Sandboxing Adoption in Open Source Ecosystems

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Alhindi, Maysara, Hallett, Joseph
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910443913609216
author Alhindi, Maysara
Hallett, Joseph
author_facet Alhindi, Maysara
Hallett, Joseph
contents Sandboxing mechanisms allow developers to limit how much access applications have to resources, following the least-privilege principle. However, it's not clear how much and in what ways developers are using these mechanisms. This study looks at the use of Seccomp, Landlock, Capsicum, Pledge, and Unveil in all packages of four open-source operating systems. We found that less than 1% of packages directly use these mechanisms, but many more indirectly use them. Examining how developers apply these mechanisms reveals interesting usage patterns, such as cases where developers simplify their sandbox implementation. It also highlights challenges that may be hindering the widespread adoption of sandboxing mechanisms.
format Preprint
id arxiv_https___arxiv_org_abs_2405_06447
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Sandboxing Adoption in Open Source Ecosystems
Alhindi, Maysara
Hallett, Joseph
Software Engineering
Cryptography and Security
Sandboxing mechanisms allow developers to limit how much access applications have to resources, following the least-privilege principle. However, it's not clear how much and in what ways developers are using these mechanisms. This study looks at the use of Seccomp, Landlock, Capsicum, Pledge, and Unveil in all packages of four open-source operating systems. We found that less than 1% of packages directly use these mechanisms, but many more indirectly use them. Examining how developers apply these mechanisms reveals interesting usage patterns, such as cases where developers simplify their sandbox implementation. It also highlights challenges that may be hindering the widespread adoption of sandboxing mechanisms.
title Sandboxing Adoption in Open Source Ecosystems
topic Software Engineering
Cryptography and Security
url https://arxiv.org/abs/2405.06447