Design and Implementation of Sandbox Technique for Isolated Applications

被引:0
|
作者
Ul Haq, Muhammad Shams [1 ]
Liao, Lejian [1 ]
Ma Lerong [1 ]
机构
[1] Beijing Inst Technol, Sch Comp Sci & Technol, Beijing, Peoples R China
关键词
computer security; apparmor; seccomp filters; Reference monitor; isolation;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In presence of known and unknown vulnerabilities in code and flow control of programs, virtual machine alike isolation to confine maliciousness of process is an effective strategy to contain the attack effects in isolated environment. But most of proposed isolation techniques does not offer execution sandbox. A process running in isolated environment with unrestricted access, without explicit mechanism for restriction on access for native system resources such as system call table, network and file system, can access unauthorized resources. In this paper, we propose a sandbox technique for applications running in Virtual Machine alike isolation. The proposed solution is a reference monitor that works without tampering with transitioning mechanism of process and does not require changes in program or kernel. We implemented prototype as executable shared library for dune that provides isolation to native Linux process. Reference monitor uses seccomp BPF filters, Linux Secure Module Apparmor and ptrace utility of native kernel to restrict access to system resources. Experimental results show that proposed technique provide security with acceptable overheads.
引用
收藏
页码:557 / 561
页数:5
相关论文
共 50 条
  • [31] Design and Implementation of ADPLL for Digital Communication Applications
    Chaudhary, Abhishek Kumar
    Kumar, Manoj
    2017 2ND INTERNATIONAL CONFERENCE FOR CONVERGENCE IN TECHNOLOGY (I2CT), 2017, : 397 - 401
  • [32] Design and Implementation of Textile Sensors for Biotelemetry Applications
    Cerny, M.
    Martinak, L.
    Penhaker, M.
    Rosulek, M.
    14TH NORDIC-BALTIC CONFERENCE ON BIOMEDICAL ENGINEERING AND MEDICAL PHYSICS, 2008, 20 : 194 - 197
  • [33] Design and Implementation of Optimized LDPC for SDR Applications
    Lenin, D. Sahaya
    Shekhar, Himanshu
    INTERNATIONAL TRANSACTION JOURNAL OF ENGINEERING MANAGEMENT & APPLIED SCIENCES & TECHNOLOGIES, 2021, 12 (01):
  • [34] Design and Implementation of Bionic Flying Fish with Applications
    Cai, Haifeng
    Liu, Mei
    Su, Dan
    ADVANCES IN COMPUTATIONAL INTELLIGENCE SYSTEMS, 2022, 1409 : 227 - 232
  • [35] Domain Isolated Kernel: A lightweight sandbox for untrusted kernel extensions
    Manes, Valentin J. M.
    Jang, Daehee
    Ryu, Chanho
    Kang, Brent Byunghoon
    COMPUTERS & SECURITY, 2018, 74 : 130 - 143
  • [36] A sandbox with a dynamic policy based on execution contexts of applications
    Shioya, Tomohiro
    Oyama, Yoshihiro
    Iwasaki, Hideya
    ADVANCES IN COMPUTER SCIENCE - ASIAN 2007: COMPUTER AND NETWORK SECURITY, PROCEEDINGS, 2007, 4846 : 297 - 311
  • [37] DESIGN AND IMPLEMENTATION OF A TECHNIQUE FOR ITERATIVE MAGNETORHEOLOGICAL JET POLISHING
    Li, Pak-yin Adam
    Cheung, Ming-fu Melvin
    Tong, Hang
    Cheng, Haobo
    Yam, Yeung
    INTERNATIONAL JOURNAL OF OPTOMECHATRONICS, 2014, 8 (03) : 195 - 205
  • [38] Design of a Spatial domain Watermarking technique with VLSI Implementation
    Pendyala, Manisha
    Gokhale, Aniket
    2016 CONFERENCE ON ADVANCES IN SIGNAL PROCESSING (CASP), 2016, : 498 - 503
  • [39] Lowpass Filter Design Technique for Hybrid and Monolithic Implementation
    Amrani, Faycal
    Trabelsi, Mohamed
    Saadi, Abdelhalim A.
    Touhami, Rachida
    2016 11TH IEEE INTERNATIONAL CONFERENCE ON DESIGN & TECHNOLOGY OF INTEGRATED SYSTEMS IN NANOSCALE ERA (DTIS), 2016,
  • [40] Design & Implementation of a Novel Cognitive Character Recognition Technique
    Giri, Kaiser J.
    Bashir, Rumaan
    2013 INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING AND COMMUNICATION (ICSC), 2013, : 225 - 229