Design and Implementation of Linux Application Sandbox Based on Multiple Security Mechanisms
Li Che
Abstract
Li Che
Abstract
Linux application sandbox is designed for providing an independent, secure operating environment for untrusted applications. The sandbox has its own independent working directory, and the operation of applications in the sandbox has no impact on the host. The sandbox provides fi lesystem isolation, system resources isolation, physical resources isolation, capabilities limits and mandatory access control(MAC) policies, adding memory protection policies like address randomization and non-executable memory page protection. The sandbox increases several security mechanisms relative to existing sandboxes, improving the system security and protecting the system and user's personal privacy.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Linux application sandbox is designed for providing an independent, secure operating environment for untrusted applications. The sandbox has its own independent working directory, and the operation of applications in the sandbox has no impact on the host. The sandbox provides fi lesystem isolation, system resources isolation, physical resources isolation, capabilities limits and mandatory access control(MAC) policies, adding memory protection policies like address randomization and non-executable memory page protection. The sandbox increases several security mechanisms relative to existing sandboxes, improving the system security and protecting the system and user's personal privacy.
Key concepts: Sandbox (software development), Computer science, Isolation (microbiology), Executable, Lightweight Directory Access Protocol, Computer security, Operating system, Directory