EngineeringInformation SecuritySoftware EngineeringSoftware AnalysisFormal VerificationHardware SecuritySafe Kernel ProgrammingTrusted CompilerTrusted Execution EnvironmentCompilersTrusted Operating SystemOperating System SecurityComputer EngineeringComputer ScienceLanguage-based SecurityLanguage CustomisationData SecuritySoftware SecurityOperating SystemsProgram AnalysisTrust ManagementUnikernelsSystem Software
This paper describes the implementation of the OKE, which allows users other than root to load native and fully optimised code in the Linux kernel. Safety is guaranteed by trust management, language customisation and a trusted compiler. By coupling trust management with the compiler, the OKE is able to vary the level of restrictions on the code running in the kernel, depending on the programmer's privileges. Static sandboxing is used as much as possible to check adherence to the security policies at compile time.
10
Efficient software-based fault isolation
Robert Wahbe, Steven Lucco, Thomas E. Anderson et al. · 1993 · 1.2K citations · Full text
Software Maintenance, Engineering, Computer Architecture +19
Extensibility safety and performance in the SPIN operating system
Brian N. Bershad, Stefan Savage, Przemysław Pardyak et al. · 1995 · 949 citations
The BSD packet filter: a new architecture for user-level packet capture
Steven McCanne, Van Jacobson · 1993 · 869 citations
Trevor Jim, J. Greg Morrisett, Dan Grossman et al. · 2002 · 617 citations