摘要
文中实现了一种基于Linux内核模块的沙箱安全系统。用户可以将Linux系统中的应用程序放置在受控的沙箱中运行 ,将其与系统其它部分隔离 ,从而可以防御潜在的攻击 ;或者当应用程序被攻击时 ,限制入侵者的破坏范围。这个沙箱系统作为Linux内核模块实现 ,可以在不改变原有系统内核和应用程序的情况下部署运行 ,增强了操作系统的安全性能。
This paper illustrates a sandbox system on Linux operating system. Users can put untrusted or flawed programs running in the sandbox system,so they are isolated from other parts of the operating system. It protects the system from application exploits. Thus it greatly improves the system's security level. Deploying this sandbox system needs no modification to existing operating system kernel and applications,because it is implemented as a Linux kernel module.
出处
《计算机应用》
CSCD
北大核心
2004年第1期79-81,共3页
journal of Computer Applications