A FRAMEWORK FOR APPLICATION-LEVEL ISOLATION AND RECOVERY

Shvetank Jain · TSpace (University of Toronto) · 2008

When computer systems are compromised by an attack, determining the precise extent of the damage is difficult because the state changes made by attackers and regular users can be closely intertwined. This problem can be especially severe for persistent state, making intrusion analysis and recovery a time-consuming and error-prone process. Since file sharing across applications is relatively uncommon, we propose limiting the effects of attacks and simplifying the post-intrusion recovery process through explicit sharing of all persistent data. We present a system, Solitude that uses a copy-on-write filesystem for running untrusted applications transparently in a sandboxing environment. Solitude provides two modes of recovery. If a sandboxed application proves to be untrustworthy, a coarse-grained recovery method allows completely removing the footprint of the software. However, if untrusted files are mistakenly moved from the sandbox to the regular environment via explicit sharing, then Solitude uses data dependency tracking to allow fine-grained recovery.

Read the paper · More papers on PaperTik