{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T09:23:33Z","timestamp":1761989013220,"version":"3.40.3"},"publisher-location":"Cham","reference-count":35,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319457185"},{"type":"electronic","value":"9783319457192"}],"license":[{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016]]},"DOI":"10.1007\/978-3-319-45719-2_20","type":"book-chapter","created":{"date-parts":[[2016,9,5]],"date-time":"2016-09-05T22:11:24Z","timestamp":1473113484000},"page":"437-456","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":9,"title":["Trellis: Privilege Separation for Multi-user Applications Made Easy"],"prefix":"10.1007","author":[{"given":"Andrea","family":"Mambretti","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kaan","family":"Onarlioglu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Collin","family":"Mulliner","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"William","family":"Robertson","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Engin","family":"Kirda","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Federico","family":"Maggi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stefano","family":"Zanero","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,9,7]]},"reference":[{"key":"20_CR1","unstructured":"Apache Shiro. \n                      https:\/\/shiro.apache.org\/index.html"},{"key":"20_CR2","unstructured":"HomeBank. \n                      http:\/\/homebank.free.fr"},{"key":"20_CR3","unstructured":"Linux Desktop Testing Project. \n                      http:\/\/ldtp.freedesktop.org\/"},{"key":"20_CR4","unstructured":"Parasite. \n                      https:\/\/chipx86.github.io\/gtkparasite"},{"key":"20_CR5","unstructured":"SELinux. \n                      http:\/\/selinuxproject.org"},{"key":"20_CR6","unstructured":"Spring Security. \n                      http:\/\/projects.spring.io\/spring-security"},{"key":"20_CR7","unstructured":"Abad\u00ed, M., Fournet, C.: Access control based on execution history. In: NDSS (2003)"},{"key":"20_CR8","unstructured":"Badger, L., Sterne, D., Sherman, D., Walker, K.M., Haghighat, S.A.: A domain and type enforcement UNIX prototype. In: USENIX Security (1995)"},{"key":"20_CR9","unstructured":"Bittau, A., Marchenko, P., Handley, M., Karp, B.: Wedge: splitting applications into reduced-privilege compartments. In: USENIX NSDI (2008)"},{"key":"20_CR10","unstructured":"Brumley, D., Song, D.: Privtrans: automatically partitioning programs for privilege separation. In: USENIX Security (2004)"},{"key":"20_CR11","unstructured":"Carson, M.E.: Sendmail without the superuser. In: USENIX Security (1993)"},{"key":"20_CR12","doi-asserted-by":"crossref","unstructured":"Chong, S., Liu, J., Myers, A.C., Qi, X., Vikram, K., Zheng, L., Zheng, X.: Secure web applications via automatic partitioning. In: ACM SOSP (2007)","DOI":"10.1145\/1294261.1294265"},{"key":"20_CR13","unstructured":"Cowan, C., Pu, C., Maier, D., Walpole, J., Bakke, P., Beattie, S., Grier, A., Wagle, P., Zhang, Q., Hinton, H.: StackGuard: automatic adaptive detection and prevention of buffer-overflow attacks. In: USENIX Security (1998)"},{"key":"20_CR14","doi-asserted-by":"crossref","unstructured":"Efstathopoulos, P., Krohn, M., VanDeBogart, S., Frey, C., Ziegler, D., Kohler, E., Mazi\u00e8res, D., Kaashoek, F., Morris, R.: Labels and event processes in the Asbestos operating system. In: ACM SOSP (2005)","DOI":"10.1145\/1095810.1095813"},{"key":"20_CR15","unstructured":"Evans, C.: Very Secure FTP Daemon. \n                      http:\/\/security.appspot.com\/vsftpd.html"},{"key":"20_CR16","unstructured":"Kilpatrick, D.: Privman: a library for partitioning applications. In: USENIX ATC (2003)"},{"key":"20_CR17","unstructured":"Kim, T., Zeldovich, N.: Making Linux protection mechanisms egalitarian with UserFS. In: USENIX Security (2010)"},{"key":"20_CR18","doi-asserted-by":"crossref","unstructured":"Krohn, M., Yip, A., Brodsky, M., Cliffer, N., Kaashoek, M.F., Kohler, E., Morris, R.: Information flow control for standard OS abstractions. In: ACM SOSP (2007)","DOI":"10.1145\/1294261.1294293"},{"key":"20_CR19","unstructured":"McCamant, S., Morrisett, G.: Evaluating SFI for a CISC architecture. In: USENIX Security (2006)"},{"key":"20_CR20","doi-asserted-by":"crossref","unstructured":"Morrisett, G., Tan, G., Tassarotti, J., Tristan, J.B., Gan, E.: RockSalt: better, faster, stronger SFI for the x86. In: ACM PLDI (2012)","DOI":"10.1145\/2254064.2254111"},{"key":"20_CR21","doi-asserted-by":"crossref","unstructured":"Mulliner, C., Robertson, W., Kirda, E.: Hidden GEMs: automated discovery of access control vulnerabilities in graphical user interfaces. In: IEEE Security and Privacy (2014)","DOI":"10.1109\/SP.2014.17"},{"key":"20_CR22","doi-asserted-by":"crossref","unstructured":"Murray, D.G., Hand, S.: Privilege separation made easy: trusting small libraries not big processes. In: EuroSec (2008)","DOI":"10.1145\/1355284.1355292"},{"key":"20_CR23","unstructured":"Peterson, D., Bishop, M., Pandey, R.: A flexible containment mechanism for executing untrusted code. In: USENIX Security (2002)"},{"key":"20_CR24","unstructured":"Provos, N., Friedl, M., Honeyman, P.: Preventing privilege escalation. In: USENIX Security (2003)"},{"issue":"7","key":"20_CR25","doi-asserted-by":"publisher","first-page":"388","DOI":"10.1145\/361011.361067","volume":"17","author":"JH Saltzer","year":"1974","unstructured":"Saltzer, J.H.: Protection and the control of information sharing in multics. Commun. ACM 17(7), 388\u2013402 (1974)","journal-title":"Commun. ACM"},{"key":"20_CR26","doi-asserted-by":"crossref","unstructured":"Shapiro, J.S., Smith, J.M., Farber, D.J.: EROS: a fast capability system. In: ACM SOSP (1999)","DOI":"10.1145\/319151.319163"},{"key":"20_CR27","unstructured":"The PaX Team: PaX Address Space Layout Randomization (ASLR) (2003). \n                      http:\/\/pax.grsecurity.net\/docs\/aslr.txt"},{"key":"20_CR28","unstructured":"Venema, W.: The Postfix Homepage. \n                      http:\/\/www.postfix.org\/"},{"key":"20_CR29","doi-asserted-by":"crossref","unstructured":"Wahbe, R., Lucco, S., Anderson, T.E., Graham, S.L.: Efficient software-based fault isolation. In: ACM SOSP (1993)","DOI":"10.1145\/168619.168635"},{"key":"20_CR30","unstructured":"Walker, K.M., Sterne, D.F., Badger, M.L., Petkac, M.J., Sherman, D.L., Oostendorp, K.A.: Confining root programs with domain and type enforcement (DTE). In: USENIX Security (1996)"},{"key":"20_CR31","volume-title":"The Cambridge CAP Computer and Its Operating System","author":"MV Wilkes","year":"1979","unstructured":"Wilkes, M.V.: The Cambridge CAP Computer and Its Operating System. North-Holland Publishing Co., Amsterdam (1979)"},{"key":"20_CR32","doi-asserted-by":"crossref","unstructured":"Wu, Y., Sun, J., Liu, Y., Dong, J.S.: Automatically partition software into least privilege components using dynamic data dependency analysis. In: IEEE\/ACM ASE (2013)","DOI":"10.1109\/ASE.2013.6693091"},{"issue":"3","key":"20_CR33","doi-asserted-by":"publisher","first-page":"283","DOI":"10.1145\/566340.566343","volume":"20","author":"S Zdancewic","year":"2002","unstructured":"Zdancewic, S., Zheng, L., Nystrom, N., Myers, A.C.: Secure program partitioning. ACM Trans. Comput. Syst. 20(3), 283\u2013328 (2002)","journal-title":"ACM Trans. Comput. Syst."},{"key":"20_CR34","unstructured":"Zeldovich, N., Boyd-Wickizer, S., Kohler, E., Mazi\u00e8res, D.: Making information flow explicit in HiStar. In: USENIX OSDI (2006)"},{"key":"20_CR35","unstructured":"Zheng, L., Chong, S., Myers, A.C., Zdancewic, S.: Using replication and partitioning to build secure distributed systems. In: IEEE Security and Privacy (2003)"}],"container-title":["Lecture Notes in Computer Science","Research in Attacks, Intrusions, and Defenses"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-45719-2_20","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,20]],"date-time":"2019-05-20T01:01:29Z","timestamp":1558314089000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-45719-2_20"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016]]},"ISBN":["9783319457185","9783319457192"],"references-count":35,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-45719-2_20","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2016]]},"assertion":[{"value":"7 September 2016","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"RAID","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Symposium on Research in Attacks, Intrusions, and Defenses","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Paris","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"France","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2016","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19 September 2016","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21 September 2016","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"raid2016","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}