Design and Implementation of Sandbox Technique for Isolated Applications

被引:0
|
作者
Ul Haq, Muhammad Shams [1 ]
Liao, Lejian [1 ]
Ma Lerong [1 ]
机构
[1] Beijing Inst Technol, Sch Comp Sci & Technol, Beijing, Peoples R China
关键词
computer security; apparmor; seccomp filters; Reference monitor; isolation;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In presence of known and unknown vulnerabilities in code and flow control of programs, virtual machine alike isolation to confine maliciousness of process is an effective strategy to contain the attack effects in isolated environment. But most of proposed isolation techniques does not offer execution sandbox. A process running in isolated environment with unrestricted access, without explicit mechanism for restriction on access for native system resources such as system call table, network and file system, can access unauthorized resources. In this paper, we propose a sandbox technique for applications running in Virtual Machine alike isolation. The proposed solution is a reference monitor that works without tampering with transitioning mechanism of process and does not require changes in program or kernel. We implemented prototype as executable shared library for dune that provides isolation to native Linux process. Reference monitor uses seccomp BPF filters, Linux Secure Module Apparmor and ptrace utility of native kernel to restrict access to system resources. Experimental results show that proposed technique provide security with acceptable overheads.
引用
收藏
页码:557 / 561
页数:5
相关论文
共 50 条
  • [1] Design issues of an isolated sandbox used to analyze malwares
    Miwa, Shinsuke
    Miyachi, Toshiyuki
    Eto, Masashi
    Yoshizumi, Masashi
    Shinoda, Yoichi
    ADVANCES IN INFORMATION AND COMPUTER SECURITY, PROCEEDINGS, 2007, 4752 : 13 - +
  • [2] Concepts and applications of the sandbox
    Lockowandt, O
    ZEITSCHRIFT FUR KINDER-UND JUGENDPSYCHIATRIE UND PSYCHOTHERAPIE, 1998, 26 (03): : 221 - 222
  • [3] The sandbox design experience course
    Schmit, H
    Kroll, T
    Khusid, M
    Kourtev, I
    Vijaykrishnan, N
    Landis, D
    2003 IEEE INTERNATIONAL CONFERENCE ON MICROELECTRONIC SYSTEMS EDUCATION, PROCEEDINGS, 2003, : 39 - 40
  • [4] Implementation of therapeutic design applications
    Stoneham, J
    INTERACTION BY DESIGN: BRINGING PEOPLE AND PLANTS TOGETHER FOR HEALTH AND WELL BEING, 2002, : 157 - 163
  • [5] STRATEGY IMPLEMENTATION - A TECHNIQUE FOR ORGANIZATIONAL DESIGN
    DRAZIN, R
    HOWARD, P
    COLUMBIA JOURNAL OF WORLD BUSINESS, 1984, 19 (02): : 40 - 46
  • [6] Modelling, design, control, and implementation of advanced isolated DC/DC converters for renewable energy applications
    Wei, Yuqi
    Luo, Quanming
    Mou, Di
    Zhao, Shuang
    Liserre, Marco
    Mantooth, H. Alan
    IET POWER ELECTRONICS, 2024, 17 (10) : 1159 - 1162
  • [8] ITE Micromobility Sandbox Design Competition
    不详
    ITE JOURNAL-INSTITUTE OF TRANSPORTATION ENGINEERS, 2020, 90 (10): : 10 - 10
  • [9] The Sandbox: Development and Implementation of a Technology-Enhanced Classroom
    Logan, Rebecca M.
    Johnson, Cynthia E.
    Worsham, Jeremy
    NURSING EDUCATION PERSPECTIVES, 2020, 41 (05) : E50 - E51
  • [10] Design and Implementation of LNA for Biomedical Applications
    Bansal, Malti
    Srivastava, Gaurav
    INTELLIGENT COMPUTING, INFORMATION AND CONTROL SYSTEMS, ICICCS 2019, 2020, 1039 : 154 - 167