2014•Unpublished venueRequires access

Design and Implementation of Linux Application Sandbox Based on Multiple Security Mechanisms

Li Che

Open publisher page 0 citations

Abstract

Linux application sandbox is designed for providing an independent, secure operating environment for untrusted applications. The sandbox has its own independent working directory, and the operation of applications in the sandbox has no impact on the host. The sandbox provides fi lesystem isolation, system resources isolation, physical resources isolation, capabilities limits and mandatory access control(MAC) policies, adding memory protection policies like address randomization and non-executable memory page protection. The sandbox increases several security mechanisms relative to existing sandboxes, improving the system security and protecting the system and user's personal privacy.

About this research paper

What this paper is about

Linux application sandbox is designed for providing an independent, secure operating environment for untrusted applications. The sandbox has its own independent working directory, and the operation of applications in the sandbox has no impact on the host. The sandbox provides fi lesystem isolation, system resources isolation, physical resources isolation, capabilities limits and mandatory access control(MAC) policies, adding memory protection policies like address randomization and non-executable memory page protection. The sandbox increases several security mechanisms relative to existing sandboxes, improving the system security and protecting the system and user's personal privacy.

Why it matters

A significance statement is not available in the OpenAlex record.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Linux application sandbox is designed for providing an independent, secure operating environment for untrusted applications. The sandbox has its own independent working directory, and the operation of applications in the sandbox has no impact on the host. The sandbox provides fi lesystem isolation, system resources isolation, physical resources isolation, capabilities limits and mandatory access control(MAC) policies, adding memory protection policies like address randomization and non-executable memory page protection. The sandbox increases several security mechanisms relative to existing sandboxes, improving the system security and protecting the system and user's personal privacy.

Key concepts: Sandbox (software development), Computer science, Isolation (microbiology), Executable, Lightweight Directory Access Protocol, Computer security, Operating system, Directory

Related papers

Back to paper searchBrowse research topicsOriginal source
Design and Implementation of Linux Application Sandbox Based on Multiple Security Mechanisms — Research Paper | ScholarLens