loading
Papers Papers/2022 Papers Papers/2022

Research.Publish.Connect.

Paper

Paper Unlock

Authors: Guido van ’t Noordende 1 ; Ádám Balogh 2 ; Rutger Hofman 1 ; Frances M. T. Brazier 1 and Andrew S. Tanenbaum 1

Affiliations: 1 Vrije Universiteit, Netherlands ; 2 Eötvös Loránd University, Hungary

Keyword(s): System Call Interception, Application Confinement, Jailing.

Related Ontology Subjects/Areas/Topics: Cryptographic Techniques and Key Management ; Information and Systems Security ; Mobile Code & Agent Security ; Secure Software Development Methodologies ; Security Engineering ; Security for Grid Computing ; Security in Information Systems ; Security Information Systems Architecture and Design and Security Patterns ; Security Requirements

Abstract: System call interception based jailing is a well-known method for confining (sandboxing) untrusted binary applications. Existing systems that are implemented using standard UNIX debugging mechanisms are rendered insecure by several race conditions. This paper gives an overview of the most important threats to jailing systems, and presents novel mechanisms for implementing jailing securely on standard UNIX systems. We implemented these solutions on Linux, and achieve competitive performance compared to existing jailing systems. Performance results are provided for this implementation, and for an implementation that uses a special-purpose extension to the Linux kernel designed to improve performance of the jailing system.

CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 18.221.85.33

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
van ’t Noordende, G.; Balogh, Á.; Hofman, R.; M. T. Brazier, F. and S. Tanenbaum, A. (2007). A SECURE JAILING SYSTEM FOR CONFINING UNTRUSTED APPLICATIONS. In Proceedings of the Second International Conference on Security and Cryptography (ICETE 2007) - SECRYPT; ISBN 978-989-8111-12-8; ISSN 2184-3236, SciTePress, pages 414-423. DOI: 10.5220/0002129404140423

@conference{secrypt07,
author={Guido {van ’t Noordende}. and Ádám Balogh. and Rutger Hofman. and Frances {M. T. Brazier}. and Andrew {S. Tanenbaum}.},
title={A SECURE JAILING SYSTEM FOR CONFINING UNTRUSTED APPLICATIONS},
booktitle={Proceedings of the Second International Conference on Security and Cryptography (ICETE 2007) - SECRYPT},
year={2007},
pages={414-423},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0002129404140423},
isbn={978-989-8111-12-8},
issn={2184-3236},
}

TY - CONF

JO - Proceedings of the Second International Conference on Security and Cryptography (ICETE 2007) - SECRYPT
TI - A SECURE JAILING SYSTEM FOR CONFINING UNTRUSTED APPLICATIONS
SN - 978-989-8111-12-8
IS - 2184-3236
AU - van ’t Noordende, G.
AU - Balogh, Á.
AU - Hofman, R.
AU - M. T. Brazier, F.
AU - S. Tanenbaum, A.
PY - 2007
SP - 414
EP - 423
DO - 10.5220/0002129404140423
PB - SciTePress