SoK: Software Compartmentalization
Fuente:
arXiv
Saved in:
| Main Authors: | Lefeuvre, Hugo, Dautenhahn, Nathan, Chisnall, David, Olivier, Pierre |
|---|---|
| Format: | Preprint |
| Published: |
2024
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Securing Monolithic Kernels using Compartmentalization
by: Lim, Soo Yee, et al.
Published: (2024)
by: Lim, Soo Yee, et al.
Published: (2024)
BULKHEAD: Secure, Scalable, and Efficient Kernel Compartmentalization with PKS
by: Guo, Yinggang, et al.
Published: (2024)
by: Guo, Yinggang, et al.
Published: (2024)
B-Side: Binary-Level Static System Call Identification
by: Thévenon, Gaspard, et al.
Published: (2024)
by: Thévenon, Gaspard, et al.
Published: (2024)
When eBPF Meets Machine Learning: On-the-fly OS Kernel Compartmentalization
by: Wang, Zicheng, et al.
Published: (2024)
by: Wang, Zicheng, et al.
Published: (2024)
Pomegranate: A Lightweight Compartmentalization Architecture using Virtualization Extensions
by: Raja, Shriram, et al.
Published: (2026)
by: Raja, Shriram, et al.
Published: (2026)
Contextualizing Security and Privacy of Software-Defined Vehicles: A Literature Review and Industry Perspectives
by: De Vincenzi, Marco, et al.
Published: (2024)
by: De Vincenzi, Marco, et al.
Published: (2024)
Bomfather: An eBPF-based Kernel-level Monitoring Framework for Accurate Identification of Unknown, Unused, and Dynamically Loaded Dependencies in Modern Software Supply Chains
by: Srinivasan, Naveen, et al.
Published: (2025)
by: Srinivasan, Naveen, et al.
Published: (2025)
SoK: Trusted Execution in SoC-FPGAs
by: Perkins, Garrett, et al.
Published: (2025)
by: Perkins, Garrett, et al.
Published: (2025)
CAEC: Confidential, Attestable, and Efficient Inter-CVM Communication with Arm CCA
by: Abdollahi, Sina, et al.
Published: (2025)
by: Abdollahi, Sina, et al.
Published: (2025)
AgenTEE: Confidential LLM Agent Execution on Edge Devices
by: Abdollahi, Sina, et al.
Published: (2026)
by: Abdollahi, Sina, et al.
Published: (2026)
UPSS: a User-centric Private Storage System with its applications
by: Bozorgi, Arastoo, et al.
Published: (2024)
by: Bozorgi, Arastoo, et al.
Published: (2024)
Retrofitting XoM for Stripped Binaries without Embedded Data Relocation
by: Luo, Chenke, et al.
Published: (2024)
by: Luo, Chenke, et al.
Published: (2024)
The HitchHiker's Guide to High-Assurance System Observability Protection with Efficient Permission Switches
by: Zhang, Chuqi, et al.
Published: (2024)
by: Zhang, Chuqi, et al.
Published: (2024)
Beyond Control: Exploring Novel File System Objects for Data-Only Attacks on Linux Systems
by: Zhou, Jinmeng, et al.
Published: (2024)
by: Zhou, Jinmeng, et al.
Published: (2024)
CRISP: Confidentiality, Rollback, and Integrity Storage Protection for Confidential Cloud-Native Computing
by: Hartono, Ardhi Putra Pratama, et al.
Published: (2024)
by: Hartono, Ardhi Putra Pratama, et al.
Published: (2024)
Fight Hardware with Hardware: System-wide Detection and Mitigation of Side-Channel Attacks using Performance Counters
by: Carnà, Stefano, et al.
Published: (2024)
by: Carnà, Stefano, et al.
Published: (2024)
Blindfold: Confidential Memory Management by Untrusted Operating System
by: Li, Caihua, et al.
Published: (2024)
by: Li, Caihua, et al.
Published: (2024)
Physical Memory Attacks and a Memory Safe Management System for Memory Defense
by: Hillel-Tuch, Alon, et al.
Published: (2024)
by: Hillel-Tuch, Alon, et al.
Published: (2024)
SafeBPF: Hardware-assisted Defense-in-depth for eBPF Kernel Extensions
by: Lim, Soo Yee, et al.
Published: (2024)
by: Lim, Soo Yee, et al.
Published: (2024)
/dev/SDB: Software Defined Boot -- A novel standard for diskless booting anywhere and everywhere
by: Mitra, Aditya, et al.
Published: (2026)
by: Mitra, Aditya, et al.
Published: (2026)
Sharing is caring: Attestable and Trusted Workflows out of Distrustful Components
by: Sadi, Amir Al, et al.
Published: (2026)
by: Sadi, Amir Al, et al.
Published: (2026)
Rethinking Provenance Completeness with a Learning-Based Linux Scheduler
by: Mao, Jinsong, et al.
Published: (2025)
by: Mao, Jinsong, et al.
Published: (2025)
WebAssembly Based Portable and Secure Sensor Interface for Internet of Things
by: Ou, Botong, et al.
Published: (2026)
by: Ou, Botong, et al.
Published: (2026)
Plug. Play. Persist. Inside a Ready-to-Go Havoc C2 Infrastructure
by: Di Santo, Alessio
Published: (2025)
by: Di Santo, Alessio
Published: (2025)
The Android Platform Security Model (2023)
by: Mayrhofer, René, et al.
Published: (2019)
by: Mayrhofer, René, et al.
Published: (2019)
Case Study: Securing MMU-less Linux Using CHERI
by: Almatary, Hesham, et al.
Published: (2023)
by: Almatary, Hesham, et al.
Published: (2023)
Automatic ISA analysis for Secure Context Switching
by: Kalani, Neelu S., et al.
Published: (2025)
by: Kalani, Neelu S., et al.
Published: (2025)
To Unpack or Not to Unpack: Living with Packers to Enable Dynamic Analysis of Android Apps
by: Asghari, Mohammad Hossein, et al.
Published: (2025)
by: Asghari, Mohammad Hossein, et al.
Published: (2025)
Sync+Sync: A Covert Channel Built on fsync with Storage
by: Jiang, Qisheng, et al.
Published: (2023)
by: Jiang, Qisheng, et al.
Published: (2023)
Goldilocks Isolation: High Performance VMs with Edera
by: Moore, Marina, et al.
Published: (2025)
by: Moore, Marina, et al.
Published: (2025)
Security, extensibility, and redundancy in the Metabolic Operating System
by: King, Samuel T.
Published: (2023)
by: King, Samuel T.
Published: (2023)
Sandlock: Confining AI Agent Code with Unprivileged Linux Primitives
by: Wang, Cong, et al.
Published: (2026)
by: Wang, Cong, et al.
Published: (2026)
Lazarus Group Targets Crypto-Wallets and Financial Data while employing new Tradecrafts
by: Di Santo, Alessio
Published: (2025)
by: Di Santo, Alessio
Published: (2025)
OAMAC: Origin-Aware Mandatory Access Control for Practical Post-Compromise Attack Surface Reduction
by: Mohammed, Omer Abdelmajeed Idris, et al.
Published: (2026)
by: Mohammed, Omer Abdelmajeed Idris, et al.
Published: (2026)
Exploiting Page Faults for Covert Communication
by: Swaminathan, Sathvik
Published: (2025)
by: Swaminathan, Sathvik
Published: (2025)
Evolution of Android's Permission-based Security Model and Challenges
by: Solanki, Rajendra Kumar, et al.
Published: (2026)
by: Solanki, Rajendra Kumar, et al.
Published: (2026)
NecoFuzz: Effective Fuzzing of Nested Virtualization via Fuzz-Harness Virtual Machines
by: Ishii, Reima, et al.
Published: (2025)
by: Ishii, Reima, et al.
Published: (2025)
pokiSEC: A Multi-Architecture, Containerized Ephemeral Malware Detonation Sandbox
by: Avina, Alejandro, et al.
Published: (2025)
by: Avina, Alejandro, et al.
Published: (2025)
Adaptive and Efficient Dynamic Memory Management for Hardware Enclaves
by: Dhanraj, Vijay, et al.
Published: (2025)
by: Dhanraj, Vijay, et al.
Published: (2025)
Ringmaster: How to juggle high-throughput host OS system calls from TrustZone TEEs
by: Habeeb, Richard, et al.
Published: (2026)
by: Habeeb, Richard, et al.
Published: (2026)
Similar Items
-
Securing Monolithic Kernels using Compartmentalization
by: Lim, Soo Yee, et al.
Published: (2024) -
BULKHEAD: Secure, Scalable, and Efficient Kernel Compartmentalization with PKS
by: Guo, Yinggang, et al.
Published: (2024) -
B-Side: Binary-Level Static System Call Identification
by: Thévenon, Gaspard, et al.
Published: (2024) -
When eBPF Meets Machine Learning: On-the-fly OS Kernel Compartmentalization
by: Wang, Zicheng, et al.
Published: (2024) -
Pomegranate: A Lightweight Compartmentalization Architecture using Virtualization Extensions
by: Raja, Shriram, et al.
Published: (2026)