{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,6]],"date-time":"2026-06-06T14:35:09Z","timestamp":1780756509730,"version":"3.54.1"},"publisher-location":"Cham","reference-count":20,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031763700","type":"print"},{"value":"9783031763717","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,12,21]],"date-time":"2024-12-21T00:00:00Z","timestamp":1734739200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,12,21]],"date-time":"2024-12-21T00:00:00Z","timestamp":1734739200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-76371-7_7","type":"book-chapter","created":{"date-parts":[[2024,12,20]],"date-time":"2024-12-20T07:45:02Z","timestamp":1734680702000},"page":"97-109","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Flexible and\u00a0Secure Process Confinement with\u00a0eBPF"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8949-2221","authenticated-orcid":false,"given":"Carlo","family":"Mazzocca","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1294-0043","authenticated-orcid":false,"given":"Andrea","family":"Garbugli","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michele","family":"Armillotta","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3687-0361","authenticated-orcid":false,"given":"Rebecca","family":"Montanari","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0992-7948","authenticated-orcid":false,"given":"Paolo","family":"Bellavista","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,12,21]]},"reference":[{"key":"7_CR1","doi-asserted-by":"publisher","unstructured":"Abbadini, M., Facchinetti, D., Oldani, G., Rossi, M., Paraboschi, S.: Cage4deno: a fine-grained sandbox for deno subprocesses. In: Proceedings of the 2023 ACM Asia Conference on Computer and Communications Security, ASIA CCS 2023, pp. 149\u2013162. Association for Computing Machinery, New York (2023). https:\/\/doi.org\/10.1145\/3579856.3595799","DOI":"10.1145\/3579856.3595799"},{"issue":"3","key":"7_CR2","doi-asserted-by":"publisher","first-page":"197","DOI":"10.1007\/s12243-019-00703-z","volume":"74","author":"MM Bazm","year":"2019","unstructured":"Bazm, M.M., Lacoste, M., S\u00fcdholt, M., Menaud, J.M.: Isolation in cloud computing infrastructures: new security challenges. Ann. Telecommun. 74(3), 197\u2013209 (2019)","journal-title":"Ann. Telecommun."},{"key":"7_CR3","doi-asserted-by":"publisher","unstructured":"B\u00e9lair, M., Laniepce, S., Menaud, J.M.: Snappy: programmable kernel-level policies for containers. In: Proceedings of the 36th Annual ACM Symposium on Applied Computing, SAC 221, pp. 1636\u20131645. Association for Computing Machinery, New York (2021). https:\/\/doi.org\/10.1145\/3412841.3442037","DOI":"10.1145\/3412841.3442037"},{"key":"7_CR4","doi-asserted-by":"publisher","unstructured":"Brimhall, B., Garrard, J., De\u00a0La\u00a0Garza, C., Coffman, J.: A comparative analysis of linux mandatory access control policy enforcement mechanisms. In: Proceedings of the 16th European Workshop on System Security, EUROSEC 2023, pp. 1\u20137. Association for Computing Machinery, New York (2023). https:\/\/doi.org\/10.1145\/3578357.3589454","DOI":"10.1145\/3578357.3589454"},{"key":"7_CR5","unstructured":"Connor, R.J., McDaniel, T., Smith, J.M., Schuchard, M.: PKU pitfalls: attacks on pku-based memory isolation systems. In: 29th USENIX Security Symposium (USENIX Security 2020), pp. 1409\u20131426. USENIX Association (2020). https:\/\/www.usenix.org\/conference\/usenixsecurity20\/presentation\/connor"},{"key":"7_CR6","doi-asserted-by":"publisher","unstructured":"Dejaeghere, J., Gbadamosi, B., Pulls, T., Rochet, F.: Comparing security in eBPF and WebAssembly. In: Proceedings of the 1st Workshop on EBPF and Kernel Extensions, eBPF 2023, pp. 35\u201341. Association for Computing Machinery, New York (2023). https:\/\/doi.org\/10.1145\/3609021.3609306","DOI":"10.1145\/3609021.3609306"},{"key":"7_CR7","unstructured":"eBPF Documentation: eBPF (2024). https:\/\/ebpf.io\/ . Accessed 2 May 2024"},{"key":"7_CR8","unstructured":"Findlay, W., Barrera, D., Somayaji, A.: Bpfcontain: fixing the soft underbelly of container security. arXiv preprint arXiv:2102.06972 (2021)"},{"key":"7_CR9","doi-asserted-by":"publisher","unstructured":"Findlay, W., Somayaji, A., Barrera, D.: bpfbox: simple precise process confinement with eBPF. In: Proceedings of the 2020 ACM SIGSAC Conference on Cloud Computing Security Workshop, CCSW 2020, pp. 91\u2013103. Association for Computing Machinery, New York (2020). https:\/\/doi.org\/10.1145\/3411495.3421358","DOI":"10.1145\/3411495.3421358"},{"key":"7_CR10","unstructured":"Fried, J., et al.: Making Kernel bypass practical for the cloud with junction. In: 21st USENIX Symposium on Networked Systems Design and Implementation (NSDI 2024), pp. 55\u201373 (2024)"},{"key":"7_CR11","doi-asserted-by":"publisher","unstructured":"Hung, H.W., Liu, Y., Sani, A.A.: Sifter: protecting security-critical kernel modules in Android through attack surface reduction. In: Proceedings of the 28th Annual International Conference on Mobile Computing And Networking, MobiCom 2022, pp. 623\u2013635. Association for Computing Machinery, New York (2022). https:\/\/doi.org\/10.1145\/3495243.3560548","DOI":"10.1145\/3495243.3560548"},{"key":"7_CR12","unstructured":"Jia, J., et al.: Programmable system call security with ebpf. arXiv preprint arXiv:2302.10366 (2023)"},{"key":"7_CR13","unstructured":"Kernel, T.L.: Seccomp BPF (SECure COMPuting with filters) (2024). https:\/\/www.kernel.org\/doc\/html\/v4.19\/userspace-api\/seccomp_filter.html. Accessed 2 May 2024"},{"key":"7_CR14","doi-asserted-by":"publisher","unstructured":"Miano, S., Bertrone, M., Risso, F., Tumolo, M., Bernal, M.V.: Creating complex network services with eBPF: experience and lessons learned. In: 2018 IEEE 19th International Conference on High Performance Switching and Routing (HPSR), pp.\u00a01\u20138 (2018). https:\/\/doi.org\/10.1109\/HPSR.2018.8850758","DOI":"10.1109\/HPSR.2018.8850758"},{"key":"7_CR15","unstructured":"manual page, L.: seccomp(2) (2024). https:\/\/man7.org\/linux\/man-pages\/man2\/seccomp.2.html. Accessed 2 May 2024"},{"key":"7_CR16","doi-asserted-by":"crossref","unstructured":"Rosa, L., Garbugli, A., Corradi, A., Bellavista, P.: INSANE: a unified middleware for QoS-aware network acceleration in edge cloud computing. In: Proceedings of the 24th International Middleware Conference, pp. 57\u201370 (2023)","DOI":"10.1145\/3590140.3629105"},{"key":"7_CR17","first-page":"70","volume":"186","author":"R Rosen","year":"2013","unstructured":"Rosen, R.: Resource management: linux kernel namespaces and cgroups. Haifux 186, 70 (2013)","journal-title":"Haifux"},{"key":"7_CR18","doi-asserted-by":"publisher","unstructured":"Shu, R., et al.: A study of security isolation techniques. ACM Comput. Surv. 49(3) (2016). https:\/\/doi.org\/10.1145\/2988545","DOI":"10.1145\/2988545"},{"key":"7_CR19","unstructured":"Vahldiek-Oberwagner, A., Elnikety, E., Duarte, N.O., Sammler, M., Druschel, P., Garg, D.: ERIM: secure, efficient in-process isolation with protection keys (MPK). In: 28th USENIX Security Symposium (USENIX Security 2019), pp. 1221\u20131238. USENIX Association, Santa Clara (2019). https:\/\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/vahldiek-oberwagner"},{"key":"7_CR20","unstructured":"Wright, C., Cowan, C., Smalley, S., Morris, J., Kroah-Hartman, G.: Linux security modules: general security support for the linux kernel. In: 11th USENIX Security Symposium (USENIX Security 2002) (2002)"}],"container-title":["Lecture Notes in Computer Science","Security and Trust Management"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-76371-7_7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,12,20]],"date-time":"2024-12-20T08:04:37Z","timestamp":1734681877000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-76371-7_7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,21]]},"ISBN":["9783031763700","9783031763717"],"references-count":20,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-76371-7_7","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,12,21]]},"assertion":[{"value":"21 December 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"STM","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Workshop on Security and Trust Management","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Bydgoszcz","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Poland","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19 September 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20 September 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"stm2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.nics.uma.es\/stm2024\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}