A Survey on Application Sandboxing Techniques
Samuel Laurén, Sampsa Rauti, Ville Leppänen · 2017
The principle of least privilege states that components in a system should only be allowed to perform actions that are required for them to function. The wish to limit what programs can access has given rise to a set of application-level sandboxing solutions. In this paper, we survey recent research on application-level sandboxing. We discuss the properties of the major implementations and highlight the key differences between them. In addition, we show how recent features in mainline Linux kernel have altered the sandboxing landscape.