A Taste of Capsicum: Practical Capabilities for UNIX.

Capsicum is a lightweight operating system (OS) capability and sandbox framework planned for inclusion in FreeBSD 9. Capsicum extends, rather than replaces, UNIX APIs, providing new kernel primitives (sandboxed capability mode and capabilities) and a userspace sandbox API. These tools support decomp...

Descripción completa

Detalles Bibliográficos
Publicado en:Communications of the ACM Vol. 55; no. 3; pp. 97 - 105
Formato: Artículo
Publicado: Association for Computing Machinery Mar2012
Materias:
Acceso en línea:Ver este registro en EBSCOhost
fields @attributes:
  recordID: 1
pdfLink:
plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=73047268&site=ehost-live
header:
  @attributes:
    shortDbName: hlh
    uiTerm: 73047268
    longDbName: Humanities International Complete
    uiTag: AN
  controlInfo:
    bkinfo:
    jinfo:
      jid:
        00010782
        ACM
      jtl: Communications of the ACM
      issn: 00010782
      maglogo: N
    pubinfo:
      dt: Mar2012
      vid: 55
      iid: 3
      pid: 68
      pub: Association for Computing Machinery
    artinfo:
      ui:
        73047268
        10.1145/2093548.2093572
      ppf: 97
      ppct: 8
      formats:
      tig:
        atl: A Taste of Capsicum: Practical Capabilities for UNIX.
      aug:
      su:
        Computer operating systems
        Unix operating systems
        Application program interfaces
        Kernel functions
        Web browsers
        Sandboxes (Computer science)
      sug:
        subj:
          Computer operating systems
          Unix operating systems
          Application program interfaces
          Kernel functions
          Web browsers
          Sandboxes (Computer science)
      ab: Capsicum is a lightweight operating system (OS) capability and sandbox framework planned for inclusion in FreeBSD 9. Capsicum extends, rather than replaces, UNIX APIs, providing new kernel primitives (sandboxed capability mode and capabilities) and a userspace sandbox API. These tools support decomposition of monolithic UNIX applications into compartmentalized logical applications, an increasingly common goal that is supported poorly by existing OS access control primitives. We demonstrate our approach by adapting core FreeBSD utilities and Google’s Chromium Web browser to use Capsicum primitives, and compare the complexity and robustness of Capsicum with other sandboxing techniques.
      pubtype: Periodical
      doctype: Article
      src: R
    language: English
    refInfo:
    copyright:
      @attributes:
        flag: Y
      dt:
        @attributes:
          year: 2012
    holdings:
      @attributes:
        islocal: N