Skip to main navigation Skip to search Skip to main content

A portable user-level approach for system-wide integrity protection

  • Stony Brook University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

5 Scopus citations

Abstract

In this paper, we develop an approach for protecting system integrity from untrusted code that may harbor sophisticated malware. We develop a novel dual-sandboxing architecture to confine not only untrusted, but also benign processes. Our sandboxes place only a few restrictions, thereby permitting most applications to function normally. Our implementation is performed entirely at the user-level, requiring no changes to the kernel. This enabled us to port the system easily from Linux to BSD. Our experimental results show that our approach preserves the usability of applications, while offering strong protection and good performance. Moreover, policy development is almost entirely automated, sparing users and administrators this cumbersome and difficult task.

Original languageEnglish
Title of host publicationProceedings - 29th Annual Computer Security Applications Conference, ACSAC 2013
Pages219-228
Number of pages10
DOIs
StatePublished - 2013
Event29th Annual Computer Security Applications Conference, ACSAC 2013 - New Orleans, LA, United States
Duration: Dec 9 2013Dec 13 2013

Publication series

NameACM International Conference Proceeding Series

Conference

Conference29th Annual Computer Security Applications Conference, ACSAC 2013
Country/TerritoryUnited States
CityNew Orleans, LA
Period12/9/1312/13/13

Fingerprint

Dive into the research topics of 'A portable user-level approach for system-wide integrity protection'. Together they form a unique fingerprint.

Cite this