Improvements the Seccomp Sandbox Based on PBE Theory

Improvements the Seccomp Sandbox Based on PBE Theory
复制标题

基于PBE理论的Seccomp沙箱改进

DOI:
10.1109/waina.2013.81
复制
发表时间:
2013
期刊:
2013 27th International Conference on Advanced Information Networking and Applications Workshops
影响因子:
--
通讯作者:
Wei Hu
Wei Hu
中科院分区:
--
文献类型:
--
作者:
Bo Ma;Dejun Mu;Weimin Fan;Wei Hu

文献摘要

被引文献

相似文献

为未知用户提供安全的计算条件是现有网络计算中的至关重要的任务,通常我们可以使用沙盒技术来屏蔽安全问题,但是在沙箱中,恶意占领资源的行为尚未得到很好的控制。在此段落中,可以通过改进Linux内核安全计算模式(SECCOMP)系统来获得访问计算效率和准确性的许可率,此外,使用系统调用判断技术来防止其恶意行为从用户代码中保护系统。在计算过程中,具体来说,可以使用改进的完美贝叶斯均衡(PBE)算法来确定系统通用过程中的用户行为,利用此算法来构建策略引擎,并使用引擎决策引擎来决定现有用户'因此,行为最大程度地提高了用户代码操作和服务器系统容量的利润。此外,在实现中断的确定和中断访问时,代理技术同时分开计算和操作系统。毕竟,改进的沙盒技术是实现用户服务效率和安全保证之间的相对优化。最后,实验表明,与Sandboxie和缓冲区技术相比,所提出的算法优化了原始SECCOMP SANDBOX中系统资源的消耗,其访问率也确定了一定程度的速度。特别是,它可以有效防止从恶意代码中进行特殊的系统调用,该系统可以在很大程度上保护系统。此外,测试速度和几个常规系统调用(例如文件访问操作)的性能,写操作也在逐步改进之下。
Providing a safe computing condition to unknown user is a crucial task in the existing network computing, and usually we can use the sandbox technology to shield security issues, but the behavior of malicious-occupying the resource has not been well controlled in the sandbox. In this passage, permission rate to access the computational efficiency and accuracy can be available by improving the Linux Kernel Secure Computing Mode(Seccomp) System, furthermore using the system calls judgment technology to prevent its malicious acts from user code can protect the system. During the calculations procedure, specifically, the improved Perfect Bayesian Equilibrium (PBE) Algorithm can be used to determine user behavior in system-call process, utilize this algorithm to construct policy engine, and use the engine decision-making engine to decide existing users' behavior as a result to maximize the profits of both the user code operating and server system capacity. Moreover agent technology that works in achieving the interrupted determination and interrupted access separate the computing and operating systems simultaneously. After all, improving sandbox technology is to achieve the relative optimization between the user service efficiency and security guarantees. Finally, the experiments show that compared with the Sandboxie and Buffer Zone technology, the proposed algorithm optimizes the consumption of the system resources in the original Seccomp Sandbox, and its access determine in rate also speeds up in the certain degree. In particular, it can effectively prevent special system call from malicious code, which can protect the system mainly in large extent. Moreover, the testing speed and the performance of several regular system calls such as file access operation, write operation also are under the progressive improvement.