A SECURE JAILING SYSTEM FOR CONFINING UNTRUSTED APPLICATIONS

G.J. van t Noordende, Ádám Balogh, Rutger Hofman, F.M. Brazier, Andrew S. Tanenbaum · 2007

System call interception based jailing is a well-known method for confining (sandboxing) untrusted binary applications. Existing systems that are implemented using standard UNIX debugging mechanisms are rendered insecure by several race conditions. This paper gives an overview of the most important threats to jailing systems, and presents novel mechanisms for implementing jailing securely on standard UNIX systems. We implemented these solutions on Linux, and achieve competitive performance compared to existing jailing systems. Performance results are provided for this implementation, and for an implementation that uses a special-purpose extension to the Linux kernel designed to improve performance of the jailing system.

Read the paper · More papers on PaperTik