Design and Implementation of Sandbox Technique for Isolated Applications

被引:0
|
作者
Ul Haq, Muhammad Shams [1 ]
Liao, Lejian [1 ]
Ma Lerong [1 ]
机构
[1] Beijing Inst Technol, Sch Comp Sci & Technol, Beijing, Peoples R China
关键词
computer security; apparmor; seccomp filters; Reference monitor; isolation;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In presence of known and unknown vulnerabilities in code and flow control of programs, virtual machine alike isolation to confine maliciousness of process is an effective strategy to contain the attack effects in isolated environment. But most of proposed isolation techniques does not offer execution sandbox. A process running in isolated environment with unrestricted access, without explicit mechanism for restriction on access for native system resources such as system call table, network and file system, can access unauthorized resources. In this paper, we propose a sandbox technique for applications running in Virtual Machine alike isolation. The proposed solution is a reference monitor that works without tampering with transitioning mechanism of process and does not require changes in program or kernel. We implemented prototype as executable shared library for dune that provides isolation to native Linux process. Reference monitor uses seccomp BPF filters, Linux Secure Module Apparmor and ptrace utility of native kernel to restrict access to system resources. Experimental results show that proposed technique provide security with acceptable overheads.
引用
收藏
页码:557 / 561
页数:5
相关论文
共 50 条
  • [41] Ancient Sandbox Technique: An Experimental Study Using Piezoelectric Sensors
    Daka, Trishala
    Udatha, Lokesh
    Pasupuleti, Venkata Dilip Kumar
    Kalapatapu, Prafulla
    Rajaram, Bharghava
    DIGITAL HERITAGE: PROGRESS IN CULTURAL HERITAGE: DOCUMENTATION, PRESERVATION, AND PROTECTION, EUROMED 2018, PT II, 2018, 11197 : 173 - 184
  • [42] Design and characterization of a HMPPT technique for PV applications
    Aurilio, Gianluca
    Balato, Marco
    Gallo, Daniele
    Landi, Carmine
    Luiso, Mario
    Vitelli, Massimo
    2013 IEEE INTERNATIONAL WORKSHOP ON APPLIED MEASUREMENTS FOR POWER SYSTEMS (AMPS), 2013, : 162 - 167
  • [43] Design and Implementation of a Cuk Based Isolated Bidirectional DC-DC Converter with Active Snubber Circuit for EV Applications
    Das, Debabrata
    Barai, Mukti
    2021 NATIONAL POWER ELECTRONICS CONFERENCE (NPEC), 2021,
  • [44] A Serious Game Design Combining Simulation and Sandbox Approaches
    Lukosch, Heide
    van Bussel, Roy
    Meijer, Sebastiaan A.
    FRONTIERS IN GAMING SIMULATION, 2014, 8264 : 52 - 59
  • [45] Designing a Mixed-Reality Sandbox Game on Implementation in Inbound Logistics
    Hauge, Jannicke Baalsrud
    Chowdhury, Anindya
    Basu, Prabahan
    Fatima, Sundus
    Schurig, Artem
    SERIOUS GAMES, JCSG 2021, 2021, 12945 : 47 - 54
  • [46] Applications and implementation of the iterative convolution/superposition dose reconstruction technique
    McNutt, TR
    Mackie, TR
    Reckwerdt, PJ
    Paliwal, BR
    PROCEEDINGS OF THE XIITH INTERNATIONAL CONFERENCE ON THE USE OF COMPUTERS IN RADIATION THERAPY, 1997, : 111 - 113
  • [47] 2023 Designing Main Street Sandbox Design Competition
    不详
    ITE JOURNAL-INSTITUTE OF TRANSPORTATION ENGINEERS, 2023, 93 (10): : 12 - 15
  • [48] A Scenario Based Virtual Military Sandbox Implementation Using Web Services
    Koyuncu, Baki
    Bostanci, Erkan
    INTERNATIONAL CONFERENCE ON ADVANCED COMPUTER CONTROL : ICACC 2009 - PROCEEDINGS, 2009, : 767 - 771
  • [49] Leaving the sandbox: Third party validation for Java']Java applications
    Jermyn, I
    Monrose, F
    Wyckoff, P
    INTERNATIONAL SOCIETY FOR COMPUTERS AND THEIR APPLICATIONS 13TH INTERNATIONAL CONFERENCE ON COMPUTERS AND THEIR APPLICATIONS, 1998, : 436 - 439
  • [50] Tutorial: Voting Advice Applications: Design, Implementation, and Impact
    Rissi, Robin Bartlett
    Teran, Luis
    Fivaz, Jan
    Schwarz, Daniel
    2020 SEVENTH INTERNATIONAL CONFERENCE ON EDEMOCRACY & EGOVERNMENT (ICEDEG), 2020, : 6 - 8