Fine-grained user-space security through virtualization

Mathias Payer, Thomas Groß · 2011

This paper presents an approach to the safe execution of applications based on software-based fault isolation and policy-based system call authorization. A running application is encapsulated in an additional layer of protection using dynamic binary translation in user-space. This virtualization layer dynamically recompiles the machine code and adds multiple dynamic security guards that verify the running code to protect and contain the application.

Read the paper · More papers on PaperTik