules. A prototype of OMEGA has been implemented using workstations connected by a 155 Mb/s dedicated ATM local-area network (LAN). To simplify implementation, we assumed networked multimedia application with periodic media streams, specifically a master/slave telerobotics application. This application employs media with highly diverse QoS requirements (e.g., interarrival times, loss rate, and bandwidth) and therefore provides a good platform for testing how closely one can achieve QoS guarantees with workstation hosts and cell-switching. Experience with this implementation has helped to identify new challenges to extending these techniques to a larger domain of applications and systems, and suggests promising new research questions.
Klara Nahrstedt, Jonathan M. Smith
IEEE J. Sel. Areas Commun.2
1994 Quad-Tree Segmentation for Texture-Based Image Query
abstract
In this paper we propose a technique for segmenting images by texture content with application to indexing images in a large image database. Using quad-tree decomposition, texture features are extracted from spatial blocks at a hierarchy of scales in each image. The quad-tree is grown by iteratively testing conditions for splitting parent blocks based on texture content of children blocks. While this approach does not achieve smooth identification of texture region borders, homogeneous blocks of texture are extracted which can be used in a database index. Furthermore, this technique performs the segmentation directly using image spatial-frequency data. In the segmentation reported here, texture features are extracted from the wavelet representation of the image. This method however, can use other subband decompositions including Discrete Cosine Transform (DCT), which has been adopted by the JPEG standard for image coding. This makes our segmentation method extremely applicable to databases containing compressed image data. We show application of the texture segmentation towards providing a new method for searching for images in large image databases using “Query-by-texture.”
Jonathan M. Smith, Shih-Fu Chang
ACM Multimedia1
1993 An application-driven approach to networked multimedia systems
abstract
Several architectural choices possible in logical multiplexing, accommodating QoS dynamics, and functional divisions between senders and receivers are discussed. The authors' application requirements favor integration rather than channelization, supporting quality of service (QoS) dynamics with a renegotiation mechanism, and pushing complexity towards receivers. The choices are tested via implementation of a telerobotics/teleoperation application. This application is particularly challenging due to its demand for multiple concurrent media streams with varied QoS requirements.
Klara Nahrstedt, Jonathan M. Smith
LCN2
1993 The AURORA Gigabit Testbed
David D. Clark, Bruce S. Davie, David J. Farber, Inder S. Gopal, Bharath K. Kadaba, W. David Sincoskie, Jonathan M. Smith, David L. Tennenhouse
Comput. Networks ISDN Syst.7
1993 Hardware/Software Organization of a High-Performance ATM Host Interface
abstract
A successful hardware/software architecture that resolves performance bottlenecks at the workstation-to-network host interface and offers high end-to-end performance is described. The solution reported carefully splits protocol processing functions into hardware and software implementations. The interface hardware is highly parallel and performs all per-cell functions with dedicated logic to maximize performance. Software provides support for the transfer of data between the interface and application memory, as well as the state management necessary for virtual circuit setup and maintenance. In addition, all higher-level protocol processing is implemented with host software. The prototype connects a RISC System/6000 to a SONET-based asynchronous transfer model (ATM) network carrying data at the OC-3c rate of 155 Mb/s. An experimental evaluation of the interface hardware and software has been performed. Several conclusions are drawn about this host interface architecture and the workstations to which it is connected.>
C. Brandan S. Traw, Jonathan M. Smith
IEEE J. Sel. Areas Commun.2
1992 An Overview of the AURORA Gigabit Testbed
abstract
AURORA is one of five US testbeds charged with exploring applications of, and technologies necessary for, networks operating at gigabit per second or higher bandwidths. The authors provide an overview of the goals and methodologies employed in AURORA and report preliminary results from the first year of research. AURORA is an experiment in collaboration, where government support has spurred interaction among centers of excellence in industry, academia, and government. The emphasis of the AURORA testbed is research into the supporting technologies for gigabit networking. The targets include new software architectures, network abstractions, hardware technologies, and applications. The AURORA testbed will provide a platform in which researchers can explore business and scientific applications of gigabit networks, while evolving the network architecture to meet the needs of these emerging applications.>
David D. Clark, David L. Tennenhouse, David J. Farber, Jonathan M. Smith, Bruce S. Davie, W. David Sincoskie, Inder S. Gopal, Bharath K. Kadaba
INFOCOM4
1991 Exploiting Parallelism in Hardware Implementations of the DES
Albert G. Broscius, Jonathan M. Smith
CRYPTO2
1991 A High-Performance Host Interface for ATM Networks
abstract
The advent of high speed networks has increased demands on processor architectures.These architectural demands are due to the increase in network bandwidth relative to the speeds of processor components.One impottant component for a balanced system is the workstation-to-network ho,u inlerjface.Our solution migrates a carefully selected set of protocol processing functions into hardware.It connects an IBM RS/6000 workstation to a Synchronous Optical Network (SONET) STS-3c~line carrying fmedsize Asynchronous Transfer Mode (ATM) cells.The host interface described in this paper is highly parallel and a pure hardware solution to maximize performance.The~is a clean separation between the interface functions, such as segmentation and reassembly, and the interfacelhost communication.This separation eases porting the interface to other workstation plafforms.We intend to use this interface (and its successors) as a component of the AURORA gigabit per second (Gbps) testbed.
C. Brandan S. Traw, Jonathan M. Smith
SIGCOMM2
1991 Traffic Characteristics of a Distributed Memory System
abstract
We believe that many distributed computing systems of the future will use distributed shared memory as a technique for interprocess communication. Thus, traffic generated by memory requests will be a major component of the traffic for any networks which connect nodes in such a system. In this paper, we study memory reference strings gathered with a tracing program we devised. We study several models. First, we look at raw reference data, as would be seen if the network were a backplane. Second, we examine references in units of “blocks”, first using a one-block cache model and then with an infinite cache. Finally, we study the effect of predictive prepaging of these “blocks” on the traffic. We provide a novel representation of memory reference data which can used to calculate interarrival distributions directly. Integrating communication with computation can be used to control both traffic and performance.
Jonathan M. Smith, David J. Farber
Comput. Networks ISDN Syst.1
1989 Practical Problems with a Cryptographic Protection Scheme
Jonathan M. Smith
CRYPTO1
1989 Transparent Concurrent Execution of Mutually Exclusive Alternatives
abstract
The task of concurrently computing alternative solutions to a problem where only one of the solutions is needed is examined. In this case the rule for selecting between the solutions is faster first, where the first successful alternative is selected. For problems where the required execution time is unpredictable, this method shows substantial execution time performance increases over other methods. In order to test the utility of the design, it is used for two application areas: distributed execution of recovery blocks and OR-parallelism in Prolog. The authors present: (1) a model for selection of alternatives in a sequential setting: (2) a transformation that allows alternatives to execute concurrently; (3) a description of the semantics-preservation mechanism; and (4) parameterization of where the performance improvements can be expected. Additionally, examples of application areas for the method are given.>
Jonathan M. Smith, Gerald Q. Maguire Jr.
ICDCS1
1989 Exploring "Multiple Worlds" in Parallel
Jonathan M. Smith, Gerald Q. Maguire Jr.
ICPP (2)1
1989 Rapid Location of Mount Points
Jonathan M. Smith
Softw. Pract. Exp.1