Stanford Security Lunch

Welcome to Security Lunch. We host speakers from both industry and academia to give talks related to applied cryptography, and system and network security.
If you're interested in attending, please sign up for the mailing list to receive updates about upcoming talks. There is an option to join virtually on Zoom.
If you're interested in giving a talk, we would love to have you! Please find more details in the About page.
You can find the upcoming and past talks for the current quarter below. We meet every Wednesday, 12 pm in CoDa E160.

Summer 2026

Upcoming

Abstract: Virtual Machine Introspection (VMI) offers a compelling foundation for cloud security: by moving security mechanisms outside the monitored virtual machine, it can remain effective even when the guest OS is fully compromised. Yet, despite this strong isolation property, VMI has seen limited practical adoption. Existing approaches often rely on coarse-grained VM pauses to obtain a consistent view of the guest state, leading to prohibitive performance overheads and poor scalability. In this talk, I will present GoodKit, a framework that revisits the design of live virtual machine introspection. GoodKit runs observers inside lightweight VMs colocated with the virtual machine monitor, providing near-native access to the target VM state while preserving strong isolation. It introduces fine-grained, lock-aware mechanisms for memory coherence, a configurable probing infrastructure for I/O and kernel events, and a mutualization layer that allows multiple observers to efficiently monitor the same VM. We evaluate GoodKit across 21 real-world use cases, ranging from rootkit detection and ransomware monitoring to operating-system and scheduler introspection. The results show that live introspection does not have to come at the cost of target performance. Beyond GoodKit itself, this talk will discuss a broader question: can we make out-of-VM monitoring practical enough to become a first-class building block for cloud security and observability?

Bio: Alain Tchana (https://lig-membres.imag.fr/tchanaa/index.html) is a Professor of Computer Science at Grenoble INP – UGA and a member of the Grenoble Informatics Laboratory (LIG), where he leads the KrakOS research team (https://lig-krakos.imag.fr/). His research focuses on operating systems, virtualization, and cloud computing, with a particular interest in building efficient, secure, and practical systems. He received his PhD in Computer Science from Toulouse INP in 2011. Before joining Grenoble INP in 2022, he held faculty positions at Toulouse INP, Université Côte d’Azur, and ENS Lyon. Alain has published more than 70 papers in major systems, networking, and security venues, including OSDI, EuroSys, USENIX ATC, INFOCOM, SIGMETRICS, NSDI, VEE, Middleware, RAID, DSN. He has served on the program committees of conferences including SOSP, EuroSys, USENIX ATC, NSDI. He received the CNRS GDR RSD Best Junior Researcher Award and the Prix de la Francophonie pour Jeunes Chercheurs. At heart, he describes himself simply as “a Systems guy.”

Past