Survey of Real-World Process Sandboxing
Arto Niemi · 2024
Attackers often exploit vulnerabilities in network-facing processes to gain access to the rest of the system. To combat this, modern operating systems such as Android, iOS and major Linux distributions allow running vulnerable or untrusted processes inside sandboxes – confined execution environments, where access to resources is restricted according to an implicit or configurable security policy. Major building blocks of sandbox implementations include namespace virtualization, system call interposition and kernel subsystem hooking. In this paper, we survey the state-of-the-art in process sandboxing, focusing on solutions that are widely deployed in consumer devices and cloud servers.