Ostia: A Delegating Architecture for Secure System Call Interposition.

Tal Garfinkel, Ben Pfaff, Mendel Rosenblum · 2004

Application sandboxes provide restricted execution environments that limit an application's access to sensitive OS resources. These systems are an increasingly popular method for limiting the impact of a compromise. While a variety of mechanisms for building these systems have been proposed, the most thoroughly implemented and studied are based on system call interposition. Current interpositionbased architectures offer a wide variety of properties that make them an attractive approach for building sandboxing systems. Unfortunately, these architectures also possess several critical properties that make their implementation error prone and limit their functionality. We present

Read the paper · More papers on PaperTik