{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,26]],"date-time":"2025-03-26T18:35:51Z","timestamp":1743014151519,"version":"3.40.3"},"publisher-location":"Berlin, Heidelberg","reference-count":43,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783540886242"},{"type":"electronic","value":"9783540886259"}],"license":[{"start":{"date-parts":[[2008,1,1]],"date-time":"2008-01-01T00:00:00Z","timestamp":1199145600000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2008]]},"DOI":"10.1007\/978-3-540-88625-9_14","type":"book-chapter","created":{"date-parts":[[2008,10,15]],"date-time":"2008-10-15T04:03:06Z","timestamp":1224043386000},"page":"206-221","source":"Crossref","is-referenced-by-count":5,"title":["Reusability of Functionality-Based Application Confinement Policy Abstractions"],"prefix":"10.1007","author":[{"given":"Z. Cliffe","family":"Schreuders","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christian","family":"Payne","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"14_CR1","doi-asserted-by":"publisher","first-page":"136","DOI":"10.1145\/990036.990059","volume-title":"Proceedings of the Ninth ACM Symposium on Access Control Models and Technologies","author":"G. Zanin","year":"2004","unstructured":"Zanin, G., Mancini, L.V.: Towards a Formal Model for Security Policies Specification and Validation in the SElinux System. In: Proceedings of the Ninth ACM Symposium on Access Control Models and Technologies, pp. 136\u2013145. ACM Press, Yorktown Heights (2004)"},{"key":"14_CR2","volume-title":"Proceedings of the 6th USENIX Security Symposium","author":"I. Goldberg","year":"1996","unstructured":"Goldberg, I., Wagner, D., Thomas, R., Brewer, E.A.: A Secure Environment for Untrusted Helper Applications: Confining the Wily Hacker. In: Proceedings of the 6th USENIX Security Symposium. University of California, San Jose (1996)"},{"key":"14_CR3","doi-asserted-by":"publisher","first-page":"42","DOI":"10.1145\/1016998.1017001","volume":"2","author":"P.-H. Kamp","year":"2004","unstructured":"Kamp, P.-H., Watson, R.: Building Systems to be Shared Securely. ACM Queue\u00a02, 42\u201351 (2004)","journal-title":"ACM Queue"},{"key":"14_CR4","doi-asserted-by":"crossref","unstructured":"Madnick, S.E., Donovan, J.J.: Application and Analysis of the Virtual Machine Approach to Information Security. In: Proceedings of the ACM Workshop on Virtual Computer Systems, Cambridge, MA, USA, March 1973, pp. 210\u2013224 (1973)","DOI":"10.1145\/800122.803961"},{"key":"14_CR5","unstructured":"Kamp, P.-H., Watson, R.: Jails: Confining the Omnipotent Root. In: Sane 2000 - 2nd International SANE Conference (2000)"},{"key":"14_CR6","unstructured":"Tucker, A., Comay, D.: Solaris Zones: Operating System Support for Server Consolidation. In: 3rd Virtual Machine Research and Technology Symposium Works-in-Progress"},{"key":"14_CR7","doi-asserted-by":"crossref","unstructured":"Whitaker, A., Shaw, M., Gribble, S.D.: Lightweight virtual machines for distributed and networked applications. In: Proceedings of the 5th USENIX Symposium on Operating Systems Design and Implementation, pp. 195\u2013209 (2002)","DOI":"10.1145\/1060289.1060308"},{"key":"14_CR8","volume-title":"USENIX Symposium on Internet Technologies and Systems","author":"L. Gong","year":"1997","unstructured":"Gong, L., Mueller, M., Prafullchandra, H., Schemers, R.: Going Beyond the Sandbox: An Overview of the New Security Architecture in the Java Development Kit 1.2. In: USENIX Symposium on Internet Technologies and Systems. Prentice Hall PTR, Monterey (1997)"},{"key":"14_CR9","first-page":"229","volume-title":"Net Security and Cryptography","author":"P. Thorsteinson","year":"2003","unstructured":"Thorsteinson, P., Ganesh, G.G.A.: Net Security and Cryptography, p. 229. Prentice Hall PTR, Englewood Cliffs (2003)"},{"key":"14_CR10","doi-asserted-by":"crossref","unstructured":"Li, N., Mao, Z., Chen, H.: Usable Mandatory Integrity Protection for Operating Systems. In: Proceedings of the IEEE Symposium on Security and Privacy, pp. 164\u2013178 (2007)","DOI":"10.1109\/SP.2007.37"},{"key":"14_CR11","doi-asserted-by":"crossref","unstructured":"Sun, W., Sekar, R., Poothia, G., Karandikar, T.: Practical Proactive Integrity Preservation: A Basis for Malware Defense. Security and Privacy. In: IEEE Symposium on SP 2008, pp. 248\u2013262 (2008)","DOI":"10.1109\/SP.2008.35"},{"key":"14_CR12","unstructured":"Wagner, D.A.: Janus: An Approach for Confinement of Untrusted Applications. Technical Report: CSD-99-1056. Electrical Engineering and Computer Sciences. University of California, Berkeley, USA (1999)"},{"key":"14_CR13","volume-title":"12th USENIX Security Symposium","author":"N. Provos","year":"2002","unstructured":"Provos, N.: Improving Host Security with System Call Policies. In: 12th USENIX Security Symposium, vol.\u00a010. USENIX, Washington (2002)"},{"key":"14_CR14","unstructured":"Cowan, C., Beattie, S., Kroah-Hartman, G., Pu, C., Wagle, P., Gligor, V.: SubDomain: Parsimonious Server Security. In: USENIX 14th Systems Administration Conference (LISA) (2000)"},{"key":"14_CR15","unstructured":"Berman, A., Bourassa, V., Selberg, E.: TRON: Process-Specific File Protection for the UNIX Operating System. In: Proceedings of the 1995 Winter USENIX Conference (1995)"},{"key":"14_CR16","unstructured":"Bacarella, M.: Taking advantage of Linux capabilities. Linux Journal (2002)"},{"key":"14_CR17","doi-asserted-by":"crossref","unstructured":"Krsti, I., Garfinkel, S.L.: Bitfrost: the one laptop per child security model. In: ACM International Conference Proceeding Series, vol.\u00a0229, pp. 132\u2013142 (2007)","DOI":"10.1145\/1280680.1280697"},{"key":"14_CR18","doi-asserted-by":"crossref","unstructured":"Miller, M.S., Tulloh, B., Shapiro, J.S.: The structure of authority: Why security is not a separable concern. In: Multiparadigm Programming in Mozart\/Oz: Proceedings of MOZ 3389 (2004)","DOI":"10.1007\/978-3-540-31845-3_2"},{"key":"14_CR19","doi-asserted-by":"publisher","first-page":"83","DOI":"10.1145\/1151030.1151033","volume":"49","author":"M. Stiegler","year":"2006","unstructured":"Stiegler, M., Karp, A.H., Yee, K.P., Close, T., Miller, M.S.: Polaris: virus-safe computing for Windows XP. Communications of the ACM\u00a049, 83\u201388 (2006)","journal-title":"Communications of the ACM"},{"key":"14_CR20","doi-asserted-by":"crossref","unstructured":"Wagner, D.: Object capabilities for security. In: Conference on Programming Language Design and Implementation: Proceedings of the 2006 workshop on Programming languages and analysis for security, vol.\u00a010, pp. 1\u20132 (2006)","DOI":"10.1145\/1134744.1134745"},{"key":"14_CR21","doi-asserted-by":"publisher","first-page":"66","DOI":"10.1109\/SECPRI.1995.398923","volume-title":"Proceedings of the 1995 IEEE Symposium on Security and Privacy","author":"L. Badger","year":"1995","unstructured":"Badger, L., Sterne, D.F., Sherman, D.L., Walker, K.M., Haghighat, S.A.: Practical Domain and Type Enforcement for UNIX. In: Proceedings of the 1995 IEEE Symposium on Security and Privacy, p. 66. IEEE Computer Society, Los Alamitos (1995)"},{"key":"14_CR22","unstructured":"Ott, A.: The Role Compatibility Security Model. In: 7th Nordic Workshop on Secure IT Systems (2002)"},{"key":"14_CR23","unstructured":"Krohn, M., Efstathopoulos, P., Frey, C., Kaashoek, F., Kohler, E., Mazieres, D., Morris, R., Osborne, M., VanDeBogart, S., Ziegler, D.: Make least privilege a right (not a privilege). In: Procedings of 10th Hot Topics in Operating Systems Symposium (HotOS-X), Santa Fe, NM, USA, pp. 1\u201311 (2005)"},{"key":"14_CR24","doi-asserted-by":"crossref","unstructured":"Marceau, C., Joyce, R.: Empirical Privilege Profiling. In: Proceedings of the 2005 Workshop on New Security Paradigms, pp. 111\u2013118 (2005)","DOI":"10.1145\/1146269.1146294"},{"key":"14_CR25","unstructured":"Jaeger, T., Sailer, R., Zhang, X.: Analyzing Integrity Protection in the SELinux Example Policy. In: Proceedings of the 12th USENIX Security Symposium, pp. 59\u201374 (2003)"},{"key":"14_CR26","unstructured":"Hinrichs, S., Naldurg, P.: Attack-based Domain Transition Analysis. In: 2nd Annual Security Enhanced Linux Symposium, Baltimore, Md., USA (2006)"},{"key":"14_CR27","unstructured":"Ferraiolo, D., Kuhn, R.: Role-Based Access Control. In: 15th National Computer Security Conference, Baltimore, MD, USA, pp. 554\u2013563 (1992)"},{"key":"14_CR28","doi-asserted-by":"publisher","first-page":"38","DOI":"10.1109\/2.485845","volume":"29","author":"R.S. Sandhu","year":"1995","unstructured":"Sandhu, R.S., Coyne, E.J., Feinstein, H.L., Youman, C.E.: Role-Based Access Control Models. IEEE Computer\u00a029, 38\u201347 (1995)","journal-title":"IEEE Computer"},{"key":"14_CR29","doi-asserted-by":"crossref","unstructured":"Simon, R.T., Zurko, M.E.: Separation of Duty in Role-Based Environments. In: Proceedings of 10th IEEE Computer Security Foundations Workshop, Rockport, MD, pp. 183\u2013194 (1997)","DOI":"10.1109\/CSFW.1997.596811"},{"key":"14_CR30","first-page":"72","volume-title":"Proceedings of SECRYPT 2008: International Conference on Security and Cryptography","author":"Z.C. Schreuders","year":"2008","unstructured":"Schreuders, Z.C., Payne, C.: Functionality-Based Application Confinement: Parameterised Hierarchical Application Restrictions. In: Proceedings of SECRYPT 2008: International Conference on Security and Cryptography, pp. 72\u201377. INSTICC Press, Porto (2008)"},{"key":"14_CR31","doi-asserted-by":"publisher","first-page":"224","DOI":"10.1145\/501978.501980","volume":"4","author":"D.F. Ferraiolo","year":"2001","unstructured":"Ferraiolo, D.F., Sandhu, R., Gavrila, S., Kuhn, D.R., Chandramouli, R.: Proposed NIST Standard for Role-Based Access Control. ACM Transactions on Information and System Security\u00a04, 224\u2013274 (2001)","journal-title":"ACM Transactions on Information and System Security"},{"key":"14_CR32","unstructured":"ANSI INCITS 359-2004. American National Standards Institute \/ International Committee for Information Technology Standards (ANSI\/INCITS)"},{"key":"14_CR33","unstructured":"Acharya, A., Raje, M.: MAPbox: Using Parameterized Behavior Classes to Confine Applications. In: Proceedings of the 2000 USENIX Security Symposium, Denver, CO, USA (2000)"},{"key":"14_CR34","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1145\/270152.270183","volume-title":"Proceedings of the first ACM Workshop on Role-based access control","author":"T. Jaeger","year":"1996","unstructured":"Jaeger, T., Prakash, A.: Requirements of role-based access control for collaborative systems. In: Proceedings of the first ACM Workshop on Role-based access control, p. 16. ACM Press, Gaithersburg (1996)"},{"key":"14_CR35","first-page":"83","volume-title":"Proceedings of the second ACM workshop on Role-based access control","author":"C. Friberg","year":"1997","unstructured":"Friberg, C., Held, A.: Support for discretionary role based access control in ACL-oriented operating systems. In: Proceedings of the second ACM workshop on Role-based access control, pp. 83\u201394. ACM Press, Fairfax (1997)"},{"key":"14_CR36","first-page":"476","volume-title":"Proceedings of the 21st National Information Systems Security Conference","author":"W.A. Jansen","year":"1998","unstructured":"Jansen, W.A.: Inheritance Properties of Role Hierarchies. In: Proceedings of the 21st National Information Systems Security Conference, pp. 476\u2013485. National Institute of Standards and Technology, Gaithersburg (1998)"},{"key":"14_CR37","unstructured":"Wright, C., Cowan, C., Smalley, S., Morris, J., Kroah-Hartman, G.: Linux Security Module Framework. In: Ottawa Linux Symposium, Ottawa, Canada (2002)"},{"key":"14_CR38","first-page":"163","volume-title":"Proceedings of the 10th Network and Distributed System Security Symposium","author":"T. Garfinkel","year":"2003","unstructured":"Garfinkel, T.: Traps and Pitfalls: Practical Problems in System Call Interposition Based Security Tools. In: Proceedings of the 10th Network and Distributed System Security Symposium, pp. 163\u2013176. Stanford University, San Diego (2003)"},{"key":"14_CR39","doi-asserted-by":"crossref","unstructured":"Bratus, S., Ferguson, A., McIlroy, D., Smith, S.: Pastures: Towards Usable Security Policy Engineering. In: Proceedings of the Second International Conference on Availability, Reliability and Security, pp. 1052\u20131059 (2007)","DOI":"10.1109\/ARES.2007.114"},{"key":"14_CR40","unstructured":"Tresys: SELinux Reference Policy (2008)"},{"key":"14_CR41","unstructured":"Harada, T., Horie, T., Tanaka, K.: Towards a manageable Linux security. In: Linux Conference 2005 (Japanese) (2005), http:\/\/lc.linux.or.jp\/lc2005\/02.html"},{"key":"14_CR42","unstructured":"Tresys: SELinux Reference Policy (2008), http:\/\/oss.tresys.com\/projects\/refpolicy"},{"key":"14_CR43","unstructured":"Raje, M.: Behavior-based Confinement of Untrusted Applications. TRCS 99-12. Department of Computer Science. University of Calfornia, Santa Barbara (1999)"}],"container-title":["Lecture Notes in Computer Science","Information and Communications Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-540-88625-9_14","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,2,1]],"date-time":"2025-02-01T19:20:58Z","timestamp":1738437658000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-540-88625-9_14"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2008]]},"ISBN":["9783540886242","9783540886259"],"references-count":43,"URL":"https:\/\/doi.org\/10.1007\/978-3-540-88625-9_14","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2008]]}}}