Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                
skip to main content
10.1109/WAINA.2013.81guideproceedingsArticle/Chapter ViewAbstractPublication PagesConference Proceedingsacm-pubtype
Article

Improvements the Seccomp Sandbox Based on PBE Theory

Published: 25 March 2013 Publication History

Abstract

Providing a safe computing condition to unknown user is a crucial task in the existing network computing, and usually we can use the sandbox technology to shield security issues, but the behavior of malicious-occupying the resource has not been well controlled in the sandbox. In this passage, permission rate to access the computational efficiency and accuracy can be available by improving the Linux Kernel Secure Computing Mode(Seccomp) System, furthermore using the system calls judgment technology to prevent its malicious acts from user code can protect the system. During the calculations procedure, specifically, the improved Perfect Bayesian Equilibrium (PBE) Algorithm can be used to determine user behavior in system-call process, utilize this algorithm to construct policy engine, and use the engine decision-making engine to decide existing users' behavior as a result to maximize the profits of both the user code operating and server system capacity. Moreover agent technology that works in achieving the interrupted determination and interrupted access separate the computing and operating systems simultaneously. After all, improving sandbox technology is to achieve the relative optimization between the user service efficiency and security guarantees. Finally, the experiments show that compared with the Sandboxie and Buffer Zone technology, the proposed algorithm optimizes the consumption of the system resources in the original Seccomp Sandbox, and its access determine in rate also speeds up in the certain degree. In particular, it can effectively prevent special system call from malicious code, which can protect the system mainly in large extent. Moreover, the testing speed and the performance of several regular system calls such as file access operation, write operation also are under the progressive improvement.

Cited By

View all
  • (2017)SandcrustProceedings of the 9th Workshop on Programming Languages and Operating Systems10.1145/3144555.3144562(51-57)Online publication date: 28-Oct-2017

Recommendations

Comments

Information & Contributors

Information

Published In

cover image Guide Proceedings
WAINA '13: Proceedings of the 2013 27th International Conference on Advanced Information Networking and Applications Workshops
March 2013
1656 pages
ISBN:9780769549521

Publisher

IEEE Computer Society

United States

Publication History

Published: 25 March 2013

Author Tags

  1. Perfect Bayesian Equilibrium (PBE) algorithm
  2. Sandbox
  3. Seccomp
  4. Virtualization Technology

Qualifiers

  • Article

Contributors

Other Metrics

Bibliometrics & Citations

Bibliometrics

Article Metrics

  • Downloads (Last 12 months)0
  • Downloads (Last 6 weeks)0
Reflects downloads up to 01 Jan 2025

Other Metrics

Citations

Cited By

View all
  • (2017)SandcrustProceedings of the 9th Workshop on Programming Languages and Operating Systems10.1145/3144555.3144562(51-57)Online publication date: 28-Oct-2017

View Options

View options

Media

Figures

Other

Tables

Share

Share

Share this Publication link

Share on social media