Publication | Closed Access
Labels and event processes in the asbestos operating system
331
Citations
36
References
2005
Year
Event-driven ArchitectureEngineeringUsable SecurityInformation SecuritySoftware EngineeringSoftware AnalysisAsbestos Operating SystemAccess ControlIsolation MechanismsTrusted Operating SystemRadiologyEvent ProcessingChemical HazardOperating System SecurityData PrivacyComputer ScienceWeb ServerSoftware DesignData SecurityAsbestos LabelsOperating SystemsOccupational HygieneSystem Software
Asbestos, a new prototype operating system, provides novel labeling and isolation mechanisms that help contain the effects of exploitable software flaws. Applications can express a wide range of policies with Asbestos's kernel-enforced label mechanism, including controls on inter-process communication and system-wide information flow. A new event process abstraction provides lightweight, isolated contexts within a single process, allowing the same process to act on behalf of multiple users while preventing it from leaking any single user's data to any other user. A Web server that uses Asbestos labels to isolate user data requires about 1.5 memory pages per user, demonstrating that additional security can come at an acceptable cost.
| Year | Citations | |
|---|---|---|
Page 1
Page 1