Open AccessJournal Article
SoftwarePot: An encapsulated transferable file system for secure software circulation
Kazuhiko Katol,Yoshihiro Oyama +1 more
25
TL;DR: In this paper, a general approach to enable secure circulation of software in an open network environment such as the Internet is presented, where software can be transferred even in an iterative manner such as through redistribution or using mobile agents.
read more
Abstract: We have developed a general approach to enable secure circulation of software in an open network environment such as the Internet. By software circulation, we mean a generalized conventional software distribution concept in which software can be transferred even in an iterative manner such as through redistribution or using mobile agents. To clarify the problem that arises when software is circulated in an open network environment, we first considered a simple model for unsecure software circulation and then developed a model for secure software circulation (SSC). In the SSC model, we extended the sandbox concept to include its own file system and to have the ability to be transferred via a network. In this sense, our approach is characterized by an encapsulated, transferable file system. We describe how the SoftwarePot system was designed to implement the SSC model, and discuss the implications of experimental results that we obtained during the implementation.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
Isolated program execution: an application transparent approach for executing untrusted programs
Zhenkai Liang,V. N. Venkatakrishnan,R. C. Sekar +2 more
- 08 Dec 2003
TL;DR: Key benefits of this approach are that it requires no changes to the untrusted programs (to be isolated) or the underlying operating system; it cannot be subverted by malicious programs; and it achieves these benefits with acceptable runtime overheads.
112
The state of the art of application restrictions and sandboxes
TL;DR: The motivation for application restrictions and sandboxes is described, presenting an in-depth review of the literature covering existing systems, and recommendations for usability and abstraction are considered to be considered to a further extent when designing application-oriented access controls.
29
Alcatraz: An Isolated Environment for Experimenting with Untrusted Software
TL;DR: This article develops two different implementation approaches, one in user-land and the other in the OS kernel, for realizing a safe-execution environment that enables users to “try out” new software without the fear of damaging the system in any manner.
A Virtual Machine Migration System Based on a CPU Emulator
Koichi Onoue,Yoshihiro Oyama,Akinori Yonezawa +2 more
- 17 Nov 2006
TL;DR: This paper describes Quasar, a virtual machine (VM) migration system implemented on top of the QEMU CPU emulator, and examines the viability of Quasar through experiments, in which Quasar was compared with Xen, SBUML, and UML.
19
Expanding Malware Defense by Securing Software Installations
Weiqing Sun,R. C. Sekar,Zhenkai Liang,V. N. Venkatakrishnan +3 more
- 10 Jul 2008
TL;DR: A simple policy is presented that can be used to prevent untrusted software from modifying any of the files used by benign software packages, thus blocking the most common mechanism used by malware to ensure that it is run automatically after each system reboot.
References
•Book
Cryptography and Network Security: Principles and Practice
William Stallings
- 19 Aug 1998
TL;DR: The new edition of William Stallings' Cryptography and Network Security: Principles and Practice, 5e is a practical survey of cryptography and network security with unmatched support for instructors and students.
5.6K
Efficient software-based fault isolation
Robert Wahbe,Steven Lucco,Thomas Anderson,Susan L. Graham +3 more
- 01 Dec 1993
TL;DR: It is demonstrated that for frequently communicating modules, implementing fault isolation in software rather than hardware can substantially improve end-to-end application performance.
UFO: a personal global file system based on user-level extensions to the operating system
TL;DR: The article gives a detailed performance analysis of the approach to extending the OS and establishes that Ufo introduces acceptable overhead for common applications even though intercepting individual system calls incurs a high cost.
89
A new dimension for the UNIX file system
D. G. Korn,E. Krell +1 more
TL;DR: The concept of viewpathing is introduced followed by a description of the second component of the 3‐D file system, transparent viewPathing, and the implementation and future directions are described.
51
A flexible security system for using Internet content
TL;DR: FlexxGuard is a flexible interpreter that dynamically derives protection domains and uses those domains to authorize content operations, to contend with the risks of downloading content from the Internet.
50