2016•2016 IEEE Information Technology, Networking, Electronic and Automation Control ConferenceRequires access

Design and implementation of sandbox technique for isolated applications

Muhammad Shams Ul Haq, Lejian Liao, Lerong Ma

Open publisher page 7 citations

Abstract

In presence of known and unknown vulnerabilities in code and flow control of programs, virtual machine alike isolation to confine maliciousness of process is an effective strategy to contain the attack effects in isolated environment. But most of proposed isolation techniques does not offer execution sandbox. A process running in isolated environment with unrestricted access, without explicit mechanism for restriction on access for native system resources such as system call table, network and file system, can access unauthorized resources. In this paper, we propose a sandbox technique for applications running in Virtual Machine alike isolation. The proposed solution is a reference monitor that works without tampering with transitioning mechanism of process and does not require changes in program or kernel. We implemented prototype as executable shared library for dune that provides isolation to native Linux process. Reference monitor uses seccomp BPF filters, Linux Secure Module Apparmor and ptrace utility of native kernel to restrict access to system resources. Experimental results show that proposed technique provide security with acceptable overheads.

About this research paper

What this paper is about

In presence of known and unknown vulnerabilities in code and flow control of programs, virtual machine alike isolation to confine maliciousness of process is an effective strategy to contain the attack effects in isolated environment. But most of proposed isolation techniques does not offer execution sandbox. A process running in isolated environment with unrestricted access, without explicit mechanism for restriction on access for native system resources such as system call table, network and file system, can access unauthorized resources. In this paper, we propose a sandbox technique for applications running in Virtual Machine alike isolation. The proposed solution is a reference monitor that works without tampering with transitioning mechanism of process and does not require changes in program or kernel. We implemented prototype as executable shared library for dune that provides isolation to native Linux process. Reference monitor uses seccomp BPF filters, Linux Secure Module Apparmor and ptrace utility of native kernel to restrict access to system resources. Experimental results show that proposed technique provide security with acceptable overheads.

Why it matters

OpenAlex reports 7 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

In presence of known and unknown vulnerabilities in code and flow control of programs, virtual machine alike isolation to confine maliciousness of process is an effective strategy to contain the attack effects in isolated environment. But most of proposed isolation techniques does not offer execution sandbox. A process running in isolated environment with unrestricted access, without explicit mechanism for restriction on access for native system resources such as system call table, network and file system, can access unauthorized resources. In this paper, we propose a sandbox technique for applications running in Virtual Machine alike isolation. The proposed solution is a reference monitor that works without tampering with transitioning mechanism of process and does not require changes in program or kernel. We implemented prototype as executable shared library for dune that provides isolation to native Linux process. Reference monitor uses seccomp BPF filters, Linux Secure Module Apparmor and ptrace utility of native kernel to restrict access to system resources. Experimental results show that proposed technique provide security with acceptable overheads.

Key concepts: Sandbox (software development), Computer science, System call, Isolation (microbiology), Executable, Operating system, Process (computing), Rootkit

Related papers

Back to paper searchBrowse research topicsOriginal source
Design and implementation of sandbox technique for isolated applications — Research Paper | ScholarLens