{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,27]],"date-time":"2025-03-27T04:41:24Z","timestamp":1743050484034,"version":"3.40.3"},"publisher-location":"Cham","reference-count":30,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783031168147"},{"type":"electronic","value":"9783031168154"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-031-16815-4_7","type":"book-chapter","created":{"date-parts":[[2022,9,23]],"date-time":"2022-09-23T20:19:35Z","timestamp":1663964375000},"page":"104-123","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Hybrid Isolation Model for\u00a0Device Application Sandboxing Deployment in\u00a0Zero Trust Architecture"],"prefix":"10.1007","author":[{"given":"Jingci","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jun","family":"Zheng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zheng","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tian","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kefan","family":"Qiu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Quanxin","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuanzhang","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,9,24]]},"reference":[{"key":"7_CR1","unstructured":"Babar, M.A., Ramsey, B.: Understanding container isolation mechanisms for building security-sensitive private cloud. In: The University of Adelaide, Australia (2017)"},{"key":"7_CR2","doi-asserted-by":"crossref","unstructured":"Bell, D.E., La Padula, L.J.: Secure computer system: Unified exposition and multics interpretation. Tech. rep. MITRE CORP BEDFORD MA (1976)","DOI":"10.21236\/ADA023588"},{"key":"7_CR3","unstructured":"Biba, K.J.: Integrity considerations for secure computer systems. Technical report MITRE CORP BEDFORD MA (1977)"},{"key":"7_CR4","doi-asserted-by":"crossref","unstructured":"Brewer, D.F., Nash, M.J: The Chinese wall security policy. In: 1989 IEEE Symposium on Security and Privacy, Oakland, p. 206 (1989)","DOI":"10.1109\/SECPRI.1989.36295"},{"key":"7_CR5","unstructured":"Bui, T.: Analysis of docker security. arXiv preprint arXiv:1501.02967 (2015)"},{"key":"7_CR6","doi-asserted-by":"publisher","first-page":"102496","DOI":"10.1016\/j.cose.2021.102496","volume":"112","author":"R Coulter","year":"2022","unstructured":"Coulter, R., et al.: Domain adaptation for windows advanced persistent threat detection. Comput. Secur. 112, 102496 (2022)","journal-title":"Comput. Secur."},{"key":"7_CR7","unstructured":"Ferraiolo, D., Kuhn, D.R., Chandramouli, R.: Role Based Access Control. Artech House (2003)"},{"issue":"5","key":"7_CR8","doi-asserted-by":"publisher","first-page":"973","DOI":"10.1016\/j.jcss.2014.02.005","volume":"80","author":"J Jang-Jaccard","year":"2014","unstructured":"Jang-Jaccard, J., Nepal, S.: A survey of emerging threats in cybersecurity. J. Comput. Syst. Sci. 80(5), 973\u2013993 (2014)","journal-title":"J. Comput. Syst. Sci."},{"key":"7_CR9","doi-asserted-by":"crossref","unstructured":"Jian, Z., Chen, L.: A defense method against docker escape attack. In: Proceedings of the 2017 International Conference on Cryptography, Security and Privacy, pp. 142\u2013146 (2017)","DOI":"10.1145\/3058060.3058085"},{"key":"7_CR10","unstructured":"Kindervag, J., et al.: Build security into your network\u2019s DNA: the zero trust network architecture, pp. 1\u201326. Forrester Research Inc. (2010)"},{"key":"7_CR11","doi-asserted-by":"crossref","unstructured":"Lin, T.Y.: Chinese wall security policy-an aggressive model. In: 1989 Fifth Annual Computer Security Applications Conference. IEEE Computer Society, pp. 282\u2013283 (1989)","DOI":"10.1109\/CSAC.1989.81064"},{"key":"7_CR12","doi-asserted-by":"crossref","unstructured":"Lu, T., Chen, J.: Research of penetration testing technology in docker environment. In: 2017 5th International Conference on Mechatronics, Materials, Chemistry and Computer Engineering (ICMMCCE 2017), pp. 1354\u20131359. Atlantis Press (2017)","DOI":"10.2991\/icmmcce-17.2017.238"},{"key":"7_CR13","doi-asserted-by":"publisher","first-page":"30","DOI":"10.1016\/j.comcom.2018.03.011","volume":"122","author":"A Martin","year":"2018","unstructured":"Martin, A., et al.: Docker ecosystem-vulnerability analysis. Comput. Commun. 122, 30\u201343 (2018)","journal-title":"Comput. Commun."},{"key":"7_CR14","doi-asserted-by":"crossref","unstructured":"Al-Mawee, W., Carr, S., Mayo, J.: Admonita: a recommendationbased trust model for dynamic data integrity. In: ICISSP, pp. 273\u2013282 (2021)","DOI":"10.5220\/0010150402730282"},{"issue":"2","key":"7_CR15","doi-asserted-by":"publisher","first-page":"67","DOI":"10.1016\/0020-0190(85)90065-1","volume":"20","author":"J McLean","year":"1985","unstructured":"McLean, J.: A comment on the \u2018basic security theorem\u2019 of Bell and LaPadula. Inf. Processing Lett. 20(2), 67\u201370 (1985)","journal-title":"Inf. Processing Lett."},{"key":"7_CR16","doi-asserted-by":"crossref","unstructured":"Mehraj S., Banday, M.T.: Establishing a zero trust strategy in cloud computing environment. In: 2020 International Conference on Computer Communication and Informatics (ICCCI), pp. 1\u20136. IEEE (2020)","DOI":"10.1109\/ICCCI48352.2020.9104214"},{"key":"7_CR17","unstructured":"Mouat, A.: Docker Security: Using Containers Safely in Production. O\u2019Reilly Media (2015)"},{"key":"7_CR18","doi-asserted-by":"crossref","unstructured":"Oleshchuk, V.: Trust-enhanced data integrity model. In: 2012 IEEE 1st International Symposium on Wireless Systems (IDAACS-SWS), pp. 109\u2013112. IEEE (2012)","DOI":"10.1109\/IDAACS-SWS.2012.6377645"},{"issue":"2","key":"7_CR19","doi-asserted-by":"publisher","first-page":"85","DOI":"10.1145\/354876.354878","volume":"3","author":"S Osborn","year":"2000","unstructured":"Osborn, S., Sandhu, R., Munawer, Q.: Configuring role based access control to enforce mandatory and discretionary access control policies. ACM Trans. Inf. Syst. Secur. (TISSEC) 3(2), 85\u2013106 (2000)","journal-title":"ACM Trans. Inf. Syst. Secur. (TISSEC)"},{"issue":"6","key":"7_CR20","doi-asserted-by":"publisher","first-page":"8644","DOI":"10.1007\/s11227-021-04201-9","volume":"78","author":"M Panahnejad","year":"2021","unstructured":"Panahnejad, M., Mirabi, M.: APT-Dt-KC: advanced persistent threat detection based on kill-chain model. J. Supercomput. 78(6), 8644\u20138677 (2021). https:\/\/doi.org\/10.1007\/s11227-021-04201-9","journal-title":"J. Supercomput."},{"key":"7_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"77","DOI":"10.1007\/978-3-319-11599-3_5","volume-title":"Secure IT Systems","author":"E Reshetova","year":"2014","unstructured":"Reshetova, E., Karhunen, J., Nyman, T., Asokan, N.: Security of OS-level virtualization technologies. In: Bernsmed, K., Fischer-H\u00fcbner, S. (eds.) NordSec 2014. LNCS, vol. 8788, pp. 77\u201393. Springer, Cham (2014). https:\/\/doi.org\/10.1007\/978-3-319-11599-3_5"},{"key":"7_CR22","doi-asserted-by":"crossref","unstructured":"Rose, S.W., et al.: Zero trust architecture (2020)","DOI":"10.6028\/NIST.SP.800-207-draft2"},{"key":"7_CR23","unstructured":"Rutkowska, J., Wojtczuk, R.: Qubes OS architecture. In: Invisible Things Lab Technical report, vol. 54 , p. 65 (2010)"},{"key":"7_CR24","doi-asserted-by":"crossref","unstructured":"Es-Salhi, K., Espes, D., Cuppens, N.: DTE access control model for integrated ICS systems. In: Proceedings of the 14th International Conference on Availability, Reliability and Security, pp. 1\u20139 (2019)","DOI":"10.1145\/3339252.3340498"},{"key":"7_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"137","DOI":"10.1007\/3-540-45608-2_3","volume-title":"Foundations of Security Analysis and Design","author":"P Samarati","year":"2001","unstructured":"Samarati, P., de Vimercati, S.C.: Access control: policies, models, and mechanisms. In: Focardi, R., Gorrieri, R. (eds.) FOSAD 2000. LNCS, vol. 2171, pp. 137\u2013196. Springer, Heidelberg (2001). https:\/\/doi.org\/10.1007\/3-540-45608-2_3"},{"key":"7_CR26","doi-asserted-by":"crossref","unstructured":"Sandhu R., Munawer, Q.: How to do discretionary access control using roles. In: Proceedings of the Third ACM Workshop on Role-Based Access Control, pp. 47\u201354 (1998)","DOI":"10.1145\/286884.286893"},{"issue":"11","key":"7_CR27","first-page":"1","volume":"1","author":"WR Shockley","year":"1989","unstructured":"Shockley, W.R.: A9 implementing the Clark\/Wilson integrity policy using current technology. Comput. Sci. Technol. 1(11), 1 (1989)","journal-title":"Comput. Sci. Technol."},{"key":"7_CR28","doi-asserted-by":"crossref","unstructured":"Xu, Q., Liu, G.: Configuring Clark-Wilson integrity model to enforce flexible protection. In: 2009 International Conference on Computational Intelligence and Security, vol. 2, pp. 15\u201320. IEEE (2009)","DOI":"10.1109\/CIS.2009.249"},{"issue":"1","key":"7_CR29","doi-asserted-by":"crossref","DOI":"10.1088\/1361-6471\/ac9e0f","volume":"1871","author":"B Zhao","year":"2021","unstructured":"Zhao, B., et al.: Research on container-oriented isolation control technology. J. Phys.: Conf. Ser. 1871(1), 012016 (2021)","journal-title":"J. Phys.: Conf. Ser."},{"key":"7_CR30","unstructured":"Zhao L., et al.: A lightweight isolation mechanism for secure branch predictors. arXiv preprint arXiv:2005.08183 (2020)"}],"container-title":["Lecture Notes in Computer Science","Applied Cryptography and Network Security Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-16815-4_7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,15]],"date-time":"2025-03-15T13:09:18Z","timestamp":1742044158000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-16815-4_7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783031168147","9783031168154"],"references-count":30,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-16815-4_7","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"24 September 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ACNS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Applied Cryptography and Network Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Rome","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Italy","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20 June 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23 June 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"acns2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/sites.google.com\/di.uniroma1.it\/acns2022\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}