A SECURE JAILING SYSTEM FOR CONFINING UNTRUSTED APPLICATIONS

Guido van ’t Noordende, Ádám Balogh, Rutger Hofman, Frances M. T. Brazier, Andrew S. Tanenbaum

2007

Abstract

System call interception based jailing is a well-known method for confining (sandboxing) untrusted binary applications. Existing systems that are implemented using standard UNIX debugging mechanisms are rendered insecure by several race conditions. This paper gives an overview of the most important threats to jailing systems, and presents novel mechanisms for implementing jailing securely on standard UNIX systems. We implemented these solutions on Linux, and achieve competitive performance compared to existing jailing systems. Performance results are provided for this implementation, and for an implementation that uses a special-purpose extension to the Linux kernel designed to improve performance of the jailing system.

Download


Paper Citation


in Harvard Style

van ’t Noordende G., Balogh Á., Hofman R., M. T. Brazier F. and S. Tanenbaum A. (2007). A SECURE JAILING SYSTEM FOR CONFINING UNTRUSTED APPLICATIONS . In Proceedings of the Second International Conference on Security and Cryptography - Volume 1: SECRYPT, (ICETE 2007) ISBN 978-989-8111-12-8, pages 414-423. DOI: 10.5220/0002129404140423

in Bibtex Style

@conference{secrypt07,
author={Guido van ’t Noordende and Ádám Balogh and Rutger Hofman and Frances M. T. Brazier and Andrew S. Tanenbaum},
title={A SECURE JAILING SYSTEM FOR CONFINING UNTRUSTED APPLICATIONS},
booktitle={Proceedings of the Second International Conference on Security and Cryptography - Volume 1: SECRYPT, (ICETE 2007)},
year={2007},
pages={414-423},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0002129404140423},
isbn={978-989-8111-12-8},
}


in EndNote Style

TY - CONF
JO - Proceedings of the Second International Conference on Security and Cryptography - Volume 1: SECRYPT, (ICETE 2007)
TI - A SECURE JAILING SYSTEM FOR CONFINING UNTRUSTED APPLICATIONS
SN - 978-989-8111-12-8
AU - van ’t Noordende G.
AU - Balogh Á.
AU - Hofman R.
AU - M. T. Brazier F.
AU - S. Tanenbaum A.
PY - 2007
SP - 414
EP - 423
DO - 10.5220/0002129404140423