Attackers often exploit vulnerabilities in network-facing processes to gain access to the rest of the system. To combat this, modern operating systems such as Android, iOS and major Linux distributions allow running vulnerable or untrusted processes inside sandboxes – confined execution environments, where access to resources is restricted according to an implicit or configurable security policy. Major building blocks of sandbox implementations include namespace virtualization, system call interposition and kernel subsystem hooking. In this paper, we survey the state-of-the-art in process sandboxing, focusing on solutions that are widely deployed in consumer devices and cloud servers.
No takes yet. Share an insight, caveat, or question.
Arto Niemi (2024) studied this question.
Synapse has enriched 2 closely related papers on similar clinical questions. Consider them for comparative context: