- 153
- 8 768
Mass Open Cloud
เข้าร่วมเมื่อ 14 ก.พ. 2019
Building Secure and Trustworthy Operating Systems presented by Vasileios (Vasilis) Kemerlis
Talk Title: Building Secure and Trustworthy Operating Systems
Speaker: Vasileios (Vasilis) Kemerlis, Associate Professor, Brown University
Abstract:
Modern operating systems consist of large, monolithic blobs of complex code, and are plagued with vulnerabilities that allow perpetrators to exploit them for profit. This, coupled with the sophistication of modern adversaries, makes the need for effective and targeted defenses more critical than ever. In this talk, I will present our work on developing novel protection mechanisms and exploit prevention techniques that improve the security posture of commodity operating system kernels. In particular, I will discuss xMP and SafeSLAB, two projects whose goal is to harden contemporary OSes, against attacks that exploit memory safety vulnerabilities in kernel code, without using super-privileged software (for example, a hypervisor or VMM). In addition, I will talk about EPF and BeeBox: the former is a new kernel exploitation technique that we developed, which unveils how in-kernel runtime environments, like that of (e)BPF, can be abused to significantly weaken the effectiveness of deployed, state of-the-art kernel defenses (I will also briefly discuss how to mitigate EPF-style attacks); the latter is a new security architecture that hardens (e)BPF against transient execution attacks. Lastly, during the talk, I will delve into the evolution of kernel exploitation and explore the emerging challenges in building secure and trustworthy OSes.
Bio:
Vasileios (Vasilis) Kemerlis is an Associate Professor of Computer Science at Brown University. His research interests are in the areas of systems and software security, with a focus on OS kernel protection, automated software hardening, information-flow tracking, and hardware-assisted security. Many of Vasilis’ proposed systems and defensive techniques have been adopted by major vendors, like Intel, Microsoft, and Apple, or open source projects, such as the Linux kernel, Mozilla Firefox, and the Tor Browser. His work on kernel exploitation and defense won the first prize in the Applied Research competition, at the Cyber Security Awareness Week (CSAW) 2014 conference, and nominated for a Pwnie award in 2015. Lastly, Vasilis’ work on fuzz testing ML/DL frameworks for memory errors has helped the TensorFlow and PyTorch developers identify and fix many 0-day vulnerabilities, and was awarded with ~40 CVEs. Vasilis has also contributed to the design and implementation of Microsoft’s primary solution for automatically triaging crash dumps (RETracer), which is now part of the Windows Error Reporting (WER) platform. In the past, he was a member of the Solaris Core Kernel team at Oracle, where he worked on adding support for full Address Space Layout Randomization (ASLR) in the Solaris OS. Other professional accolades include the NSF CAREER Award, a Distinguished Paper Award in ACM ASIA CCS 2023, two service awards from ACM CCS (2023 and 2024; “Top/Distinguished Reviewer”), and a service award from DIMVA 2020 (“Outstanding Reviewer”). Vasilis holds a PhD (2015), MPhil (2013), and MS (2010) in Computer Science from Columbia University, and a BS (2006) in Computer Science from Athens University of Economics and Business.
Speaker: Vasileios (Vasilis) Kemerlis, Associate Professor, Brown University
Abstract:
Modern operating systems consist of large, monolithic blobs of complex code, and are plagued with vulnerabilities that allow perpetrators to exploit them for profit. This, coupled with the sophistication of modern adversaries, makes the need for effective and targeted defenses more critical than ever. In this talk, I will present our work on developing novel protection mechanisms and exploit prevention techniques that improve the security posture of commodity operating system kernels. In particular, I will discuss xMP and SafeSLAB, two projects whose goal is to harden contemporary OSes, against attacks that exploit memory safety vulnerabilities in kernel code, without using super-privileged software (for example, a hypervisor or VMM). In addition, I will talk about EPF and BeeBox: the former is a new kernel exploitation technique that we developed, which unveils how in-kernel runtime environments, like that of (e)BPF, can be abused to significantly weaken the effectiveness of deployed, state of-the-art kernel defenses (I will also briefly discuss how to mitigate EPF-style attacks); the latter is a new security architecture that hardens (e)BPF against transient execution attacks. Lastly, during the talk, I will delve into the evolution of kernel exploitation and explore the emerging challenges in building secure and trustworthy OSes.
Bio:
Vasileios (Vasilis) Kemerlis is an Associate Professor of Computer Science at Brown University. His research interests are in the areas of systems and software security, with a focus on OS kernel protection, automated software hardening, information-flow tracking, and hardware-assisted security. Many of Vasilis’ proposed systems and defensive techniques have been adopted by major vendors, like Intel, Microsoft, and Apple, or open source projects, such as the Linux kernel, Mozilla Firefox, and the Tor Browser. His work on kernel exploitation and defense won the first prize in the Applied Research competition, at the Cyber Security Awareness Week (CSAW) 2014 conference, and nominated for a Pwnie award in 2015. Lastly, Vasilis’ work on fuzz testing ML/DL frameworks for memory errors has helped the TensorFlow and PyTorch developers identify and fix many 0-day vulnerabilities, and was awarded with ~40 CVEs. Vasilis has also contributed to the design and implementation of Microsoft’s primary solution for automatically triaging crash dumps (RETracer), which is now part of the Windows Error Reporting (WER) platform. In the past, he was a member of the Solaris Core Kernel team at Oracle, where he worked on adding support for full Address Space Layout Randomization (ASLR) in the Solaris OS. Other professional accolades include the NSF CAREER Award, a Distinguished Paper Award in ACM ASIA CCS 2023, two service awards from ACM CCS (2023 and 2024; “Top/Distinguished Reviewer”), and a service award from DIMVA 2020 (“Outstanding Reviewer”). Vasilis holds a PhD (2015), MPhil (2013), and MS (2010) in Computer Science from Columbia University, and a BS (2006) in Computer Science from Athens University of Economics and Business.
มุมมอง: 16
วีดีโอ
Integrating D4N with K8s presented by Austin Jamais
มุมมอง 1919 ชั่วโมงที่ผ่านมา
Talk Title: Integrating D4N with K8s Speaker: Austin Jamais
Distributed PIR: Scaling Private Messaging via the Users’ Machines presented by Yossi Gilad
มุมมอง 1019 ชั่วโมงที่ผ่านมา
Talk Title: Distributed PIR: Scaling Private Messaging via the Users’ Machines Speaker: Yossi Gilad, Associate Professor, Hebrew University of Jerusalem, Israel Abstract: This work presents a new architecture for metadata-private messaging that counters scalability challenges by offloading most computations to the clients. At the core of our design is a distributed private information retrieval...
Unikernal Linux Dynamic Linkage presented by Ross Mikulskis & Vance Raiti
มุมมอง 3919 ชั่วโมงที่ผ่านมา
Talk Title: Unikernal Linux Dynamic Linkage Speakers: Ross Mikulskis & Vance Raiti
Phase-Driven Resource Management presented by Yann Arif
มุมมอง 819 ชั่วโมงที่ผ่านมา
Talk Title: Phase-Driven Resource Management Speaker: Yann Arif
AI-based Telemetry Analysis and Root Cause Inference with PraxiPaaS Student Presentation
มุมมอง 1919 ชั่วโมงที่ผ่านมา
Talk Title: AI-based Telemetry Analysis and Root Cause Inference with PraxiPaaS Speakers: Rohan Kumar & Jason Li
FRAMESHIFTER-Security Implications of HTTP/2-to-HTTP/1 Conversion Anomalies presented by Engin Kirda
มุมมอง 2519 ชั่วโมงที่ผ่านมา
Talk Title: FRAMESHIFTER-Security Implications of HTTP/2-to-HTTP/1 Conversion Anomalies Speaker: Engin Kirda, Professor of Computer Science at Northeastern University Abstract: HTTP/2 adoption is rapidly climbing. However, in practice, Internet communications still rarely happen over end-to-end HTTP/2 channels. This is due to Content Delivery Networks and other reverse proxies, ubiquitous and n...
Empirical Study on Scams and Attacks on Social Media Platforms presented by Dr. Bhupendra Acharya
มุมมอง 1619 ชั่วโมงที่ผ่านมา
Talk Title: Empirical Study on Scams and Attacks on Social Media Platforms Speaker: Dr. Bhupendra Acharya, Postdoctoral Researcher, CISPA Helmholtz Center for Information Security Abstract: With the ubiquitous of social media, fraudsters use this as an opportunity to trick users through fake profiles performing various social engineering techniques. These attacks cause millions of dollars of fi...
BU Computer Systems Seminar: Denis Hoornaert
มุมมอง 378 หลายเดือนก่อน
Thursday, April 4, 2024 Talk Title: "On-the-fly Reorganization of High-Order Data Objects to Achieve Effortless Locality" Speaker: Denis Hoornaert, Ph.D. Candidate, Technical University of Munich Abstract: The shift to data-intensive processing from the cloud to the edge has brought new challenges and expectations for the next generation of intelligent computing systems. However, a substantial ...
Discussion Groups Report Out
มุมมอง 139 หลายเดือนก่อน
Thursday, February 29, 2024 2024 MOC Alliance Workshop Session 4-Operations and Discussions Discussion Group Report Out
Jonathan Appavoo & Danni Shi-OPE and Education on NERC
มุมมอง 369 หลายเดือนก่อน
Thursday, February 29, 2024 2024 MOC Alliance Workshop Session 4-Operations and Discussions Speakers: Jonathan Appavoo, Associate Professor, Boston University, and Danni Shi, Senior Software Engineer, Red Hat Talk Title: OPE and Education on NERC Talk Abstract: OPE leverages modern open source technologies to create an open environment and platform in which educators can create, publish, and op...
Heidi Dempsey & Mike Zink-Back to the Future Systems Research
มุมมอง 359 หลายเดือนก่อน
Thursday, February 29, 2024 2024 MOC Alliance Workshop Session 4-Operations and Discussions Speakers: Heidi Dempsey, Research Director, US, Red Hat Research, and Mike Zink, Professor, UMass Amherst Talk Title: Back to the Future Systems Research Talk Abstract: Ongoing systems experiments, development and systems research topics for 2024. We’ll touch on testbed federation, connections to large d...
Milson Munakami & Christopher Simmons-Fostering Cloud Adoption Using a Community Driven Approach
มุมมอง 119 หลายเดือนก่อน
Thursday, February 29, 2024 2024 MOC Alliance Workshop Session 4-Operations and Discussions Speakers: Christopher Simmons, Deputy Executive Director, MGHPCC, and Milson Munakami, Lead Cloud Engineer, Harvard University Talk Title: Fostering Cloud Adoption Using a Community-Driven Approach Talk Abstract: In this talk, we will summarize our current user outreach strategy and propose several commu...
John Goodhue & Jon Stumpf-Governance and Partnerships
มุมมอง 209 หลายเดือนก่อน
Thursday, February 29, 2024 2024 MOC Alliance Workshop Session 4-Operations and Discussions Speakers: John Goodhue, Executive Director, MGHPCC, and Jon Stumpf, Strategic Coordinator, MOC Alliance Talk Title: Governance and Partnerships Talk Abstract: We are interested in discussing opportunities to improve efficiency and responsiveness in how the MOC Alliance engages with current and prospectiv...
Chistopher Simmons-Getting Started with the Open Storage Network
มุมมอง 489 หลายเดือนก่อน
Thursday, February 29, 2024 2024 MOC Alliance Workshop Session 3-Open Cloud Speaker: Christopher Simmons, Deputy Executive Director, MGHPCC Talk Title: Getting Started with the Open Storage Network Talk Abstract: The Open Storage Network (OSN), funded by the NSF, the Schmidt Futures Foundation and Dalio Philanthropies, developed a storage platform to support scientific and scholarly production ...
Peter Desnoyers & Isaac Khor-Gateway LSVD: Disaggregated Storage for an Open Cloud
มุมมอง 399 หลายเดือนก่อน
Peter Desnoyers & Isaac Khor-Gateway LSVD: Disaggregated Storage for an Open Cloud
Naved Ansari, Tzu Mainn Chen, and Hakan Saplakoglu-ESI: Details, Status, and Switch Management Tool
มุมมอง 189 หลายเดือนก่อน
Naved Ansari, Tzu Mainn Chen, and Hakan Saplakoglu-ESI: Details, Status, and Switch Management Tool
Adam Belay-Transforming Production Cloud Workloads into Realistic System Benchmarks
มุมมอง 1629 หลายเดือนก่อน
Adam Belay-Transforming Production Cloud Workloads into Realistic System Benchmarks
Kristi Nikolla-Building the Services Powering the Open Cloud
มุมมอง 179 หลายเดือนก่อน
Kristi Nikolla-Building the Services Powering the Open Cloud
Mark Roth-Memento: Why Good Artifact Naming Matters
มุมมอง 1979 หลายเดือนก่อน
Mark Roth-Memento: Why Good Artifact Naming Matters
Matt Benjamin & Amin Mosayyebzadeh-D4N: A Community Cache for an Open Cloud
มุมมอง 529 หลายเดือนก่อน
Matt Benjamin & Amin Mosayyebzadeh-D4N: A Community Cache for an Open Cloud
Rory Macneil-The Norwegian Research Commons: A Model for NERC?
มุมมอง 379 หลายเดือนก่อน
Rory Macneil-The Norwegian Research Commons: A Model for NERC?
Ellen Grant & Rudolph Pienaar-AI for Medicine and Radiology on NERC
มุมมอง 369 หลายเดือนก่อน
Ellen Grant & Rudolph Pienaar-AI for Medicine and Radiology on NERC
Stefano Iacus-Bringing the Data Close to the Compute at Harvard Dataverse
มุมมอง 689 หลายเดือนก่อน
Stefano Iacus-Bringing the Data Close to the Compute at Harvard Dataverse
Wayne Gilmore & Emre Keskin-The Building Blocks of Cloud: Research Enablement
มุมมอง 549 หลายเดือนก่อน
Wayne Gilmore & Emre Keskin-The Building Blocks of Cloud: Research Enablement
Larry Rudolph-The Benefits of Sharing and Collaboration in the MOC
มุมมอง 439 หลายเดือนก่อน
Larry Rudolph-The Benefits of Sharing and Collaboration in the MOC
David Palaitis-Fourth Generation Compute @ Two Sigma
มุมมอง 2459 หลายเดือนก่อน
David Palaitis-Fourth Generation Compute @ Two Sigma
Eshed Ohn Bar-Scaling Systems with Everyone, Everywhere, All the Time: The Co Ops Project
มุมมอง 499 หลายเดือนก่อน
Eshed Ohn Bar-Scaling Systems with Everyone, Everywhere, All the Time: The Co Ops Project
Interesting to see companies reinvent the wheel by building technology categories. Perhaps there are specific and unique business needs that demand this, but I wonder if this is restricting data users on how they can get or use data, even the solution seems very technical. I see many companies leaning closer to Enterprise Data Governance and Catalog to provide data lineage and interactive business context, even for Python Notebook users. Databricks has done interesting work in this space, but it is interesting to see a company fund the development of free, open-source code.
P R O M O S M
See you soon
How’s it going?! Enjoying the uploads. Have you thought about using FollowSM . c o m to help grow your channel?
Vah, nice, very good and God bless you