| C. Cowan, S. Beattie, C. Pu, P. Wagle, and V. Gligor. SubDomain: Parsimonious Security for Server Appliances. In Proceedings of the 14th USENIX System Administration Conference (LISA 2000. |
....Systems like Janus [10] Consh [2] and Mapbox [1] operate at user level and confine applications by filtering access to system calls. To accomplish this they rely on ptrace(2) the proc file system, and special shared libraries. Another category of systems like Tron [5] SubDomain [8] and others go a step further. They intercept system calls inside the kernel and use policy engines to decide whether to permit the call or not. Our architecture focuses on separation of policy enforcement and specification, and support for distributed compartmentalized services. Capabilities and ....
C. Cowan, S. Beattie, C. Pu, P. Wagle, and V. Gligor. SubDomain: Parsimonious Security for Server Appliances. In Proceedings of the 14th USENIX System Administration Conference (LISA 2000.
....for prefetching data, so as to improve the performance of a confined application. This is in stark contrast to the usual security mechanism, which measures performance impacts entirely in terms of added costs. Extensive additional documentation on SubDomain is available in this white paper [3] available by request from WireX. CryptoMark: CryptoMark is a kernel enhancement to detect and reject Trojan Horse programs through cryptographic signatures. WireX cryptographically signs all of the programs on the system that need to run at a given trust level (e.g. programs that need to run as ....
Crispin Cowan, Steve Beattie, Calton Pu, Perry Wagle, and Virgil Gligor. SubDomain: Parsimonious Security for Server Appliances. March 2000.
....for prefetching data, so as to improve the performance of a confined application. This is in stark contrast to the usual security mechanism, which measures performance impacts entirely in terms of added costs. Extensive additional documentation on SubDomain is available in this white paper [3] available by request from WireX. CryptoMark: CryptoMark is a kernel enhancement to detect and reject Trojan Horse programs through cryptographic signatures. WireX cryptographically signs all of the programs on the system that need to run at a given trust level (e.g. programs that need to run as ....
Crispin Cowan, Steve Beattie, Calton Pu, Perry Wagle, and Virgil Gligor. SubDomain: Parsimonious Security for Server Appliances. March 2000.
No context found.
C. Cowan, S. Beattie, C. Pu, P. Wagle, and V. Gligor. SubDomain: Parsimonious Security for Server Appliances. In Proceedings of the 14th USENIX System Administration Conference (LISA 2000.
No context found.
C. Cowan, S. Beattie, C. Pu, P. Wagle, and V. Gligor. SubDomain: Parsimonious Security for Server Appliances. In Proceedings of the 14th USENIX System Administration Conference (LISA 2000.
No context found.
C. Cowan, S. Beattie, C. Pu, P. Wagle, and V. Gligor. SubDomain: Parsimonious Security for Server Appliances. In Proceedings of the 14th USENIX System Administration Conference (LISA 2000.
No context found.
C. Cowan, S. Beattie, C. Pu, P. Wagle, and V. Gligor. SubDomain: Parsimonious Security for Server Appliances. In Proceedings of the 14th USENIX System Administration Conference (LISA 2000.
No context found.
Crispin Cowan, Steve Beattie, Calton Pu, Perry Wagle, and Virgil Gligor. Subdomain: Parsimonious security for server appliances. In 14th USENIX System Administration Conference (LISA 2000.
No context found.
C. Cowan, S. Beattie, C. Pu, P. Wagle, and V. Gligor. SubDomain: Parsimonious Security for Server Appliances. In Proceedings of the 14th USENIX System Administration Conference (LISA 2000), March 2000.
No context found.
Cowan, Crispin, Beattie, Steve, Pu, Calton, Wagle, Perry, and Gligor, Virgil (2000). SubDomain: Parsimonious Security for Server Appliances. In Proceedings of the 14th USENIX System Administration Conference.
Online articles have much greater impact More about CiteSeer.IST Add search form to your site Submit documents Feedback
CiteSeer.IST - Copyright Penn State and NEC