Recursive Sandboxes: Extending Systrace to Empower Applications

Aleksey Kurchuk, Angelos D. Keromytis · 2004

The systrace system-call interposition mechanism has become a popular method for containing untrusted code through program-specific policies enforced by user-level daemons. We describe our extensions to systrace that allow sand-boxed processes to further limit their children processes by issuing dynamically constructed policies. We discuss our extensions to the systrace daemon and the OpenBSD kernel, as well as a simple API for constructing simple policies. We present two separate implementations of our scheme, and compare their perfor mance with the base systrace system . We show how our extensions can be used by processes such asftpd, sendmail , and sshd .

Read the paper · More papers on PaperTik