{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,26]],"date-time":"2026-03-26T14:01:13Z","timestamp":1774533673526,"version":"3.50.1"},"reference-count":71,"publisher":"Association for Computing Machinery (ACM)","issue":"4","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Program. Lang. Syst."],"published-print":{"date-parts":[[2005,7]]},"abstract":"<jats:p>\n            Single-language runtime systems, in the form of Java virtual machines, are widely deployed platforms for executing untrusted mobile code. These runtimes provide some of the features that operating systems provide: interapplication memory protection and basic system services. They do not, however, provide the ability to isolate applications from each other. Neither do they provide the ability to limit the resource consumption of applications. Consequently, the performance of current systems degrades severely in the presence of malicious or buggy code that exhibits ill-behaved resource usage. We show that Java runtime systems can be extended to support\n            <jats:italic>processes<\/jats:italic>\n            , and that processes can provide robust and efficient support for untrusted applications.We have designed and built KaffeOS, a Java runtime system that provides support for processes. KaffeOS isolates processes and manages the physical resources available to them: CPU and memory. Unlike existing Java virtual machines, KaffeOS can safely terminate processes without adversely affecting the integrity of the system, and it can fully reclaim a terminated process's resources. Finally, KaffeOS requires no changes to the Java language. The novel aspects of the KaffeOS architecture include the application of a user\/kernel boundary as a structuring principle for runtime systems, the employment of garbage collection techniques for resource management and isolation, and a model for direct sharing of objects between untrusted applications. The difficulty in designing KaffeOS lay in balancing the goals of isolation and resource management against the goal of allowing direct sharing of objects.For the SpecJVM benchmarks, the overhead that our KaffeOS prototype incurs ranges from 0% to 25%, when compared to the open-source JVM on which it is based. We consider this overhead acceptable for the safety that KaffeOS provides. In addition, our KaffeOS prototype can scale to run more applications than running multiple JVMs. Finally, in the presence of malicious or buggy code that engages in a denial-of-service attack, KaffeOS can contain the attack, remove resources from the attacked applications, and continue to provide robust service to other clients.\n          <\/jats:p>","DOI":"10.1145\/1075382.1075383","type":"journal-article","created":{"date-parts":[[2005,8,3]],"date-time":"2005-08-03T08:30:55Z","timestamp":1123057855000},"page":"583-630","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":33,"title":["The KaffeOS Java runtime system"],"prefix":"10.1145","volume":"27","author":[{"given":"Godmar","family":"Back","sequence":"first","affiliation":[{"name":"Virginia Polytechnic Institute and State University, Blacksburg, VA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wilson C.","family":"Hsieh","sequence":"additional","affiliation":[{"name":"Google, Inc., Mountain View, CA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2005,7]]},"reference":[{"key":"e_1_2_1_2_1","volume-title":"Proceedings of the SIGPLAN '98 Conference on Programming Language Design and Implementation (Montreal, Ont., Canada). ACM","author":"Bacon D. F.","unstructured":"Bacon , D. F. , Konuru , R. , Murthy , C. , and Serrano , M . 1998. Thin locks: Featherweight synchronization for Java . In Proceedings of the SIGPLAN '98 Conference on Programming Language Design and Implementation (Montreal, Ont., Canada). ACM , New York, 258--268.]] 10.1145\/277650.277734 Bacon, D. F., Konuru, R., Murthy, C., and Serrano, M. 1998. Thin locks: Featherweight synchronization for Java. In Proceedings of the SIGPLAN '98 Conference on Programming Language Design and Implementation (Montreal, Ont., Canada). ACM, New York, 258--268.]] 10.1145\/277650.277734"},{"key":"e_1_2_1_3_1","volume-title":"Proceedings of the 18th International Conference on Distributed Computing Systems","author":"Balfanz D.","unstructured":"Balfanz , D. and Gong , L . 1998. Experience with secure multi-processing in Java . In Proceedings of the 18th International Conference on Distributed Computing Systems ( Amsterdam, The Netherlands). 398--405.]] Balfanz, D. and Gong, L. 1998. Experience with secure multi-processing in Java. In Proceedings of the 18th International Conference on Distributed Computing Systems (Amsterdam, The Netherlands). 398--405.]]"},{"key":"e_1_2_1_4_1","volume-title":"Proceedings of the 9th International Conference on Architectural Support for Programming Languages and Operating Systems","author":"Berger E. D.","unstructured":"Berger , E. D. , McKinley , K. S. , Blumofe , R. D. , and Wilson , P. R . 2000. Hoard: A scalable memory allocator for multithreaded applications . In Proceedings of the 9th International Conference on Architectural Support for Programming Languages and Operating Systems ( Cambridge, Mass.). ACM, New York, 117--128.]] 10.1145\/378993.379232 Berger, E. D., McKinley, K. S., Blumofe, R. D., and Wilson, P. R. 2000. Hoard: A scalable memory allocator for multithreaded applications. In Proceedings of the 9th International Conference on Architectural Support for Programming Languages and Operating Systems (Cambridge, Mass.). ACM, New York, 117--128.]] 10.1145\/378993.379232"},{"key":"e_1_2_1_5_1","volume-title":"JavaServer Pages","author":"Bergsten H.","unstructured":"Bergsten , H. 2000. JavaServer Pages , First ed. O'Reilly & Associates, Inc. , Sebastopol, Calif .]] Bergsten, H. 2000. JavaServer Pages, First ed. O'Reilly & Associates, Inc., Sebastopol, Calif.]]"},{"key":"e_1_2_1_6_1","volume-title":"Proceedings of the IEEE Workshop on Programming Languages for Real-Time Industrial Applications","author":"Bernadat P.","unstructured":"Bernadat , P. , Lambright , D. , and Travostino , F . 1998. Towards a resource-safe Java for service guarantees in uncooperative environments . In Proceedings of the IEEE Workshop on Programming Languages for Real-Time Industrial Applications ( Madrid, Spain). IEEE Computer Society Press, Los Alamitos, Calif., 101--111.]] Bernadat, P., Lambright, D., and Travostino, F. 1998. Towards a resource-safe Java for service guarantees in uncooperative environments. In Proceedings of the IEEE Workshop on Programming Languages for Real-Time Industrial Applications (Madrid, Spain). IEEE Computer Society Press, Los Alamitos, Calif., 101--111.]]"},{"key":"e_1_2_1_7_1","volume-title":"Proceedings of the 5th Workshop on Hot Topics in Operating Systems (Orcas Island, Wash.). 62--65","author":"Bershad B.","unstructured":"Bershad , B. , Savage , S. , Pardyak , P. , Becker , D. , Fiuczynski , M. , and Sirer , E . 1995a. Protection is a software issue . In Proceedings of the 5th Workshop on Hot Topics in Operating Systems (Orcas Island, Wash.). 62--65 .]] Bershad, B., Savage, S., Pardyak, P., Becker, D., Fiuczynski, M., and Sirer, E. 1995a. Protection is a software issue. In Proceedings of the 5th Workshop on Hot Topics in Operating Systems (Orcas Island, Wash.). 62--65.]]"},{"key":"e_1_2_1_8_1","volume-title":"Proceedings of the 15th Symposium on Operating Systems Principles (Copper Mountain, Col.). 267--284","author":"Bershad B.","unstructured":"Bershad , B. , Savage , S. , Pardyak , P. , Sirer , E. , Fiuczynski , M. , Becker , D. , Eggers , S. , and Chambers , C . 1995b. Extensibility, safety and performance in the spin operating system . In Proceedings of the 15th Symposium on Operating Systems Principles (Copper Mountain, Col.). 267--284 .]] 10.1145\/224056.224077 Bershad, B., Savage, S., Pardyak, P., Sirer, E., Fiuczynski, M., Becker, D., Eggers, S., and Chambers, C. 1995b. Extensibility, safety and performance in the spin operating system. In Proceedings of the 15th Symposium on Operating Systems Principles (Copper Mountain, Col.). 267--284.]] 10.1145\/224056.224077"},{"key":"e_1_2_1_9_1","volume-title":"Proceedings of the ACM Conference on Object-Oriented Programming Systems, Languages, and Applications (OOPSLA '01)","author":"Blackburn S. M.","unstructured":"Blackburn , S. M. , Singhai , S. , Hertz , M. , McKinley , K. S. , and Moss , J. E. B. 2001. Pretenuring for Java . In Proceedings of the ACM Conference on Object-Oriented Programming Systems, Languages, and Applications (OOPSLA '01) (Tampa Bay, Fla.). ACM, New York, 342--352.]] 10.1145\/504282.504307 Blackburn, S. M., Singhai, S., Hertz, M., McKinley, K. S., and Moss, J. E. B. 2001. Pretenuring for Java. In Proceedings of the ACM Conference on Object-Oriented Programming Systems, Languages, and Applications (OOPSLA '01) (Tampa Bay, Fla.). ACM, New York, 342--352.]] 10.1145\/504282.504307"},{"key":"e_1_2_1_10_1","doi-asserted-by":"crossref","unstructured":"Bollella G. Gosling J. Brosgol B. Dibble P. Furr S. and Turnbull M. 2000. The Real-Time Specification for Java First ed. The Java Series. Addison-Wesley Reading Mass.]]   Bollella G. Gosling J. Brosgol B. Dibble P. Furr S. and Turnbull M. 2000. The Real-Time Specification for Java First ed. The Java Series. Addison-Wesley Reading Mass.]]","DOI":"10.1109\/2.846318"},{"key":"e_1_2_1_11_1","unstructured":"Chan P. Lee R. and Kramer D. 1998. The Java Class Libraries: Volume 1 Second ed. The Java Series. Addison-Wesley Reading Mass.]]   Chan P. Lee R. and Kramer D. 1998. The Java Class Libraries: Volume 1 Second ed. The Java Series. Addison-Wesley Reading Mass.]]"},{"key":"e_1_2_1_13_1","volume-title":"Proceedings of the 9th ACM Conference on Computer and Communications Security (Washington, D.C.). ACM","author":"Chen H.","unstructured":"Chen , H. and Wagner , D . 2002. MOPS: An infrastructure for examining security properties of software . In Proceedings of the 9th ACM Conference on Computer and Communications Security (Washington, D.C.). ACM , New York, 235--244.]] 10.1145\/586110.586142 Chen, H. and Wagner, D. 2002. MOPS: An infrastructure for examining security properties of software. In Proceedings of the 9th ACM Conference on Computer and Communications Security (Washington, D.C.). ACM, New York, 235--244.]] 10.1145\/586110.586142"},{"key":"e_1_2_1_14_1","volume-title":"Proceedings of the SIGPLAN '98 Conference on Programming Language Design and Implementation (Montreal, Ont., Canada). ACM","author":"Cheng P.","unstructured":"Cheng , P. , Harper , R. , and Lee , P . 1998. Generational stack collection and profile-driven pretenuring . In Proceedings of the SIGPLAN '98 Conference on Programming Language Design and Implementation (Montreal, Ont., Canada). ACM , New York, 162--173.]] 10.1145\/277650.277718 Cheng, P., Harper, R., and Lee, P. 1998. Generational stack collection and profile-driven pretenuring. In Proceedings of the SIGPLAN '98 Conference on Programming Language Design and Implementation (Montreal, Ont., Canada). ACM, New York, 162--173.]] 10.1145\/277650.277718"},{"key":"e_1_2_1_15_1","volume-title":"Proceedings of the ACM Conference on Object-Oriented Programming Systems, Languages, and Applications (OOPSLA '00)","author":"Czajkowski G.","year":"2000","unstructured":"Czajkowski , G. 2000 . Application isolation in the Java virtual machine . In Proceedings of the ACM Conference on Object-Oriented Programming Systems, Languages, and Applications (OOPSLA '00) (Minneapolis, Minn.). ACM, New York, 354--366.]] 10.1145\/353171.353195 Czajkowski, G. 2000. Application isolation in the Java virtual machine. In Proceedings of the ACM Conference on Object-Oriented Programming Systems, Languages, and Applications (OOPSLA '00) (Minneapolis, Minn.). ACM, New York, 354--366.]] 10.1145\/353171.353195"},{"key":"e_1_2_1_16_1","volume-title":"Proceedings of the 8th ACM SIGOPS European Workshop","author":"Czajkowski G.","year":"1998","unstructured":"Czajkowski , G. , Chang , C.-C. , Hawblitzel , C. , Hu , D. , and von Eicken , T. 1998 . Resource management for extensible Internet servers . In Proceedings of the 8th ACM SIGOPS European Workshop ( Sintra, Portugal). ACM, New York, 33--39.]] 10.1145\/3 19195.319201 Czajkowski, G., Chang, C.-C., Hawblitzel, C., Hu, D., and von Eicken, T. 1998. Resource management for extensible Internet servers. In Proceedings of the 8th ACM SIGOPS European Workshop (Sintra, Portugal). ACM, New York, 33--39.]] 10.1145\/319195.319201"},{"key":"e_1_2_1_17_1","volume-title":"Proceedings of the ACM Conference on Object-Oriented Programming Systems, Languages, and Applications (OOPSLA '01)","author":"Czajkowski G.","unstructured":"Czajkowski , G. and Dayn\u00e9s , L . 2001. Multitasking without compromise: A virtual machine evolution . In Proceedings of the ACM Conference on Object-Oriented Programming Systems, Languages, and Applications (OOPSLA '01) (Tampa Bay, Fla.). ACM, New York, 125--138.]] 10.1145\/504282.504292 Czajkowski, G. and Dayn\u00e9s, L. 2001. Multitasking without compromise: A virtual machine evolution. In Proceedings of the ACM Conference on Object-Oriented Programming Systems, Languages, and Applications (OOPSLA '01) (Tampa Bay, Fla.). ACM, New York, 125--138.]] 10.1145\/504282.504292"},{"key":"e_1_2_1_18_1","volume-title":"Proceedings of the ACM Conference on Object-Oriented Programming Systems, Languages, and Applications (OOPSLA '98)","author":"Czajkowski G.","unstructured":"Czajkowski , G. and von Eicken, T. 1998. JRes: A resource accounting interface for Java . In Proceedings of the ACM Conference on Object-Oriented Programming Systems, Languages, and Applications (OOPSLA '98) (Vancouver, B.C. Canada). ACM, New York, 21--35.]] 10.1145\/286936.286944 Czajkowski, G. and von Eicken, T. 1998. JRes: A resource accounting interface for Java. In Proceedings of the ACM Conference on Object-Oriented Programming Systems, Languages, and Applications (OOPSLA '98) (Vancouver, B.C. Canada). ACM, New York, 21--35.]] 10.1145\/286936.286944"},{"key":"e_1_2_1_19_1","volume-title":"Proceedings of the 4th ACM Conference on Computer and Communications Security","author":"Dean D.","year":"1997","unstructured":"Dean , D. 1997 . The security of static typing with dynamic linking . In Proceedings of the 4th ACM Conference on Computer and Communications Security ( Zurich, Switzerland). ACM, New York, 18--27.]] 10.1145\/266420.266428 Dean, D. 1997. The security of static typing with dynamic linking. In Proceedings of the 4th ACM Conference on Computer and Communications Security (Zurich, Switzerland). ACM, New York, 18--27.]] 10.1145\/266420.266428"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1147\/sj.391.0194"},{"key":"e_1_2_1_21_1","volume-title":"Proceedings of the 3rd International Symposium on Memory Management","author":"Domani T.","unstructured":"Domani , T. , Goldshtein , G. , Kolodner , E. K. , Lewis , E. , Petrank , E. , and Sheinwald , D . 2002. Thread-local heaps for Java . In Proceedings of the 3rd International Symposium on Memory Management ( Berlin, Germany). ACM, New York, 183--194.]] 10.1145\/512429.512439 Domani, T., Goldshtein, G., Kolodner, E. K., Lewis, E., Petrank, E., and Sheinwald, D. 2002. Thread-local heaps for Java. In Proceedings of the 3rd International Symposium on Memory Management (Berlin, Germany). ACM, New York, 183--194.]] 10.1145\/512429.512439"},{"key":"e_1_2_1_22_1","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1002\/bltj.2028","article-title":"The Inferno operating system","volume":"2","author":"Dorward S.","year":"1997","unstructured":"Dorward , S. , Pike , R. , Presotto , D. L. , Ritchie , D. M. , Trickey , H. , and Winterbottom , P. 1997 . The Inferno operating system . Bell Labs Tech. J. 2 , 1, 5 -- 18 .]] Dorward, S., Pike, R., Presotto, D. L., Ritchie, D. M., Trickey, H., and Winterbottom, P. 1997. The Inferno operating system. Bell Labs Tech. J. 2, 1, 5--18.]]","journal-title":"Bell Labs Tech. J."},{"key":"e_1_2_1_23_1","volume-title":"Proceedings of the 4th Symposium on Operating Systems Design and Implementation","author":"Engler D.","unstructured":"Engler , D. , Chelf , B. , Chou , A. , and Hallem , S . 2000. Checking system rules using system-specific, programmer-written compiler extensions . In Proceedings of the 4th Symposium on Operating Systems Design and Implementation ( San Diego, Calif.). USENIX Association, 1-- 16.]] Engler, D., Chelf, B., Chou, A., and Hallem, S. 2000. Checking system rules using system-specific, programmer-written compiler extensions. In Proceedings of the 4th Symposium on Operating Systems Design and Implementation (San Diego, Calif.). USENIX Association, 1-- 16.]]"},{"key":"e_1_2_1_24_1","volume-title":"Proceedings of the 15th Symposium on Operating Systems Principles (Copper Mountain, Col.). 251--266","author":"Engler D. R.","year":"1995","unstructured":"Engler , D. R. , Kaashoek , M. F. , and O'Toole Jr ., J. 1995 . Exokernel: An operating system architecture for application-level resource management . In Proceedings of the 15th Symposium on Operating Systems Principles (Copper Mountain, Col.). 251--266 .]] 10.1145\/224056.224076 Engler, D. R., Kaashoek, M. F., and O'Toole Jr., J. 1995. Exokernel: An operating system architecture for application-level resource management. In Proceedings of the 15th Symposium on Operating Systems Principles (Copper Mountain, Col.). 251--266.]] 10.1145\/224056.224076"},{"key":"e_1_2_1_25_1","volume-title":"Proceedings of the SIGPLAN '04 Conference on Programming Language Design and Implementation (Washington, D.C.). ACM","author":"Flatt M.","unstructured":"Flatt , M. and Findler , R . 2004. Kill-safe synchronization abstractions . In Proceedings of the SIGPLAN '04 Conference on Programming Language Design and Implementation (Washington, D.C.). ACM , New York.]] 10.1145\/996841.996849 Flatt, M. and Findler, R. 2004. Kill-safe synchronization abstractions. In Proceedings of the SIGPLAN '04 Conference on Programming Language Design and Implementation (Washington, D.C.). ACM, New York.]] 10.1145\/996841.996849"},{"key":"e_1_2_1_26_1","volume-title":"Microkernels meet recursive virtual machines. In Proceedings of the 2nd Symposium on Operating Systems Design and Implementation","author":"Ford B.","unstructured":"Ford , B. , Hibler , M. , Lepreau , J. , Tullmann , P. , Back , G. , and Clawson , S . 1996 . Microkernels meet recursive virtual machines. In Proceedings of the 2nd Symposium on Operating Systems Design and Implementation ( Seattle, Wash.). USENIX Association, 137--151.]] 10.1145\/238721.238769 Ford, B., Hibler, M., Lepreau, J., Tullmann, P., Back, G., and Clawson, S. 1996. Microkernels meet recursive virtual machines. In Proceedings of the 2nd Symposium on Operating Systems Design and Implementation (Seattle, Wash.). USENIX Association, 137--151.]] 10.1145\/238721.238769"},{"key":"e_1_2_1_27_1","volume-title":"Proceedings of WebNet '97, World Conference of the WWW, Internet, and Intranet, S. Lobodzinski and I. Tomek, Eds. Association for the Advancement of Computing in Education","author":"Franz M.","year":"1997","unstructured":"Franz , M. 1997 . Beyond Java: An infrastructure for high-performance mobile code on the World Wide Web . In Proceedings of WebNet '97, World Conference of the WWW, Internet, and Intranet, S. Lobodzinski and I. Tomek, Eds. Association for the Advancement of Computing in Education , Toronto, Ont., Canada, 33--38.]] Franz, M. 1997. Beyond Java: An infrastructure for high-performance mobile code on the World Wide Web. In Proceedings of WebNet '97, World Conference of the WWW, Internet, and Intranet, S. Lobodzinski and I. Tomek, Eds. Association for the Advancement of Computing in Education, Toronto, Ont., Canada, 33--38.]]"},{"key":"e_1_2_1_28_1","volume-title":"Proceedings of the SIGPLAN '98 Conference on Programming Language Design and Implementation (Montreal, Ont., Canada). ACM","author":"Gay D.","unstructured":"Gay , D. and Aiken , A . 1998. Memory management with explicit regions . In Proceedings of the SIGPLAN '98 Conference on Programming Language Design and Implementation (Montreal, Ont., Canada). ACM , New York, 313--323.]] 10.1145\/277650.277748 Gay, D. and Aiken, A. 1998. Memory management with explicit regions. In Proceedings of the SIGPLAN '98 Conference on Programming Language Design and Implementation (Montreal, Ont., Canada). ACM, New York, 313--323.]] 10.1145\/277650.277748"},{"key":"e_1_2_1_29_1","unstructured":"Gorrie L. 1998. Echidna---A free multiprocess system in Java. http:\/\/www.javagroup.org\/ echidna\/.]]  Gorrie L. 1998. Echidna---A free multiprocess system in Java. http:\/\/www.javagroup.org\/ echidna\/.]]"},{"key":"e_1_2_1_30_1","volume-title":"Proceedings of the 1998 USENIX Annual Technical Conference (New Orleans, La.). USENIX Association, 259--270","author":"Hawblitzel C.","year":"1998","unstructured":"Hawblitzel , C. , Chang , C.-C. , Czajkowski , G. , Hu , D. , and von Eicken , T. 1998 . Implementing multiple protection domains in Java . In Proceedings of the 1998 USENIX Annual Technical Conference (New Orleans, La.). USENIX Association, 259--270 .]] Hawblitzel, C., Chang, C.-C., Czajkowski, G., Hu, D., and von Eicken, T. 1998. Implementing multiple protection domains in Java. In Proceedings of the 1998 USENIX Annual Technical Conference (New Orleans, La.). USENIX Association, 259--270.]]"},{"key":"e_1_2_1_31_1","volume-title":"Proceedings of the 5th Symposium on Operating Systems Design and Implementation","author":"Hawblitzel C.","unstructured":"Hawblitzel , C. and von Eicken, T. 2002. Luna: A flexible java protection system . In Proceedings of the 5th Symposium on Operating Systems Design and Implementation ( Boston, Mass.).]] Hawblitzel, C. and von Eicken, T. 2002. Luna: A flexible java protection system. In Proceedings of the 5th Symposium on Operating Systems Design and Implementation (Boston, Mass.).]]"},{"key":"e_1_2_1_32_1","volume-title":"Proceedings of the 14th International Conference on Computer Aided Verification (CAV'02)","author":"Henzinger T.","unstructured":"Henzinger , T. , Jhala , R. , Majumdar , R. , Necula , G. , Sutre , G. , and Weimer , W . 2002. Temporal safety proofs for systems code . In Proceedings of the 14th International Conference on Computer Aided Verification (CAV'02) (Copenhagen, Denmark).]] Henzinger, T., Jhala, R., Majumdar, R., Necula, G., Sutre, G., and Weimer, W. 2002. Temporal safety proofs for systems code. In Proceedings of the 14th International Conference on Computer Aided Verification (CAV'02) (Copenhagen, Denmark).]]"},{"key":"e_1_2_1_33_1","volume-title":"Proceedings of the 7th USENIX Security Symposium (San Antonio, Tex.). USENIX Association, 143--157","author":"Jaeger T.","unstructured":"Jaeger , T. , Liedtke , J. , and Islam , N . 1998. Operating system protection for fine-grained programs . In Proceedings of the 7th USENIX Security Symposium (San Antonio, Tex.). USENIX Association, 143--157 .]] Jaeger, T., Liedtke, J., and Islam, N. 1998. Operating system protection for fine-grained programs. In Proceedings of the 7th USENIX Security Symposium (San Antonio, Tex.). USENIX Association, 143--157.]]"},{"key":"e_1_2_1_34_1","unstructured":"Java Apache Project. 2000. The Apache JServ project. http:\/\/java.apache.org\/jserv.]]  Java Apache Project. 2000. The Apache JServ project. http:\/\/java.apache.org\/jserv.]]"},{"key":"e_1_2_1_35_1","unstructured":"Java Community Process. 2003. Jsr 121. http:\/\/www.jcp.org\/en\/jsr\/detail?id=121.]]  Java Community Process. 2003. Jsr 121. http:\/\/www.jcp.org\/en\/jsr\/detail?id=121.]]"},{"key":"e_1_2_1_36_1","unstructured":"Joy B. Steele G. Gosling J. and Bracha G. 2000. The Java Language Specification Second ed. The Java Series. Addison-Wesley Reading Mass.]]   Joy B. Steele G. Gosling J. and Bracha G. 2000. The Java Language Specification Second ed. The Java Series. Addison-Wesley Reading Mass.]]"},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/35037.42182"},{"key":"e_1_2_1_38_1","volume-title":"Proceedings of the 3rd USENIX Mach Symposium (Santa Fe, N.M.). USENIX Association, 39--55","author":"Lepreau J.","unstructured":"Lepreau , J. , Hibler , M. , Ford , B. , and Law , J . 1993. In-kernel servers on Mach 3.0: Implementation and performance . In Proceedings of the 3rd USENIX Mach Symposium (Santa Fe, N.M.). USENIX Association, 39--55 .]] Lepreau, J., Hibler, M., Ford, B., and Law, J. 1993. In-kernel servers on Mach 3.0: Implementation and performance. In Proceedings of the 3rd USENIX Mach Symposium (Santa Fe, N.M.). USENIX Association, 39--55.]]"},{"key":"e_1_2_1_39_1","volume-title":"The Java Native Interface: Programmer's Guide and Specification","author":"Liang S.","unstructured":"Liang , S. 1999. The Java Native Interface: Programmer's Guide and Specification , First ed. The Java Series. Addison-Wesley , Reading, Mass.]] Liang, S. 1999. The Java Native Interface: Programmer's Guide and Specification, First ed. The Java Series. Addison-Wesley, Reading, Mass.]]"},{"key":"e_1_2_1_40_1","volume-title":"Proceedings of the ACM Conference on Object-Oriented Programming Systems, Languages, and Applications (OOPSLA '98)","author":"Liang S.","unstructured":"Liang , S. and Bracha , G . 1998. Dynamic class loading in the Java virtual machine . In Proceedings of the ACM Conference on Object-Oriented Programming Systems, Languages, and Applications (OOPSLA '98) (Vancouver, B.C., Canada). ACM, New York, 36--44.]] 10.1145\/286936.286945 Liang, S. and Bracha, G. 1998. Dynamic class loading in the Java virtual machine. In Proceedings of the ACM Conference on Object-Oriented Programming Systems, Languages, and Applications (OOPSLA '98) (Vancouver, B.C., Canada). ACM, New York, 36--44.]] 10.1145\/286936.286945"},{"key":"e_1_2_1_41_1","unstructured":"Lizt J. 1999. Oracle JServer Scalability and Performance. http:\/\/www.oracle.com\/ java\/scalability\/index.html?testresults_twp.html. Java Products Team Oracle Server Technologies.]]  Lizt J. 1999. Oracle JServer Scalability and Performance. http:\/\/www.oracle.com\/ java\/scalability\/index.html?testresults_twp.html. Java Products Team Oracle Server Technologies.]]"},{"key":"e_1_2_1_42_1","volume-title":"Proceedings of the 1998 IEEE Symposium on Security and Privacy (Oakland, Calif.). IEEE Computer Society Press, Los Alamitos, Calif., 40--51","author":"Malkhi D.","unstructured":"Malkhi , D. , Reiter , M. K. , and Rubin , A. D . 1998. Secure execution of Java applets using a remote playground . In Proceedings of the 1998 IEEE Symposium on Security and Privacy (Oakland, Calif.). IEEE Computer Society Press, Los Alamitos, Calif., 40--51 .]] Malkhi, D., Reiter, M. K., and Rubin, A. D. 1998. Secure execution of Java applets using a remote playground. In Proceedings of the 1998 IEEE Symposium on Security and Privacy (Oakland, Calif.). IEEE Computer Society Press, Los Alamitos, Calif., 40--51.]]"},{"key":"e_1_2_1_43_1","volume-title":"Proceedings of the Conference on Programming Language Design and Implementation (Snowbird, Ut.). ACM","author":"Marlow S.","unstructured":"Marlow , S. , Jones , S. P. , Moran , A. , and Reppy , J . 2001. Asynchronous exceptions in haskell . In Proceedings of the Conference on Programming Language Design and Implementation (Snowbird, Ut.). ACM , New York, 274--285.]] 10.1145\/378795.378858 Marlow, S., Jones, S. P., Moran, A., and Reppy, J. 2001. Asynchronous exceptions in haskell. In Proceedings of the Conference on Programming Language Design and Implementation (Snowbird, Ut.). ACM, New York, 274--285.]] 10.1145\/378795.378858"},{"key":"e_1_2_1_44_1","volume-title":"Java Security: Hostile Applets, Holes, and Antidotes","author":"McGraw G.","year":"1997","unstructured":"McGraw , G. and Felten , E . 1997 . Java Security: Hostile Applets, Holes, and Antidotes . Wiley Computer Publishing , New York .]] McGraw, G. and Felten, E. 1997. Java Security: Hostile Applets, Holes, and Antidotes. Wiley Computer Publishing, New York.]]"},{"key":"e_1_2_1_45_1","unstructured":"Microsoft Corporation. 2003. NET web pages. http:\/\/msdn.microsoft.com\/netframework\/.]]  Microsoft Corporation. 2003. NET web pages. http:\/\/msdn.microsoft.com\/netframework\/.]]"},{"key":"e_1_2_1_46_1","volume-title":"Proceedings of the International Workshop on Memory Management (IWMM95)","volume":"986","author":"Plainfoss\u00e9 D.","unstructured":"Plainfoss\u00e9 , D. and Shapiro , M . 1995. A survey of distributed garbage collection techniques . In Proceedings of the International Workshop on Memory Management (IWMM95) (Kinross, Scotland). Lecture Notes in Computer Science , vol. 986 . Springer-Verlag, New York, 211--249.]] Plainfoss\u00e9, D. and Shapiro, M. 1995. A survey of distributed garbage collection techniques. In Proceedings of the International Workshop on Memory Management (IWMM95) (Kinross, Scotland). Lecture Notes in Computer Science, vol. 986. Springer-Verlag, New York, 211--249.]]"},{"key":"e_1_2_1_47_1","volume-title":"Proceedings of 2003 IEEE Symposium on Security and Privacy (Oakland, Calif.). IEEE Computer Society Press, Los Alamitos, Calif., 263--274","author":"Price D. W.","unstructured":"Price , D. W. , Rudys , A. , and Wallach , D. S . 2003. Garbage collector memory accounting in language-based systems . In Proceedings of 2003 IEEE Symposium on Security and Privacy (Oakland, Calif.). IEEE Computer Society Press, Los Alamitos, Calif., 263--274 .]] Price, D. W., Rudys, A., and Wallach, D. S. 2003. Garbage collector memory accounting in language-based systems. In Proceedings of 2003 IEEE Symposium on Security and Privacy (Oakland, Calif.). IEEE Computer Society Press, Los Alamitos, Calif., 263--274.]]"},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/358818.358822"},{"key":"e_1_2_1_49_1","first-page":"6","article-title":"The UNIX time-sharing system","volume":"57","author":"Ritchie D. M.","year":"1978","unstructured":"Ritchie , D. M. and Thompson , K. 1978 . The UNIX time-sharing system . The Bell Syst. Tech. J. 57 , 6 (July\/Aug.), 1905--1930.]] Ritchie, D. M. and Thompson, K. 1978. The UNIX time-sharing system. The Bell Syst. Tech. J. 57, 6 (July\/Aug.), 1905--1930.]]","journal-title":"The Bell Syst. Tech. J."},{"key":"e_1_2_1_50_1","volume-title":"The MD5 message-digest algorithm. Internet Request for Comments RFC 1321","author":"Rivest R.","unstructured":"Rivest , R. 1992. The MD5 message-digest algorithm. Internet Request for Comments RFC 1321 , Internet Network Working Group . April.]] Rivest, R. 1992. The MD5 message-digest algorithm. Internet Request for Comments RFC 1321, Internet Network Working Group. April.]]"},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/505586.505589"},{"key":"e_1_2_1_53_1","unstructured":"Saraswat V. 1997. Java is not type-safe. http:\/\/matrix.research.att.com\/vj\/bug.html.]]  Saraswat V. 1997. Java is not type-safe. http:\/\/matrix.research.att.com\/vj\/bug.html.]]"},{"key":"e_1_2_1_54_1","unstructured":"Saulpaugh T. and Mirho C. A. 1999. Inside the JavaOS Operating System. The Java Series. Addison-Wesley Reading Mass.]]  Saulpaugh T. and Mirho C. A. 1999. Inside the JavaOS Operating System. The Java Series. Addison-Wesley Reading Mass.]]"},{"key":"e_1_2_1_55_1","volume-title":"Proceedings of the 2nd Symposium on Operating Systems Design and Implementation","author":"Seltzer M. I.","unstructured":"Seltzer , M. I. , Endo , Y. , Small , C. , and Smith , K. A . 1996. Dealing with disaster: Surviving misbehaved kernel extensions . In Proceedings of the 2nd Symposium on Operating Systems Design and Implementation ( Seattle, Wash.). USENIX Association, 213--227.]] 10.1145\/238721.238779 Seltzer, M. I., Endo, Y., Small, C., and Smith, K. A. 1996. Dealing with disaster: Surviving misbehaved kernel extensions. In Proceedings of the 2nd Symposium on Operating Systems Design and Implementation (Seattle, Wash.). USENIX Association, 213--227.]] 10.1145\/238721.238779"},{"key":"e_1_2_1_56_1","volume-title":"Proceedings of the 2003 IEEE Symposium on Security and Privacy (Oakland, Calif.). IEEE Computer Society Press, Los Alamitos, Calif., 251--262","author":"Shapiro J. S.","year":"2003","unstructured":"Shapiro , J. S. 2003 . Vulnerabilities in synchronous IPC designs . In Proceedings of the 2003 IEEE Symposium on Security and Privacy (Oakland, Calif.). IEEE Computer Society Press, Los Alamitos, Calif., 251--262 .]] Shapiro, J. S. 2003. Vulnerabilities in synchronous IPC designs. In Proceedings of the 2003 IEEE Symposium on Security and Privacy (Oakland, Calif.). IEEE Computer Society Press, Los Alamitos, Calif., 251--262.]]"},{"key":"e_1_2_1_57_1","volume-title":"Proceedings of the 1st Workshop on Compiler Support for System Software","author":"Sirer E.","unstructured":"Sirer , E. , Fiuczynski , M. , Pardyak , P. , and Bershad , B . 1996. Safe dynamic linking in an extensible operating system . In Proceedings of the 1st Workshop on Compiler Support for System Software ( Tucson, Az.). 141--148.]] Sirer, E., Fiuczynski, M., Pardyak, P., and Bershad, B. 1996. Safe dynamic linking in an extensible operating system. In Proceedings of the 1st Workshop on Compiler Support for System Software (Tucson, Az.). 141--148.]]"},{"key":"e_1_2_1_58_1","unstructured":"SPEC. 1998. SPEC JVM98 benchmarks. http:\/\/www.spec.org\/osg\/jvm98\/.]]  SPEC. 1998. SPEC JVM98 benchmarks. http:\/\/www.spec.org\/osg\/jvm98\/.]]"},{"key":"e_1_2_1_59_1","volume-title":"Proceedings of the 2nd International Symposium on Memory Management","author":"Steensgaard B.","year":"2000","unstructured":"Steensgaard , B. 2000 . Thread-specific heaps for multi-threaded programs . In Proceedings of the 2nd International Symposium on Memory Management ( Minneapolis, Minn.). ACM, New York, 18--24.]] 10.1145\/362422.362432 Steensgaard, B. 2000. Thread-specific heaps for multi-threaded programs. In Proceedings of the 2nd International Symposium on Memory Management (Minneapolis, Minn.). ACM, New York, 18--24.]] 10.1145\/362422.362432"},{"key":"e_1_2_1_60_1","volume-title":"Proceedings of the ACM Conference on Object-Oriented Programming Systems, Languages, and Applications (OOPSLA '99)","author":"Stefanovi\u0107 D.","year":"2038","unstructured":"Stefanovi\u0107 , D. , McKinley , K. S. , and Moss , J. E. B. 1999. Age-based garbage collection . In Proceedings of the ACM Conference on Object-Oriented Programming Systems, Languages, and Applications (OOPSLA '99) (Denver, Col.). ACM, New York, 370--381.]] 10.1145\/3 2038 4.320425 Stefanovi\u0107, D., McKinley, K. S., and Moss, J. E. B. 1999. Age-based garbage collection. In Proceedings of the ACM Conference on Object-Oriented Programming Systems, Languages, and Applications (OOPSLA '99) (Denver, Col.). ACM, New York, 370--381.]] 10.1145\/320384.320425"},{"key":"e_1_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1147\/sj.391.0175"},{"key":"e_1_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/6465.6466"},{"key":"e_1_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1109\/49.917710"},{"key":"e_1_2_1_65_1","volume-title":"Proceedings of the 8th ACM SIGOPS European Workshop","author":"Tullmann P.","year":"1919","unstructured":"Tullmann , P. and Lepreau , J . 1998. Nested Java processes: OS structure for mobile code . In Proceedings of the 8th ACM SIGOPS European Workshop ( Sintra, Portugal). ACM, New York, 111--117.]] 10.1145\/3 1919 5.319212 Tullmann, P. and Lepreau, J. 1998. Nested Java processes: OS structure for mobile code. In Proceedings of the 8th ACM SIGOPS European Workshop (Sintra, Portugal). ACM, New York, 111--117.]] 10.1145\/319195.319212"},{"key":"e_1_2_1_66_1","volume-title":"Proceedings of the 9th USENIX Security Symposium (Denver, Col.). USENIX Association, 19--34","author":"van Doorn L.","year":"2000","unstructured":"van Doorn , L. 2000 . A secure Java virtual machine . In Proceedings of the 9th USENIX Security Symposium (Denver, Col.). USENIX Association, 19--34 .]] van Doorn, L. 2000. A secure Java virtual machine. In Proceedings of the 9th USENIX Security Symposium (Denver, Col.). USENIX Association, 19--34.]]"},{"key":"e_1_2_1_67_1","volume-title":"Proceedings of the 5th Workshop on Hot Topics in Operating Systems (Orcas Island, Wash.). IEEE Computer Society Press, Los Alamitos, Calif., 86--89","author":"van Doorn L.","unstructured":"van Doorn , L. , Homburg , P. , and Tanenbaum , A. S . 1995. Paramecium: an extensible object-based kernel . In Proceedings of the 5th Workshop on Hot Topics in Operating Systems (Orcas Island, Wash.). IEEE Computer Society Press, Los Alamitos, Calif., 86--89 .]] van Doorn, L., Homburg, P., and Tanenbaum, A. S. 1995. Paramecium: an extensible object-based kernel. In Proceedings of the 5th Workshop on Hot Topics in Operating Systems (Orcas Island, Wash.). IEEE Computer Society Press, Los Alamitos, Calif., 86--89.]]"},{"key":"e_1_2_1_68_1","volume-title":"Proceedings of the 14th Symposium on Operating Systems Principles (Asheville, N.C.). 203--216","author":"Wahbe R.","unstructured":"Wahbe , R. , Lucco , S. , Anderson , T. , and Graham , S . 1993. Efficient software-based fault isolation . In Proceedings of the 14th Symposium on Operating Systems Principles (Asheville, N.C.). 203--216 .]] 10.1145\/168619.168635 Wahbe, R., Lucco, S., Anderson, T., and Graham, S. 1993. Efficient software-based fault isolation. In Proceedings of the 14th Symposium on Operating Systems Principles (Asheville, N.C.). 203--216.]] 10.1145\/168619.168635"},{"key":"e_1_2_1_70_1","volume-title":"Proceedings of the 2002 Scheme Workshop","author":"Wick A.","unstructured":"Wick , A. , Flatt , M. , and Hsieh , W . 2002. Reachability-based memory accounting . In Proceedings of the 2002 Scheme Workshop ( Pittsburgh, Pa.).]] Wick, A., Flatt, M., and Hsieh, W. 2002. Reachability-based memory accounting. In Proceedings of the 2002 Scheme Workshop (Pittsburgh, Pa.).]]"},{"key":"e_1_2_1_71_1","unstructured":"Wilkinson T. 1996. Kaffe---A Java virtual machine. http:\/\/www.kaffe.org\/.]]  Wilkinson T. 1996. Kaffe---A Java virtual machine. http:\/\/www.kaffe.org\/.]]"},{"key":"e_1_2_1_72_1","volume-title":"Proceedings of the European Workshop on Parallel Computing","author":"Wilkinson T.","unstructured":"Wilkinson , T. , Stiemerling , T. , Gull , A. , Whitcroft , A. , Osmon , P. , Saulsbury , A. , and Kelly , P . 1992. Angel: A proposed multiprocessor operating system kernel . In Proceedings of the European Workshop on Parallel Computing ( Barcelona, Spain). 316--319.]] Wilkinson, T., Stiemerling, T., Gull, A., Whitcroft, A., Osmon, P., Saulsbury, A., and Kelly, P. 1992. Angel: A proposed multiprocessor operating system kernel. In Proceedings of the European Workshop on Parallel Computing (Barcelona, Spain). 316--319.]]"},{"key":"e_1_2_1_73_1","volume-title":"Proceedings of the International Workshop on Memory Management (IWMM92)","volume":"637","author":"Wilson P. R.","year":"1992","unstructured":"Wilson , P. R. 1992 . Uniprocessor garbage collection techniques . In Proceedings of the International Workshop on Memory Management (IWMM92) , Y. Bekkers and J. Cohen, Eds. Lecture Notes in Computer Science , vol. 637 . Springer-Verlag, New York, 1--42.]] Wilson, P. R. 1992. Uniprocessor garbage collection techniques. In Proceedings of the International Workshop on Memory Management (IWMM92), Y. Bekkers and J. Cohen, Eds. Lecture Notes in Computer Science, vol. 637. Springer-Verlag, New York, 1--42.]]"},{"key":"e_1_2_1_74_1","unstructured":"Wind River Systems Inc. 1995. VxWorks Programmer's Guide. Wind River Systems Inc. Alameda Calif.]]  Wind River Systems Inc. 1995. VxWorks Programmer's Guide. Wind River Systems Inc. Alameda Calif.]]"},{"key":"e_1_2_1_75_1","unstructured":"Wirth N. and Gutknecht J. 1992. Project Oberon. ACM New York.]]  Wirth N. and Gutknecht J. 1992. Project Oberon. ACM New York.]]"},{"key":"e_1_2_1_76_1","volume-title":"Proceedings of the ACM Conference on Object-Oriented Programming Systems, Languages, and Applications (OOPSLA '02)","author":"Zee K.","unstructured":"Zee , K. and Rinard , M . 2002. Write barrier removal by static analysis . In Proceedings of the ACM Conference on Object-Oriented Programming Systems, Languages, and Applications (OOPSLA '02) (Seattle, Wash.). ACM, New York, 191--210.]] 10.1145\/582419.582439 Zee, K. and Rinard, M. 2002. Write barrier removal by static analysis. In Proceedings of the ACM Conference on Object-Oriented Programming Systems, Languages, and Applications (OOPSLA '02) (Seattle, Wash.). ACM, New York, 191--210.]] 10.1145\/582419.582439"}],"container-title":["ACM Transactions on Programming Languages and Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1075382.1075383","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,12,28]],"date-time":"2022-12-28T15:24:22Z","timestamp":1672241062000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1075382.1075383"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2005,7]]},"references-count":71,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2005,7]]}},"alternative-id":["10.1145\/1075382.1075383"],"URL":"https:\/\/doi.org\/10.1145\/1075382.1075383","relation":{},"ISSN":["0164-0925","1558-4593"],"issn-type":[{"value":"0164-0925","type":"print"},{"value":"1558-4593","type":"electronic"}],"subject":[],"published":{"date-parts":[[2005,7]]},"assertion":[{"value":"2005-07-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}