Design and Implementation of Sandbox Technique for Isolated Applications

被引:0
|
作者
Ul Haq, Muhammad Shams [1 ]
Liao, Lejian [1 ]
Ma Lerong [1 ]
机构
[1] Beijing Inst Technol, Sch Comp Sci & Technol, Beijing, Peoples R China
关键词
computer security; apparmor; seccomp filters; Reference monitor; isolation;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In presence of known and unknown vulnerabilities in code and flow control of programs, virtual machine alike isolation to confine maliciousness of process is an effective strategy to contain the attack effects in isolated environment. But most of proposed isolation techniques does not offer execution sandbox. A process running in isolated environment with unrestricted access, without explicit mechanism for restriction on access for native system resources such as system call table, network and file system, can access unauthorized resources. In this paper, we propose a sandbox technique for applications running in Virtual Machine alike isolation. The proposed solution is a reference monitor that works without tampering with transitioning mechanism of process and does not require changes in program or kernel. We implemented prototype as executable shared library for dune that provides isolation to native Linux process. Reference monitor uses seccomp BPF filters, Linux Secure Module Apparmor and ptrace utility of native kernel to restrict access to system resources. Experimental results show that proposed technique provide security with acceptable overheads.
引用
收藏
页码:557 / 561
页数:5
相关论文
共 50 条
  • [21] A DYNAMIC SANDBOX DETECTION TECHNIQUE IN A PRIVATE CLOUD ENVIRONMENT
    Yang, Zhangwei
    Xiao, Junyu
    SCALABLE COMPUTING-PRACTICE AND EXPERIENCE, 2024, 25 (06): : 4995 - 5004
  • [22] Design and implementation of data stream processing applications
    Kwan, Edwin
    Getta, Janusz R.
    Vossough, Ehsan
    ICSOFT 2007: PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON SOFTWARE AND DATA TECHNOLOGIES, VOL ISDM/WSEHST/DC, 2007, : 193 - +
  • [23] DESIGN AND IMPLEMENTATION OF TREE DECODER FOR SDR APPLICATIONS
    Kumar, Sachin
    Gupta, Jyoti
    Praveen, Pushkar
    2014 INNOVATIVE APPLICATIONS OF COMPUTATIONAL INTELLIGENCE ON POWER, ENERGY AND CONTROLS WITH THEIR IMPACT ON HUMANITY (CIPECH), 2014, : 331 - 335
  • [24] Design And Implementation Robots For Industrial And Medical Applications
    Kumar, V. Madhu
    Balamurugan, R.
    Krishnan, S. Navaneetha
    Kumar, S. Dinesh
    Kumar, P. Nalin
    2013 INTERNATIONAL CONFERENCE ON CURRENT TRENDS IN ENGINEERING AND TECHNOLOGY (ICCTET), 2013, : 346 - 348
  • [25] THE DESIGN AND IMPLEMENTATION OF GIS APPLICATIONS BASED ON SOA
    Wang, Xiaolin
    Pang, Xiao
    Luo, Yingwei
    2010 IEEE INTERNATIONAL GEOSCIENCE AND REMOTE SENSING SYMPOSIUM, 2010, : 3999 - 4002
  • [26] Design and Implementation of Encoding Techniques for Wireless Applications
    Raghul, G.
    Sudhakar, K.
    Devi, Gayathri M.
    2015 INTERNATIONAL CONFERENCED ON CIRCUITS, POWER AND COMPUTING TECHNOLOGIES (ICCPCT-2015), 2015,
  • [27] Terahertz metamaterials: Design, implementation, modeling and applications
    Hokmabadi, Mohammad P.
    Balci, Soner
    Kim, Juhyung
    Philip, Elizabath
    Rivera, Elmer
    Zhu, Muliang
    Kung, Patrick
    Kim, Seongsin M.
    TERAHERTZ PHYSICS, DEVICES, AND SYSTEMS X: ADVANCED APPLICATIONS IN INDUSTRY AND DEFENSE, 2016, 9856
  • [28] DESIGN AND IMPLEMENTATION OF UART PROTOCOL FOR AVIONICS APPLICATIONS
    Nayani, A. S. Keerthi
    Nikhilesh, G.
    Kumar, S. Shiva Tej
    PROCEEDINGS OF THE 2019 INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTING AND CONTROL SYSTEMS (ICCS), 2019, : 1402 - 1407
  • [29] Design and Implementation of VI Tool for WSN Applications
    Pahuja, Roop
    Verma, H. K.
    Uddin, Moin
    WORLD CONGRESS ON ENGINEERING AND COMPUTER SCIENCE, VOLS 1 AND 2, 2010, : 838 - +
  • [30] Design and Implementation of MIMO Antenna for CR Applications
    Vijetha, T.
    Laxmi, U. Dhana
    Badrinath, P.
    Reddy, G. Vamshidhar
    Reddy, K. Harun
    2017 INTERNATIONAL CONFERENCE OF ELECTRONICS, COMMUNICATION AND AEROSPACE TECHNOLOGY (ICECA), VOL 2, 2017, : 681 - 683