Behavior-based Confinement of Untrusted Applications
Mandar Raje · 1999
In my thesis, I propose a class-specific sandboxing mechanism to confine untrusted applications. The key idea is to identify different application classes like editor, browser, mail client, shell, filter, server etc and to confine applications belonging to each class in a sandbox that is tailored to the expected behavior/requirements of the class. For example, the sandbox for a MIME-mail client could be restricted to allow it to spawn only a set of helper applications explicitly listed in the mailcap file; the sandbox for an editor could be restricted to disallow network accesses and process creation. Such a mechanism retains the ease-of-use of sandboxes while significantly increasing their flexibility. End-users do not need to maintain complex access control lists or interact frequently with the security subsystem; nor do they need to depend solely on a digital signature. They can configure their systems by specifying the set of classes they would like to allow. To evaluate the feasi...