Operating Systems
OS design, scheduling, virtualization, and systems software
20 papers indexed
Pomegranate: A Lightweight Compartmentalization Architecture using Virtualization Extensions
Pomegranate is a novel framework that uses hardware-assisted virtualization and Extended Page Tables to securely compartmentalize existing operating systems with minimal source code modification, enab…
Multi-target Coverage-based Greybox Fuzzing
The paper proposes MTCFuzz, a multi-target coverage-based greybox fuzzer, to deeply explore vulnerabilities in modern system architectures where an operating system and firmware cooperate.
Agent libOS: A Library-OS-Inspired Runtime for Long-Running, Capability-Controlled LLM Agents
Agent libOS introduces a library-OS-inspired runtime substrate that treats LLM agents as schedulable processes, providing explicit capability control and robust auditing for long-running, stateful age…
CTF as a Service: A reproducible and scalable infrastructure for cybersecurity training
This paper introduces and evaluates a scalable, reproducible 'CTF as a Service' (CaaS) platform designed to simplify the infrastructure management required for cybersecurity training.
Formal Verification of Secure Encrypted Virtualization
This paper introduces a formal framework to rigorously verify the security guarantees (confidentiality, integrity, and availability) of AMD SEV confidential virtual machines.
Formal Verification of Secure Encrypted Virtualization
This paper introduces a formal framework to rigorously verify the security guarantees (confidentiality, integrity, and availability) of AMD SEV confidential virtual machines.
A UEFI System with SPDM to Protect Against Unauthorized Device Connections
The paper proposes a UEFI system utilizing SPDM to authenticate connected PCIe and USB devices, successfully demonstrating that this enhanced security mechanism introduces an acceptable processing ove…
Kumo: A Security-Focused Serverless Cloud Simulator
Wei Shao, Khaled Khasawneh, Setareh Rafatirad, Houman Homayoun +1 more
The paper introduces Kumo, a novel security-focused simulator that enables controlled analysis of resource sharing and scheduling risks in serverless cloud environments, demonstrating that scheduler c…
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization
Zonghao Ying, Haozheng Wang, Jiangfan Liu, Quanchen Zou +4 more
AgentVisor is a novel defense framework that uses semantic virtualization, inspired by OS principles, to significantly reduce LLM agent vulnerability to prompt injection while maintaining high utility…
unix-ctf: Procedural Environments for Unix-Competence Reinforcement Learning
The paper introduces unix-ctf, a procedural generator for capture-the-flag tasks, demonstrating that Unix competence is a separable and trainable skill distinct from general programming ability.
unix-ctf: Procedural Environments for Unix-Competence Reinforcement Learning
The paper introduces unix-ctf, a procedural generator for capture-the-flag tasks, demonstrating that Unix competence is a separable and trainable skill distinct from general programming ability.
Cross-IP Request Coalescing: Relocating the Fan-out Point in Virtualized I/O
This paper proposes cross-IP request coalescing to reduce latency in virtualized cloud data centers by submitting multi-device I/O as a single compound request.
Speed Kills: Exploring Confused Deputy Attacks Through Edge AI Accelerators
This paper investigates Confused Deputy Attacks (CDAs) on AI Accelerators (AIAs) and finds that CDA is feasible on most major vendor AIAs, impacting a vast number of devices.
Isolation Failure From Shared Storage: Characterizing and Exploiting Page-Cache SCA Leakage Across Containers and VMs
This paper investigates the persistence of a timing side channel through the shared page cache in modern cloud platforms with various isolation mechanisms.
A Sustainable Remote Access Architecture for Digital Inclusion through the Reuse of Discredited TV-BOX Devices
Italo Thiago Felix dos Santos, Carlos Eduardo Correa Queiroz, Adevan Neves Santos, Edgard Luciano Oliveira da Silva
This paper presents a sustainable, low-cost Desktop Virtualization Infrastructure using discarded electronic equipment for digital education.
KernelScript: Cross-Boundary Typed DSL for eBPF Applications
The paper introduces KernelScript, a DSL for eBPF that types maps, program handles, and execution domains to unify cross-boundary relationships, prevent bugs at compile time, and reduce diff size.
Agentic AI and the Industrialization of Cyber Offense: Forecast, Consequences, and Defensive Priorities for Enterprises and the Mittelstand
The paper forecasts that agentic AI will compress the cyber attack lifecycle by lowering the cost of multiple attack stages, necessitating immediate operational security upgrades for enterprises and t…
A Core-Structure-Based Automated Analysis Tool for Commercial Virtualization Obfuscation Deobfuscation
The paper introduces VMPredator, an automated tool that analyzes and deobfuscates virtualization obfuscation in malware by extracting semantic units, successfully restoring program functionality with…
Agent Operating Systems (AOS): Integrating Agentic Control Planes into, and Beyond, Traditional Operating Systems
The paper proposes the concept of an Agent Operating System (AOS) to provide a rigorous, controllable, and accountable systems foundation for running complex, probabilistic, and goal-directed AI agent…
Agent Operating Systems (AOS): Integrating Agentic Control Planes into, and Beyond, Traditional Operating Systems
The paper proposes the concept of an Agent Operating System (AOS) to provide a necessary systems foundation for managing the unique, non-deterministic, and goal-directed execution characteristics of m…