A method for system calls sandboxing based on atomic trusted code region
Miloš Subotić, Nemanja Fimić, Darko Dejanovic, Goran S. Miljkovic · 2014
This paper presents a new algorithm for the sandboxing system calls based on the atomic trusted code region. The algorithm successfully protects against any kind of code-injection attacks as well as any kind of mimicry attack including known-address attacks and scanning attacks. The algorithm is lightweight and simple. The implementation of algorithm does not need any change on an untrusted machine code and does not need extensive changes on system source code. Whole security policy could be enforced in user space as a plug-in, which gives great flexibility.