<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-36203843</id><updated>2011-06-07T23:42:48.132-07:00</updated><title type='text'>osdi2006</title><subtitle type='html'>This is an open forum for discussion of papers
presented at OSDI 2006.  Please add your comments
to these postings.  We invite comments from anyone
who has read the paper or heard the presentation;
please note that the papers themselves are not available for free online access until 2007.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>OSDI06 PC</name><uri>http://www.blogger.com/profile/10296610751162559661</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>30</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-36203843.post-116292329883291504</id><published>2006-11-07T10:13:00.000-08:00</published><updated>2006-11-07T10:14:59.346-08:00</updated><title type='text'>General comments on OSDI 2006</title><content type='html'>Please use comments on this posting to discuss the conference in general,&lt;br /&gt;including suggestions for improvements.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116292329883291504?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116292329883291504/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116292329883291504' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116292329883291504'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116292329883291504'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/11/general-comments-on-osdi-2006.html' title='General comments on OSDI 2006'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116286564740294344</id><published>2006-11-06T18:12:00.000-08:00</published><updated>2006-11-06T18:14:07.463-08:00</updated><title type='text'>OSDI Poster Session</title><content type='html'>Please comment on the OSDI Poster Session.&lt;br /&gt;&lt;br /&gt; The OSDI Posters are listed at&lt;br /&gt;    http://www.usenix.org/events/osdi06/poster.html&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116286564740294344?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116286564740294344/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116286564740294344' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116286564740294344'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116286564740294344'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/11/osdi-poster-session.html' title='OSDI Poster Session'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116286551847525886</id><published>2006-11-06T18:10:00.000-08:00</published><updated>2006-11-06T18:11:58.816-08:00</updated><title type='text'>OSDI Work-in-Progress Session</title><content type='html'>Please comment on the Work-in-Progress (WIP) Session.&lt;br /&gt;&lt;br /&gt;The  OSDI  WIPs are listed at&lt;br /&gt;   http://www.usenix.org/events/osdi06/wips.html&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116286551847525886?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116286551847525886/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116286551847525886' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116286551847525886'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116286551847525886'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/11/osdi-work-in-progress-session.html' title='OSDI Work-in-Progress Session'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116234486387277226</id><published>2006-10-31T17:33:00.000-08:00</published><updated>2006-10-31T17:34:23.986-08:00</updated><title type='text'>Paper: "Rethink the Sync"</title><content type='html'>&lt;p&gt; &lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt;&lt;b&gt;Rethink the Sync&lt;/b&gt;&lt;br /&gt;Edmund B. Nightingale, Kaushik Veeraraghavan, Peter M. Chen, and Jason Flinn, &lt;i&gt;University of Michigan&lt;/i&gt; &lt;/span&gt;&lt;/p&gt;&lt;h3&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Abstract&lt;/span&gt;&lt;/h3&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;We introduce &lt;em&gt;external synchrony&lt;/em&gt;, a new model for local file I/O that provides the reliability and simplicity of synchronous I/O, yet also closely approximates the performance of asynchronous I/O. An external observer cannot distinguish the output of a computer with an externally synchronous file system from the output of a computer with a synchronous file system. No application modification is required to use an externally synchronous file system: in fact, application developers can program to the simpler synchronous I/O abstraction and still receive excellent performance. We have implemented an externally synchronous file system for Linux, called xsyncfs. Xsyncfs provides the same durability and ordering guarantees as those provided by a &lt;em&gt;synchronously&lt;/em&gt; mounted ext3 file system. Yet, even for I/O-intensive benchmarks, xsyncfs performance is within 7% of ext3 mounted &lt;em&gt;asynchronously&lt;/em&gt;. Compared to ext3 mounted synchronously, xsyncfs is up to two orders of magnitude faster.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116234486387277226?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116234486387277226/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116234486387277226' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234486387277226'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234486387277226'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/10/paper-rethink-sync_31.html' title='Paper: &quot;Rethink the Sync&quot;'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116234481592223006</id><published>2006-10-31T17:32:00.000-08:00</published><updated>2006-10-31T17:33:36.066-08:00</updated><title type='text'>Paper: "Type-Safe Disks"</title><content type='html'>&lt;p&gt; &lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt;&lt;b&gt;Type-Safe Disks&lt;/b&gt;&lt;br /&gt;Gopalan Sivathanu, Swaminathan Sundararaman, and Erez Zadok, &lt;i&gt;Stony Brook University&lt;/i&gt; &lt;/span&gt;&lt;/p&gt;&lt;h3&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Abstract&lt;/span&gt;&lt;/h3&gt; &lt;!-- CHANGE --&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;We present the notion of a &lt;i&gt;type-safe disk&lt;/i&gt; (TSD).  Unlike a traditional disk system, a TSD is aware of the pointer relationships between disk blocks that are imposed by higher layers such as the file system.  A TSD utilizes this knowledge in two key ways.  First, it enables active enforcement of invariants on data access based on the pointer relationships, resulting in better security and integrity. Second, it enables semantics-aware optimizations within the disk system.  Through case studies, we demonstrate the benefits of TSDs and show that a TSD presents a simple yet effective general interface to build the next generation of storage systems.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116234481592223006?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116234481592223006/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116234481592223006' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234481592223006'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234481592223006'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/10/paper-type-safe-disks_31.html' title='Paper: &quot;Type-Safe Disks&quot;'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116234475544389032</id><published>2006-10-31T17:31:00.000-08:00</published><updated>2006-10-31T17:32:35.550-08:00</updated><title type='text'>Paper: "Stasis: Flexible Transactional Storage"</title><content type='html'>&lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt;&lt;b&gt;Stasis: Flexible Transactional Storage&lt;/b&gt;&lt;br /&gt;Russell Sears and Eric Brewer, &lt;i&gt;University of California, Berkeley&lt;/i&gt;&lt;br /&gt;&lt;/span&gt;&lt;h3&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Abstract&lt;/span&gt;&lt;/h3&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt; An increasing range of applications requires robust support for atomic, durable and concurrent transactions. Databases provide the default solution, but force applications to interact via SQL and to forfeit control over data layout and access mechanisms. We argue there is a gap between DBMSs and file systems that limits designers of data-oriented applications. &lt;/span&gt;&lt;p&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Stasis is a storage framework that incorporates ideas from traditional write-ahead logging algorithms and file systems. It provides applications with flexible control over data structures, data layout, robustness, and performance. Stasis enables the development of unforeseen variants on transactional storage by generalizing write-ahead logging algorithms. Our partial implementation of these ideas already provides specialized (and cleaner) semantics to applications. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;We evaluate the performance of a traditional transactional storage system based on Stasis, and show that it performs favorably relative to existing systems. We present examples that make use of custom access methods, modified buffer manager semantics, direct log file manipulation, and LSN-free pages. These examples facilitate sophisticated performance optimizations such as zero-copy I/O. These extensions are composable, easy to implement and significantly improve performance. &lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116234475544389032?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116234475544389032/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116234475544389032' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234475544389032'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234475544389032'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/10/paper-stasis-flexible-transactional.html' title='Paper: &quot;Stasis: Flexible Transactional Storage&quot;'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116234466320883842</id><published>2006-10-31T17:30:00.000-08:00</published><updated>2006-10-31T17:31:03.276-08:00</updated><title type='text'>Paper: "SafeDrive: Safe and Recoverable Extensions Using Language-Based Techniques"</title><content type='html'>&lt;p&gt; &lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt;&lt;b&gt;SafeDrive: Safe and Recoverable Extensions Using Language-Based Techniques&lt;/b&gt;&lt;br /&gt;Feng Zhou, Jeremy Condit, Zachary Anderson, and Ilya Bagrak, &lt;i&gt;University of California, Berkeley;&lt;/i&gt; Rob Ennals, &lt;i&gt;Intel Research Berkeley;&lt;/i&gt; Matthew Harren, George Necula, and Eric Brewer, &lt;i&gt;University of California, Berkeley&lt;/i&gt; &lt;/span&gt;&lt;/p&gt;&lt;h3&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Abstract&lt;/span&gt;&lt;/h3&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;We present SafeDrive, a system for detecting and recovering from type safety violations in software extensions. SafeDrive has low overhead and requires minimal changes to existing source code. To achieve this result, SafeDrive uses a novel type system that provides fine-grained isolation for existing extensions written in C. In addition, SafeDrive tracks invariants using simple wrappers for the host system API and restores them when recovering from a violation. This approach achieves fine-grained memory error detection and recovery with few code changes and at a significantly lower performance cost than existing solutions based on hardware-enforced domains, such as Nooks, L4, and Xen, or software-enforced domains, such as SFI. The principles used in SafeDrive can be applied to any large system with loadable, error-prone extension modules. &lt;/span&gt;&lt;p&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;In this paper we describe our experience using SafeDrive for protection and recovery of a variety of Linux device drivers. In order to apply SafeDrive to these device drivers, we had to change less than 4% of the source code. SafeDrive recovered from all 44 crashes due to injected faults in a network card driver. In experiments with 6 different drivers, we observed increases in kernel CPU utilization of 4–23% with no noticeable degradation in end-to-end performance. &lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116234466320883842?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116234466320883842/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116234466320883842' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234466320883842'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234466320883842'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/10/paper-safedrive-safe-and-recoverable.html' title='Paper: &quot;SafeDrive: Safe and Recoverable Extensions Using Language-Based Techniques&quot;'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116234460673732025</id><published>2006-10-31T17:29:00.000-08:00</published><updated>2006-10-31T17:30:06.836-08:00</updated><title type='text'>Paper: "BrowserShield: Vulnerability-Driven Filtering of Dynamic HTML"</title><content type='html'>&lt;p&gt; &lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt;&lt;b&gt;BrowserShield: Vulnerability-Driven Filtering of Dynamic HTML&lt;/b&gt;&lt;br /&gt;Charles Reis, &lt;i&gt;University of Washington;&lt;/i&gt; John Dunagan,  Helen J. Wang, and Opher Dubrovsky, &lt;i&gt;Microsoft;&lt;/i&gt; Saher Esmeir, &lt;i&gt;Technion&lt;/i&gt; &lt;/span&gt;&lt;/p&gt;&lt;h3&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Abstract&lt;/span&gt;&lt;/h3&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Vulnerability-driven filtering of network data can offer a fast and easy-to-deploy alternative or intermediary to software patching, as exemplified in Shield. In this paper, we take Shield's vision to a new domain, inspecting and cleansing not just static content, but also dynamic content. The dynamic content we target is the dynamic HTML in web pages, which have become a popular vector for attacks. The key challenge in filtering dynamic HTML is that it is undecidable to statically determine whether an embedded script will exploit the browser at run-time. We avoid this undecidability problem by rewriting web pages and any embedded scripts into safe equivalents, inserting checks so that the filtering is done at run-time. The rewritten pages contain logic for recursively applying run-time checks to dynamically generated or modified web content, based on known vulnerabilities. We have built and evaluated &lt;i&gt;&lt;b&gt;BrowserShield,&lt;/b&gt;&lt;/i&gt; a system that performs this dynamic instrumentation of embedded scripts, and that admits policies for customized run-time actions like vulnerability-driven filtering.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116234460673732025?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116234460673732025/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116234460673732025' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234460673732025'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234460673732025'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/10/paper-browsershield-vulnerability.html' title='Paper: &quot;BrowserShield: Vulnerability-Driven Filtering of Dynamic HTML&quot;'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116234455322944034</id><published>2006-10-31T17:28:00.000-08:00</published><updated>2006-10-31T17:29:13.516-08:00</updated><title type='text'>Paper: "XFI: Software Guards for System Address Spaces"</title><content type='html'>&lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt;&lt;b&gt;XFI: Software Guards for System Address Spaces&lt;/b&gt;&lt;br /&gt;Úlfar Erlingsson, &lt;i&gt;Microsoft Research, Silicon Valley;&lt;/i&gt;  Martín Abadi, &lt;i&gt;Microsoft Research, Silicon Valley, and University of California, Santa Cruz;&lt;/i&gt;  Michael Vrable, &lt;i&gt;University of California, San Diego;&lt;/i&gt; Mihai Budiu, &lt;i&gt;Microsoft Research, Silicon Valley; &lt;/i&gt; George C. Necula, &lt;i&gt;University of California, Berkeley&lt;/i&gt; &lt;br /&gt;&lt;/span&gt;&lt;h3&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Abstract&lt;/span&gt;&lt;/h3&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;XFI is a comprehensive protection system that offers both flexible access control and fundamental integrity guarantees, at any privilege level and even for legacy code in commodity systems. For this purpose, XFI combines static analysis with inline software guards and a two-stack execution model. We have implemented XFI for Windows on the x86 architecture using binary rewriting and a simple, stand-alone verifier; the implementation's correctness depends on the verifier, but not on the rewriter. We have applied XFI to software such as device drivers and multimedia codecs. The resulting modules function safely within both kernel and user-mode address spaces, with only modest enforcement overheads.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116234455322944034?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116234455322944034/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116234455322944034' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234455322944034'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234455322944034'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/10/paper-xfi-software-guards-for-system.html' title='Paper: &quot;XFI: Software Guards for System Address Spaces&quot;'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116234426487470368</id><published>2006-10-31T17:23:00.000-08:00</published><updated>2006-10-31T17:24:25.086-08:00</updated><title type='text'>Paper: "Operating System Profiling via Latency Analysis"</title><content type='html'>&lt;p&gt; &lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt;&lt;b&gt;Operating System Profiling via Latency Analysis&lt;/b&gt;&lt;br /&gt;Nikolai Joukov, Avishay Traeger, and Rakesh Iyer, &lt;i&gt;Stony Brook University;&lt;/i&gt; Charles P. Wright, &lt;i&gt;Stony Brook University and IBM T.J. Watson Research Center;&lt;/i&gt; Erez Zadok, &lt;i&gt;Stony Brook University&lt;/i&gt; &lt;/span&gt;&lt;/p&gt;&lt;h3&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Abstract&lt;/span&gt;&lt;/h3&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Operating systems are complex and their behavior depends on many factors. Source code, if available, does not directly help one to understand the OS's behavior, as the behavior depends on actual workloads and external inputs. Runtime profiling is a key technique to prove new concepts, debug problems, and optimize performance. Unfortunately, existing profiling methods are lacking in important areas-they do not provide enough information about the OS's behavior, they require OS modification and therefore are not portable, or they incur high overheads thus perturbing the profiled OS. &lt;/span&gt;&lt;p&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;We developed OSprof: a versatile, portable, and efficient OS profiling method based on latency distributions analysis. OSprof automatically selects important profiles for subsequent visual analysis. We have demonstrated that a suitable workload can be used to profile virtually any OS component. OSprof is portable because it can intercept operations and measure OS behavior from user-level or from inside the kernel without requiring source code. OSprof has typical CPU time overheads below 4%. In this paper we describe our techniques and demonstrate their usefulness through a series of profiles conducted on Linux, FreeBSD, and Windows, including client/server scenarios. We discovered and investigated a number of interesting interactions, including scheduler behavior, multi-modal I/O distributions, and a previously unknown lock contention, which we fixed. &lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116234426487470368?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116234426487470368/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116234426487470368' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234426487470368'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234426487470368'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/10/paper-operating-system-profiling-via.html' title='Paper: &quot;Operating System Profiling via Latency Analysis&quot;'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116234420336528310</id><published>2006-10-31T17:22:00.000-08:00</published><updated>2006-10-31T17:23:30.330-08:00</updated><title type='text'>Paper: "CRAMM: Virtual Memory Support for Garbage-Collected Applications"</title><content type='html'>&lt;p&gt; &lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt;&lt;b&gt;CRAMM: Virtual Memory Support for Garbage-Collected Applications&lt;/b&gt;&lt;br /&gt;Ting Yang and Emery D. Berger, &lt;i&gt;University of Massachusetts Amherst;&lt;/i&gt; Scott F. Kaplan, &lt;i&gt;Amherst College;&lt;/i&gt; J. Eliot B. Moss, &lt;i&gt;University of Massachusetts Amherst&lt;/i&gt; &lt;/span&gt;&lt;/p&gt;&lt;h3&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Abstract&lt;/span&gt;&lt;/h3&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Existing virtual memory systems usually work well with applications written in C and C++, but they do not provide adequate support for garbage-collected applications. The performance of garbage-collected applications is sensitive to heap size. Larger heaps reduce the frequency of garbage collections, making them run several times faster. However, if the heap is too large to fit in the available RAM, garbage collection can trigger thrashing. Existing Java virtual machines attempt to adapt their application heap sizes to fit in RAM, but suffer performance degradations of up to 94% when subjected to bursts of memory pressure. &lt;/span&gt;&lt;p&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;We present CRAMM (Cooperative Robust Automatic Memory Management), a system that solves these problems. CRAMM consists of two parts: (1) a new virtual memory system that collects detailed reference information for (2) an analytical model tailored to the underlying garbage collection algorithm. The CRAMM virtual memory system tracks recent reference behavior with low overhead. The CRAMM heap sizing model uses this information to compute a heap size that maximizes throughput while minimizing paging. We present extensive empirical results demonstrating CRAMM's ability to maintain high performance in the face of changing application and system load. &lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116234420336528310?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116234420336528310/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116234420336528310' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234420336528310'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234420336528310'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/10/paper-cramm-virtual-memory-support-for.html' title='Paper: &quot;CRAMM: Virtual Memory Support for Garbage-Collected Applications&quot;'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116234413682668214</id><published>2006-10-31T17:21:00.000-08:00</published><updated>2006-10-31T17:22:16.916-08:00</updated><title type='text'>Paper: "Flight Data Recorder: Monitoring Persistent-State Interactions to Improve Systems Management"</title><content type='html'>&lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt;&lt;b&gt;Flight Data Recorder: Monitoring Persistent-State Interactions to Improve Systems Management&lt;/b&gt;&lt;br /&gt;Chad Verbowski, Emre Kıcıman, Arunvijay Kumar, and Brad Daniels, &lt;i&gt;Microsoft Research;&lt;/i&gt; Shan Lu, &lt;i&gt;University of Illinois at Urbana-Champaign;&lt;/i&gt; Juhan Lee, &lt;i&gt;Microsoft MSN;&lt;/i&gt; Yi-Min Wang, &lt;i&gt;Microsoft Research;&lt;/i&gt; Roussi Roussev, &lt;i&gt;Florida Institute of Technology&lt;/i&gt;&lt;br /&gt;&lt;/span&gt;&lt;h3&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Abstract&lt;/span&gt;&lt;/h3&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Mismanagement of the persistent  state of a system—all the executable files, configuration settings and other  data that govern how a system functions—causes reliability problems, security  vulnerabilities, and drives up operation costs.  Recent research traces  persistent state interactions—how state is read, modified, etc.—to help  troubleshooting, change management and malware mitigation, but has been limited  by the difficulty of collecting, storing, and analyzing the 10s to 100s of  millions of daily events that occur on a single machine, much less the 1000s or  more machines in many computing environments. &lt;/span&gt;&lt;p&gt;  &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;We present the Flight Data  Recorder (FDR) that enables &lt;i&gt;always-on tracing, storage and analysis&lt;/i&gt; of  persistent state interactions.  FDR uses a domain-specific log format, tailored  to observed file system workloads and common systems management queries.  Our lossless  log format compresses logs to only 0.5–0.9 bytes per interaction.  In this log  format, 1000 machine-days of logs—over 25 billion events—can be analyzed in less  than 30 minutes.  We report on our deployment of FDR to 207 production machines  at MSN, and show that a single centralized collection machine can potentially scale  to collecting and analyzing the complete records of persistent state  interactions from 4000+ machines. Furthermore, our tracing technology is  shipping as part of the Windows Vista OS.&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116234413682668214?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116234413682668214/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116234413682668214' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234413682668214'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234413682668214'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/10/paper-flight-data-recorder-monitoring.html' title='Paper: &quot;Flight Data Recorder: Monitoring Persistent-State Interactions to Improve Systems Management&quot;'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116234407424850675</id><published>2006-10-31T17:20:00.000-08:00</published><updated>2006-10-31T17:21:14.373-08:00</updated><title type='text'>Paper: "EXPLODE: A Lightweight, General System for Finding Serious Storage System Errors"</title><content type='html'>&lt;p&gt; &lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt;&lt;b&gt;&lt;span style="font-size:-2;"&gt;E&lt;/span&gt;X&lt;span style="font-size:-2;"&gt;PLODE&lt;/span&gt;: A Lightweight, General System for Finding Serious Storage System Errors&lt;/b&gt;&lt;br /&gt;Junfeng Yang, Can Sar, and Dawson Engler, &lt;i&gt;Stanford University&lt;/i&gt; &lt;/span&gt;&lt;/p&gt;&lt;h3&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Abstract&lt;/span&gt;&lt;/h3&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Storage systems such as file systems, databases, and RAID systems have a simple, basic contract: you give them data, they do not lose or corrupt it. Often they store the only copy, making its irrevocable loss almost arbitrarily bad. Unfortunately, their code is exceptionally hard to get right, since it must correctly recover from any crash at any program point, no matter how their state was smeared across volatile and persistent memory. &lt;/span&gt;&lt;p&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;This paper describes &lt;span style="font-size:-2;"&gt;E&lt;/span&gt;X&lt;span style="font-size:-2;"&gt;PLODE&lt;/span&gt;, a system that makes it easy to systematically check real storage systems for errors. It takes user-written, potentially system-specific checkers and uses them to drive a storage system into tricky corner cases, including crash recovery errors. &lt;span style="font-size:-2;"&gt;E&lt;/span&gt;X&lt;span style="font-size:-2;"&gt;PLODE&lt;/span&gt; uses a novel adaptation of ideas from model checking, a comprehensive, heavy-weight formal verification technique, that makes its checking more systematic (and hopefully more effective) than a pure testing approach while being just as lightweight. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;&lt;span style="font-size:-2;"&gt;E&lt;/span&gt;X&lt;span style="font-size:-2;"&gt;PLODE&lt;/span&gt; is effective. It found serious bugs in a broad range of real storage systems (without requiring source code): three version control systems, Berkeley DB, an NFS implementation, ten file systems, a RAID system, and the popular VMware GSX virtual machine. We found bugs in every system we checked, 36 bugs in total, typically with little effort. &lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116234407424850675?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116234407424850675/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116234407424850675' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234407424850675'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234407424850675'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/10/paper-explode-lightweight-general.html' title='Paper: &quot;EXPLODE: A Lightweight, General System for Finding Serious Storage System Errors&quot;'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116234400869525722</id><published>2006-10-31T17:19:00.000-08:00</published><updated>2006-10-31T17:20:08.753-08:00</updated><title type='text'>Paper: "Securing Software by Enforcing Data-flow Integrity"</title><content type='html'>&lt;p&gt; &lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt;&lt;b&gt;Securing Software by Enforcing Data-flow Integrity&lt;/b&gt;&lt;br /&gt;Miguel Castro, &lt;i&gt;Microsoft Research;&lt;/i&gt; Manuel Costa, &lt;i&gt;Microsoft Research  Cambridge;&lt;/i&gt; Tim Harris, &lt;i&gt;Microsoft Research&lt;/i&gt; &lt;/span&gt;&lt;/p&gt;&lt;h3&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Abstract&lt;/span&gt;&lt;/h3&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Software attacks often subvert the intended data-flow in a vulnerable program. For example, attackers exploit buffer overflows and format string vulnerabilities to write data to unintended locations. We present a simple technique that prevents these attacks by enforcing data-flow integrity. It computes a data-flow graph using static analysis, and it instruments the program to ensure that the flow of data at runtime is allowed by the data-flow graph. We describe an efficient implementation of data-flow integrity enforcement that uses static analysis to reduce instrumentation overhead. This implementation can be used in practice to detect a broad class of attacks and errors because it can be applied automatically to C and C++ programs without modifications, it does not have false positives, and it has low overhead.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116234400869525722?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116234400869525722/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116234400869525722' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234400869525722'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234400869525722'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/10/paper-securing-software-by-enforcing.html' title='Paper: &quot;Securing Software by Enforcing Data-flow Integrity&quot;'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116234393229743308</id><published>2006-10-31T17:17:00.001-08:00</published><updated>2006-10-31T17:18:56.013-08:00</updated><title type='text'>Paper: "From Uncertainty to Belief: Inferring the Specification Within"</title><content type='html'>&lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt;&lt;b&gt;From Uncertainty to Belief: Inferring the Specification Within&lt;/b&gt;&lt;br /&gt;Ted Kremenek and Paul Twohey, &lt;i&gt;Stanford University;&lt;/i&gt; Godmar Back, &lt;i&gt;Virginia Polytechnic Institute and State University;&lt;/i&gt; Andrew Ng and Dawson Engler, &lt;i&gt;Stanford University&lt;/i&gt;   &lt;/span&gt;&lt;br /&gt;&lt;h3&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Abstract&lt;/span&gt;&lt;/h3&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Automatic tools for finding software errors require a set of specifications before they can check code: if they do not know what to check, they cannot find bugs. This paper presents a novel framework based on factor graphs for automatically inferring specifications directly from programs. The key strength of the approach is that it can incorporate many disparate sources of evidence, allowing us to squeeze significantly more information from our observations than previously published techniques. &lt;/span&gt;&lt;p&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;We illustrate the strengths of our approach by applying it to the problem of inferring what functions in C programs allocate and release resources. We evaluated its effectiveness on five codebases: SDL, OpenSSH, GIMP, and the OS kernels for Linux and Mac OS X (XNU). For each codebase, starting with zero initially provided annotations, we observed an inferred annotation accuracy of 80-90%, with often near perfect accuracy for functions called as little as five times. Many of the inferred allocator and deallocator functions are functions for which we both lack the implementation and are rarely called—in some cases functions with at most one or two callsites. Finally, with the inferred annotations we quickly found both missing and incorrect properties in a specification used by a commercial static bug-finding tool. &lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116234393229743308?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116234393229743308/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116234393229743308' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234393229743308'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234393229743308'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/10/paper-from-uncertainty-to-belief.html' title='Paper: &quot;From Uncertainty to Belief: Inferring the Specification Within&quot;'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116234387154547360</id><published>2006-10-31T17:17:00.000-08:00</published><updated>2006-10-31T17:17:51.670-08:00</updated><title type='text'>Paper: "HQ Replication: A Hybrid Quorum Protocol for Byzantine Fault Tolerance"</title><content type='html'>&lt;p&gt; &lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt;&lt;b&gt;HQ Replication: A Hybrid Quorum Protocol for Byzantine Fault Tolerance&lt;/b&gt;&lt;br /&gt;James Cowling, Daniel Myers, and Barbara Liskov, &lt;i&gt;MIT CSAIL;&lt;/i&gt; Rodrigo Rodrigues, &lt;i&gt;INESC-ID and Instituto Superior Técnico;&lt;/i&gt; Liuba Shrira, &lt;i&gt;Brandeis University&lt;/i&gt; &lt;/span&gt;&lt;/p&gt; &lt;h3&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Abstract&lt;/span&gt;&lt;/h3&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;There are currently two approaches to providing Byzantine-fault-tolerant state machine replication: a replica-based approach, e.g., BFT, that uses communication between replicas to agree on a proposed ordering of requests, and a quorum-based approach, such as Q/U, in which clients contact replicas directly to optimistically execute operations. Both approaches have shortcomings: the quadratic cost of inter-replica communication is unnecessary when there is no contention, and Q/U requires a large number of replicas and performs poorly under contention. &lt;/span&gt;&lt;p&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;We present HQ, a hybrid Byzantine-fault-tolerant state machine replication protocol that overcomes these problems. HQ employs a lightweight quorum-based protocol when there is no contention, but  uses BFT to resolve contention when it arises. Furthermore, HQ uses only 3&lt;i&gt;f&lt;/i&gt;+1 replicas to tolerate &lt;i&gt;f&lt;/i&gt; faults, providing optimal resilience to node failures. &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;We implemented a prototype of HQ, and we compare its performance to BFT and Q/U analytically and experimentally. Additionally, in this work we use a new implementation of BFT designed to scale as the number of faults increases. Our results show that both HQ and our new implementation of BFT scale as &lt;i&gt;f&lt;/i&gt; increases;  additionally our hybrid approach of using BFT to handle contention works well. &lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116234387154547360?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116234387154547360/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116234387154547360' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234387154547360'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234387154547360'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/10/paper-hq-replication-hybrid-quorum.html' title='Paper: &quot;HQ Replication: A Hybrid Quorum Protocol for Byzantine Fault Tolerance&quot;'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116234381611818207</id><published>2006-10-31T17:14:00.000-08:00</published><updated>2006-10-31T17:16:56.203-08:00</updated><title type='text'>Paper: "BAR Gossip"</title><content type='html'>&lt;p&gt; &lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt;&lt;b&gt;BAR Gossip&lt;/b&gt;&lt;br /&gt;Harry C. Li, Allen Clement, Edmund L. Wong, Jeff Napper, Indrajit Roy,  Lorenzo Alvisi, and Michael Dahlin, &lt;i&gt;The University of Texas at Austin&lt;/i&gt;&lt;/span&gt;&lt;/p&gt;&lt;h3&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Abstract&lt;/span&gt;&lt;/h3&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;We present the first peer-to-peer data streaming application that guarantees predictable throughput and low latency in the BAR  (Byzantine/Altruistic/Rational) model, in which non-altruistic nodes can behave in ways that are self-serving (rational) or arbitrarily malicious (Byzantine).  At the core of our solution is a BAR-tolerant version of gossip, a well-known technique for scalable and reliable data dissemination.  BAR Gossip relies on &lt;em&gt;verifiable pseudo-random partner selection&lt;/em&gt; to eliminate non-determinism that can be used to game the system while maintaining the robustness and rapid convergence of traditional gossip.  A novel &lt;em&gt;fair enough exchange&lt;/em&gt; primitive entices cooperation among selfish nodes on short timescales, avoiding the need for long-term node reputations. Our initial experience provides evidence for BAR Gossip's robustness.  Our BAR-tolerant streaming application provides over 99% convergence for broadcast updates when all clients are selfish but not colluding, and over 95% convergence when up to 40% of clients collude while the rest follow the protocol.  BAR Gossip also performs well when the client population consists of both selfish and Byzantine nodes, achieving over 93% convergence even when 20% of the nodes are Byzantine.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116234381611818207?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116234381611818207/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116234381611818207' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234381611818207'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234381611818207'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/10/paper-bar-gossip.html' title='Paper: &quot;BAR Gossip&quot;'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116234368988171763</id><published>2006-10-31T17:13:00.000-08:00</published><updated>2006-10-31T17:14:49.980-08:00</updated><title type='text'>Paper: "Bigtable: A Distributed Storage System for Structured Data"</title><content type='html'>&lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt;&lt;b&gt;Bigtable: A Distributed Storage System for Structured Data&lt;/b&gt;&lt;br /&gt;Fay Chang, Jeffrey Dean, Sanjay Ghemawat, Wilson C. Hsieh, Deborah A. Wallach, Mike Burrows, Tushar Chandra, Andrew Fikes, and Robert E. Gruber, &lt;i&gt;Google, Inc.&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;&lt;h3&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Abstract&lt;/span&gt;&lt;/h3&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Bigtable is a distributed storage system for managing structured data that is designed to scale to a very large size: petabytes of data across thousands of commodity servers. Many projects at Google store data in Bigtable, including web indexing, Google Earth, and Google Finance. These applications place very different demands on Bigtable, both in terms of data size (from URLs to web pages to satellite imagery) and latency requirements (from backend bulk processing to real-time data serving). Despite these varied demands, Bigtable has successfully provided a flexible, high-performance solution for all of these Google products. In this paper we describe the simple data model provided by Bigtable, which gives clients dynamic control over data layout and format, and we describe the design and implementation of Bigtable.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116234368988171763?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116234368988171763/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116234368988171763' title='22 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234368988171763'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234368988171763'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/10/paper-bigtable-distributed-storage.html' title='Paper: &quot;Bigtable: A Distributed Storage System for Structured Data&quot;'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>22</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116234360913707705</id><published>2006-10-31T17:12:00.000-08:00</published><updated>2006-10-31T17:13:29.556-08:00</updated><title type='text'>Paper: "EnsemBlue: Integrating Distributed Storage and Consumer Electronics"</title><content type='html'>&lt;p&gt; &lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt;&lt;b&gt;EnsemBlue: Integrating Distributed Storage and Consumer Electronics&lt;/b&gt;&lt;br /&gt;Daniel Peek and Jason Flinn, &lt;i&gt;University of Michigan&lt;/i&gt; &lt;/span&gt;&lt;/p&gt;&lt;h3&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Abstract&lt;/span&gt;&lt;/h3&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;EnsemBlue is a distributed file system for personal multimedia that incorporates both general-purpose computers and consumer electronic devices (CEDs). EnsemBlue leverages the capabilities of a few general-purpose computers to make CEDs first class clients of the file system. It supports namespace diversity by translating between its distributed namespace and the local namespaces of CEDs. It supports extensibility through persistent queries, a robust event notification mechanism that leverages the underlying cache consistency protocols of the file system. Finally, it allows mobile clients to self-organize and share data through device ensembles. Our results show that these features impose little overhead, yet they enable the integration of emerging platforms such as digital cameras, MP3 players, and DVRs.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116234360913707705?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116234360913707705/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116234360913707705' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234360913707705'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234360913707705'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/10/paper-ensemblue-integrating.html' title='Paper: &quot;EnsemBlue: Integrating Distributed Storage and Consumer Electronics&quot;'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116234353850924149</id><published>2006-10-31T17:11:00.000-08:00</published><updated>2006-10-31T17:12:18.510-08:00</updated><title type='text'>Paper: "Persistent Personal Names for Globally Connected Mobile Devices"</title><content type='html'>&lt;p&gt; &lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt;&lt;b&gt;Persistent Personal Names for Globally Connected Mobile Devices&lt;/b&gt;&lt;br /&gt;Bryan Ford, Jacob Strauss, Chris Lesniewski-Laas, Sean Rhea, Frans Kaashoek, and Robert Morris, &lt;i&gt;Massachusetts Institute of Technology&lt;/i&gt; &lt;/span&gt;&lt;/p&gt;&lt;h3&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Abstract&lt;/span&gt;&lt;/h3&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;The &lt;em&gt;Unmanaged Internet Architecture&lt;/em&gt; (UIA) provides zero-configuration connectivity among mobile devices through &lt;i&gt;personal names&lt;/i&gt;. Users assign personal names through an ad hoc device introduction process requiring no central allocation. Once assigned, names bind securely to the global identities of their target devices independent of network location. Each user manages one namespace, shared among all the user's devices and always available on each device. Users can also name other users to share resources with trusted acquaintances. Devices with naming relationships automatically arrange connectivity when possible, both in ad hoc networks and using global infrastructure when available. A UIA prototype demonstrates these capabilities using optimistic replication for name resolution and group management and a routing algorithm exploiting the user's social network for connectivity.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116234353850924149?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116234353850924149/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116234353850924149' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234353850924149'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234353850924149'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/10/paper-persistent-personal-names-for.html' title='Paper: &quot;Persistent Personal Names for Globally Connected Mobile Devices&quot;'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116234348258264037</id><published>2006-10-31T17:10:00.000-08:00</published><updated>2006-10-31T17:11:22.583-08:00</updated><title type='text'>Paper: "A Modular Network Layer for Sensornets"</title><content type='html'>&lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt;&lt;b&gt;A Modular Network Layer for Sensornets&lt;/b&gt;&lt;br /&gt;Cheng Tien Ee, Rodrigo Fonseca, Sukun Kim, Daekyeong Moon, and Arsalan Tavakoli, &lt;i&gt;University of California, Berkeley;&lt;/i&gt; David Culler, &lt;i&gt;University of California, Berkeley, and Arch Rock Corporation;&lt;/i&gt; Scott Shenker, &lt;i&gt;University of California, Berkeley, and International Computer Science Institute (ICSI); &lt;/i&gt;Ion Stoica, &lt;i&gt;University of California, Berkeley&lt;/i&gt;&lt;br /&gt;&lt;/span&gt;&lt;h3&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Abstract&lt;/span&gt;&lt;/h3&gt; &lt;!-- CHANGE --&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;An overall sensornet architecture would help tame the increasingly complex structure of wireless sensornet software and help foster greater interoperability between different codebases. A previous step in this direction is the Sensornet Protocol (SP), a unifying link-abstraction layer. This paper takes the natural next step by proposing a modular network-layer for sensornets that sits atop SP. This modularity eases implementation of new protocols by increasing code reuse, and enables co-existing protocols to share and reduce code and resources consumed at run-time. We demonstrate how current protocols can be decomposed into this modular structure and show that the costs, in performance and code footprint, are minimal relative to their monolithic counterparts.&lt;/span&gt;&lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt; &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116234348258264037?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116234348258264037/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116234348258264037' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234348258264037'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234348258264037'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/10/paper-modular-network-layer-for.html' title='Paper: &quot;A Modular Network Layer for Sensornets&quot;'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116234342286239290</id><published>2006-10-31T17:09:00.000-08:00</published><updated>2006-10-31T17:10:22.863-08:00</updated><title type='text'>Paper: "Making Information Flow Explicit in HiStar"</title><content type='html'>&lt;p&gt; &lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt;&lt;b&gt;Making Information Flow Explicit in HiStar&lt;/b&gt;&lt;br /&gt;Nickolai Zeldovich and Silas Boyd-Wickizer, &lt;i&gt;Stanford University;&lt;/i&gt; Eddie Kohler, &lt;i&gt;University of California, Los Angeles;&lt;/i&gt;  David Mazières, &lt;i&gt;Stanford University&lt;/i&gt; &lt;/span&gt;&lt;/p&gt;&lt;h3&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Abstract&lt;/span&gt;&lt;/h3&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;HiStar is a new operating system designed to minimize the amount of code that must be trusted. HiStar provides strict information flow control, which allows users to specify precise data security policies without unduly limiting the structure of applications. HiStar's security features make it possible to implement a Unix-like environment with acceptable performance almost entirely in an untrusted user-level library. The system has no notion of superuser and no fully trusted code other than the kernel. HiStar's features permit several novel applications, including an entirely untrusted login process, separation of data between virtual private networks, and privacypreserving, untrusted virus scanners.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116234342286239290?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116234342286239290/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116234342286239290' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234342286239290'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234342286239290'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/10/paper-making-information-flow-explicit.html' title='Paper: &quot;Making Information Flow Explicit in HiStar&quot;'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116234333515510953</id><published>2006-10-31T17:08:00.000-08:00</published><updated>2006-10-31T17:08:55.156-08:00</updated><title type='text'>Paper: "Splitting Interfaces: Making Trust Between Applications and Operating Systems Configurable"</title><content type='html'>&lt;p&gt; &lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt;&lt;b&gt;Splitting Interfaces: Making Trust Between Applications and Operating Systems Configurable&lt;/b&gt;&lt;br /&gt;Richard Ta-Min, Lionel Litty, and David Lie, &lt;i&gt;University of Toronto&lt;/i&gt; &lt;/span&gt;&lt;/p&gt;&lt;h3&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Abstract&lt;/span&gt;&lt;/h3&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;In current commodity systems, applications have no way of limiting their trust in the underlying operating system (OS), leaving them at the complete mercy of an attacker who gains control over the OS. In this work, we describe the design and implementation of Proxos, a system that allows applications to configure their trust in the OS by partitioning the system call interface into trusted and untrusted components. System call routing rules that indicate which system calls are to be handled by the untrusted commodity OS, and which are to be handled by a trusted private OS, are specified by the application developer. We find that rather than defining a new system call interface, routing system calls of an existing interface allows applications currently targeted towards commodity operating systems to isolate their most sensitive components from the commodity OS with only minor source code modifications. &lt;/span&gt;&lt;p&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;We have built a prototype of our system on top of the Xen Virtual Machine Monitor with Linux as the commodity OS. In practice, we find that the system call routing rules are short and simple - on the order of 10's of lines of code. In addition, applications in Proxos incur only modest performance overhead, with most of the cost resulting from inter-VM context switches. &lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116234333515510953?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116234333515510953/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116234333515510953' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234333515510953'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234333515510953'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/10/paper-splitting-interfaces-making.html' title='Paper: &quot;Splitting Interfaces: Making Trust Between Applications and Operating Systems Configurable&quot;'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116234317481943055</id><published>2006-10-31T17:05:00.000-08:00</published><updated>2006-10-31T17:06:14.820-08:00</updated><title type='text'>Paper: "Connection Handoff Policies for TCP Offload Network Interfaces"</title><content type='html'>&lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt;&lt;b&gt;Connection Handoff Policies for TCP Offload Network Interfaces&lt;/b&gt;&lt;br /&gt;Hyong-youb Kim and Scott Rixner, &lt;i&gt;Rice University&lt;/i&gt;  &lt;br /&gt;&lt;/span&gt;&lt;h3&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Abstract&lt;/span&gt;&lt;/h3&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;This paper presents three policies for effectively utilizing TCP offload network interfaces that support connection handoff. These policies allow connection handoff to reduce the computation and memory bandwidth requirements for packet processing on the host processor without causing the resource constraints on the network interface to limit overall system performance. First, prioritizing packet processing on the network interface ensures that its TCP processing does not harm performance of the connections on the host operating system. Second, dynamically adapting the number of connections on the network interface to the current load avoids overloading the network interface. Third, the operating system can predict connection lifetimes to select long-lived connections for handoff to better utilize the network interface. The use of the first two policies improves web server throughput by 12-31% over the baseline throughput achieved without offload. The third policy helps improve performance when the network interface can only handle a small number of connections at a time. Furthermore, by using a faster offload processor, offloading can improve server throughput by 33-72%.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116234317481943055?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116234317481943055/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116234317481943055' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234317481943055'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234317481943055'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/10/paper-connection-handoff-policies-for.html' title='Paper: &quot;Connection Handoff Policies for TCP Offload Network Interfaces&quot;'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116234311803149337</id><published>2006-10-31T17:04:00.000-08:00</published><updated>2006-10-31T17:05:18.033-08:00</updated><title type='text'>Paper: "Ceph: A Scalable, High-Performance Distributed File System"</title><content type='html'>&lt;p&gt; &lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt;&lt;b&gt;Ceph: A Scalable, High-Performance Distributed File System&lt;/b&gt;&lt;br /&gt;Sage A. Weil, Scott A. Brandt, Ethan L. Miller, Darrell D. E. Long, and Carlos Maltzahn, &lt;i&gt;University of California, Santa Cruz&lt;/i&gt; &lt;/span&gt;&lt;/p&gt;&lt;h3&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Abstract&lt;/span&gt;&lt;/h3&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;We have developed Ceph, a distributed file system that provides excellent performance, reliability, and scalability. Ceph maximizes the separation between data and metadata management by replacing allocation tables with a pseudo-random data distribution function (CRUSH) designed for heterogeneous and dynamic clusters of unreliable object storage devices (OSDs). We leverage device intelligence by distributing data replication, failure detection and recovery to semi-autonomous OSDs running a specialized local object file system. A dynamic distributed metadata cluster provides extremely efficient metadata management and seamlessly adapts to a wide range of general purpose and scientific computing file system workloads. Performance measurements under a variety of workloads show that Ceph has excellent I/O performance and scalable metadata management, supporting more than 250,000 metadata operations per second.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116234311803149337?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116234311803149337/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116234311803149337' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234311803149337'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234311803149337'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/10/paper-ceph-scalable-high-performance.html' title='Paper: &quot;Ceph: A Scalable, High-Performance Distributed File System&quot;'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116234305474274755</id><published>2006-10-31T17:03:00.000-08:00</published><updated>2006-10-31T17:04:14.746-08:00</updated><title type='text'>Paper: "Distributed Directory Service in the Farsite File System"</title><content type='html'>&lt;p&gt; &lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt;&lt;b&gt;Distributed Directory Service in the Farsite File System&lt;/b&gt;&lt;br /&gt;John R. Douceur and Jon Howell, &lt;i&gt;Microsoft Research&lt;/i&gt;&lt;/span&gt;&lt;/p&gt;&lt;h3&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Abstract&lt;/span&gt;&lt;/h3&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;We present the design, implementation, and evaluation of a fully distributed directory service for Farsite, a logically centralized file system that is physically implemented on a loosely coupled network of desktop computers. Prior to this work, the Farsite system included distributed mechanisms for file content but centralized mechanisms for file metadata. Our distributed directory service introduces tree-structured file identifiers that support dynamically partitioning metadata at arbitrary granularity, recursive path leases for scalably maintaining name-space consistency, and a protocol for consistently performing operations on files managed by separate machines. It also mitigates metadata hotspots via file-field leases and the new mechanism of disjunctive leases. We experimentally show that Farsite can dynamically partition file-system metadata while maintaining full file-system semantics.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116234305474274755?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116234305474274755/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116234305474274755' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234305474274755'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234305474274755'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/10/paper-distributed-directory-service-in.html' title='Paper: &quot;Distributed Directory Service in the Farsite File System&quot;'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116234268737738170</id><published>2006-10-31T16:56:00.000-08:00</published><updated>2006-10-31T16:58:07.380-08:00</updated><title type='text'>Paper: "The Chubby Lock Service for Loosely-Coupled Distributed Systems"</title><content type='html'>&lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt;&lt;b&gt;The Chubby Lock Service for Loosely-Coupled Distributed Systems&lt;/b&gt;&lt;br /&gt;Mike Burrows, &lt;i&gt;Google Inc.&lt;/i&gt;  &lt;br /&gt;&lt;/span&gt;&lt;h3&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Abstract&lt;/span&gt;&lt;/h3&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;We describe our experiences with the Chubby lock service, which is intended to provide coarse-grained locking as well as reliable (though low-volume) storage for a loosely-coupled distributed system. Chubby provides an interface much like a distributed file system with advisory locks, but the design emphasis is on availability and reliability, as opposed to high performance. Many instances of the service have been used for over a year, with several of them each handling a few tens of thousands of clients concurrently. The paper describes the initial design and expected use, compares it with actual use, and explains how the design had to be modified to accommodate the differences.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116234268737738170?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116234268737738170/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116234268737738170' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234268737738170'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234268737738170'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/10/paper-chubby-lock-service-for-loosely.html' title='Paper: &quot;The Chubby Lock Service for Loosely-Coupled Distributed Systems&quot;'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116234259821619240</id><published>2006-10-31T16:55:00.000-08:00</published><updated>2006-10-31T16:56:38.216-08:00</updated><title type='text'>Paper: "Experiences Building PlanetLab"</title><content type='html'>&lt;p&gt; &lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt;&lt;b&gt;Experiences Building PlanetLab&lt;/b&gt;&lt;br /&gt;Larry Peterson, Andy Bavier, Marc E. Fiuczynski, and Steve Muir, &lt;i&gt;Princeton University&lt;/i&gt; &lt;/span&gt;&lt;/p&gt;&lt;h3&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Abstract&lt;/span&gt;&lt;/h3&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;This paper reports our experiences building PlanetLab over the last four years. It identifies the requirements that shaped PlanetLab, explains the design decisions that resulted from resolving conflicts among these requirements, and reports our experience implementing and supporting the system. Due in large part to the nature of the ``PlanetLab experiment,'' the discussion focuses on synthesis rather than new techniques, balancing system-wide considerations rather than improving performance along a single dimension, and learning from feedback from a live system rather than controlled experiments using synthetic workloads.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116234259821619240?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116234259821619240/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116234259821619240' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234259821619240'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234259821619240'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/10/paper-experiences-building-planetlab.html' title='Paper: &quot;Experiences Building PlanetLab&quot;'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116234254169400816</id><published>2006-10-31T16:54:00.000-08:00</published><updated>2006-10-31T16:55:41.696-08:00</updated><title type='text'>Paper: "iPlane: An Information Plane for Distributed Services"</title><content type='html'>&lt;p&gt; &lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt;&lt;b&gt;iPlane: An Information Plane for Distributed Services&lt;/b&gt;&lt;br /&gt;Harsha Madhyastha, Tomas Isdal, Michael Piatek, Colin Dixon,  Thomas Anderson, and Arvind Krishnamurthy, &lt;i&gt;University of Washington;&lt;/i&gt; Arun Venkataramani, &lt;i&gt;University of Massachusetts Amherst&lt;/i&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="font-weight: bold;"&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Abstract&lt;/span&gt;&lt;/p&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;In this paper, we present the design, implementation, and evaluation of &lt;em&gt;iPlane&lt;/em&gt;, a scalable service providing accurate predictions of Internet path performance for emerging overlay services.  Unlike the more common black box latency prediction techniques in use today, &lt;em&gt;iPlane&lt;/em&gt; adopts a structural approach and predicts end-to-end path performance by composing the performance of measured segments of  Internet paths.  For the paths we observed, this method allows us to  accurately and efficiently predict latency, bandwidth, capacity and loss rates between arbitrary Internet hosts.  We demonstrate the feasibility and utility of the &lt;em&gt;iPlane&lt;/em&gt; service by applying it to several representative overlay services in use today: content distribution, swarming peer-to-peer filesharing, and voice-over-IP. In each case, using &lt;em&gt;iPlane&lt;/em&gt;'s predictions leads to improved overlay performance.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116234254169400816?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116234254169400816/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116234254169400816' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234254169400816'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234254169400816'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/10/paper-iplane-information-plane-for.html' title='Paper: &quot;iPlane: An Information Plane for Distributed Services&quot;'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36203843.post-116234246178511496</id><published>2006-10-31T16:51:00.000-08:00</published><updated>2006-10-31T16:54:21.793-08:00</updated><title type='text'>Paper: "Fidelity and Yield in a Volcano Monitoring Sensor Network"</title><content type='html'>&lt;span style="font-family:arial, verdana,Helvetica,sans-serif;font-size:-1;color:#000000;"&gt;&lt;b&gt;Fidelity and Yield in a Volcano Monitoring Sensor Network&lt;/b&gt;&lt;br /&gt;Geoff Werner-Allen and Konrad Lorincz, &lt;i&gt;Harvard University;&lt;/i&gt; Jeff Johnson, &lt;i&gt;University of New Hampshire;&lt;/i&gt; Jonathan Lees, &lt;i&gt;University of North Carolina;&lt;/i&gt; Matt Welsh, &lt;i&gt;Harvard University&lt;/i&gt;   &lt;br /&gt;&lt;img src="http://www.usenix.org/events/osdi06/art/dot_clear.gif" alt="" height="4" width="2" /&gt;&lt;/span&gt;&lt;br /&gt;&lt;h3&gt;&lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;Abstract&lt;/span&gt;&lt;/h3&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;We present a science-centric evaluation of a 19-day sensor network deployment at Reventador, an active volcano in Ecuador. Each of the 16 sensors continuously sampled seismic and acoustic  data at 100 Hz. Nodes used an event-detection algorithm to trigger  on interesting volcanic activity and initiate reliable data transfer  to the base station. During the deployment, the network recorded 229 earthquakes, eruptions, and other seismoacoustic events.  &lt;/span&gt;&lt;p&gt; &lt;span style="font-family:verdana, arial, helvetica, sans-serif;font-size:-1;"&gt;The science requirements of reliable data collection, accurate event detection, and high timing precision  drive sensor networks in new directions for geophysical monitoring. The main contribution of this paper is an evaluation of the sensor network as a scientific instrument, holding it to the standards of existing instrumentation in terms of data &lt;em&gt;fidelity&lt;/em&gt; (the quality and accuracy of the recorded signals) and &lt;em&gt;yield&lt;/em&gt; (the quantity of the captured data).   We describe an approach to &lt;em&gt;time rectification&lt;/em&gt; of the acquired  signals that can recover accurate timing despite failures of the  underlying time synchronization protocol. In addition, we perform a  detailed study of the sensor network's data using a direct comparison  to a standalone data logger, as well as an investigation of seismic  and acoustic wave arrival times across the network.  &lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36203843-116234246178511496?l=osdi2006.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osdi2006.blogspot.com/feeds/116234246178511496/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36203843&amp;postID=116234246178511496' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234246178511496'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36203843/posts/default/116234246178511496'/><link rel='alternate' type='text/html' href='http://osdi2006.blogspot.com/2006/10/paper-fidelity-and-yield-in-volcano.html' title='Paper: &quot;Fidelity and Yield in a Volcano Monitoring Sensor Network&quot;'/><author><name>Jeff Mogul</name><uri>http://www.blogger.com/profile/16378179987714048015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry></feed>
