Capsicum: practical capabilities for UNIX

Communications of the ACM(2010)

引用 250|浏览3
暂无评分
摘要
Capsicum is a lightweight operating system capability and sandbox framework planned for inclusion in FreeBSD 9. Capsicum extends, rather than replaces, UNIX APIs, providing new kernel primitives (sandboxed capability mode and capabilities) and a userspace sandbox API. These tools support compartmentalisation of monolithic UNIX applications into logical applications, an increasingly common goal supported poorly by discretionary and mandatory access control. We demonstrate our approach by adapting core FreeBSD utilities and Google's Chromium web browser to use Capsicum primitives, and compare the complexity and robustness of Capsicum with other sandboxing techniques.
更多
查看译文
关键词
common goal,monolithic unix application,userspace sandbox,sandbox framework,chromium web browser,lightweight operating system capability,capsicum primitive,core freebsd utility,unix apis,practical capability,sandboxed capability mode
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要