A Study of Application Sandbox Policies in Linux

A Study of Application Sandbox Policies in Linux
复制标题

Linux中应用程序沙箱策略的研究

DOI:
10.1145/3532105.3535016
复制
发表时间:
2022
期刊:
ACM Symposium on Access Control Models and Technologies (SACMAT
影响因子:
--
通讯作者:
Reaves, Bradley
Reaves, Bradley
中科院分区:
--
文献类型:
--
作者:
Dunlap, Trevor;Enck, William;Reaves, Bradley

文献摘要

参考文献

被引文献

相似文献

桌面操作系统(包括 macOS、Windows 10 和 Linux)正在采用移动平台中普遍存在的基于应用程序的安全模型。在 Linux 中,这种转变是向两个独立于发行版的应用程序平台(Flatpak 和 Snap)发展的一部分。本文首次分析了为 Flatpak 和 Snap 应用程序定义的沙箱策略,涵盖两个平台中包含的 283 个应用程序。首先,我们发现所研究的 90.1% 的 Snap 和 58.3% 的 Flatpak 应用程序都包含在防篡改沙箱中。此外,我们发现有证据表明包维护者积极尝试定义最低权限应用程序策略。然而,制定政策是困难且容易出错的。在研究 Flatpak 和 Snap 应用商店中出现的一组匹配应用程序时,我们经常发现策略不匹配:例如,Flatpak 版本具有 Snap 版本所没有的广泛特权(例如文件访问权限),反之亦然。这项工作让人们相信 Flatpak 和 Snap 可以提高 Linux 平台的安全性,同时强调改进的机会。
Desktop operating systems, including macOS, Windows 10, and Linux, are adopting the application-based security model pervasive in mobile platforms. In Linux, this transition is part of the movement towards two distribution-independent application platforms: Flatpak and Snap. This paper provides the first analysis of sandbox policies defined for Flatpak and Snap applications, covering 283 applications contained in both platforms. First, we find that 90.1% of Snaps and 58.3% of Flatpak applications studied are contained by tamperproof sandboxes. Further, we find evidence that package maintainers actively attempt to define least-privilege application policies. However, defining policy is difficult and error-prone. When studying the set of matching applications that appear in both Flatpak and Snap app stores, we frequently found policy mismatches: e.g., the Flatpak version has a broad privilege (e.g., file access) that the Snap version does not, or vice versa. This work provides confidence that Flatpak and Snap improve Linux platform security while highlighting opportunities for improvement.
Linux 发行版中的软件包新鲜度
DOI: --
发表时间: 2020
期刊: IEEE International Conference on Software Maintenance and Evolution
影响因子: --
作者:
Damien Legay;Alexandre Decan;T. Mens
通讯作者: T. Mens
照照镜子:对包管理器的攻击
DOI: 10.1145/1455770.1455841
发表时间: 2008
期刊: Proceedings of the 15th ACM conference on Computer and communications security
影响因子: --
作者:
Justin Cappos;Justin Samuel;S. Baker;J. Hartman
通讯作者: J. Hartman
DOI: --
发表时间: 2012-08
期刊: --
影响因子: --
作者:
A. Felt;Serge Egelman;Matthew Finifter;Devdatta Akhawe;D. Wagner
通讯作者: A. Felt;Serge Egelman;Matthew Finifter;Devdatta Akhawe;D. Wagner
DOI: --
发表时间: 2017
期刊: International Conference on Computer Systems and Technologies
影响因子: --
作者:
S. Laurén;Sampsa Rauti;Ville Leppänen
通讯作者: Ville Leppänen