A Survey on Application Sandboxing Techniques

A Survey on Application Sandboxing Techniques
复制标题

应用程序沙箱技术综述

DOI:
--
复制
发表时间:
2017
期刊:
International Conference on Computer Systems and Technologies
影响因子:
--
通讯作者:
Ville Leppänen
Ville Leppänen
中科院分区:
--
文献类型:
--
作者:
S. Laurén;Sampsa Rauti;Ville Leppänen

文献摘要

被引文献

相似文献

最小特权原则指出,应该只允许系统中的组件执行其功能所需的操作。限制程序可以访问的内容的愿望产生了一组应用程序级沙箱解决方案。本文对应用层沙盒的最新研究进行了综述。我们将讨论主要实现的属性,并强调它们之间的主要区别。此外,我们还展示了主流Linux内核中的最新特性如何改变了沙箱环境。
The principle of least privilege states that components in a system should only be allowed to perform actions that are required for them to function. The wish to limit what programs can access has given rise to a set of application-level sandboxing solutions. In this paper, we survey recent research on application-level sandboxing. We discuss the properties of the major implementations and highlight the key differences between them. In addition, we show how recent features in mainline Linux kernel have altered the sandboxing landscape.