{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,21]],"date-time":"2026-01-21T11:09:45Z","timestamp":1768993785945,"version":"3.49.0"},"publisher-location":"Berlin, Heidelberg","reference-count":31,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783642331664","type":"print"},{"value":"9783642331671","type":"electronic"}],"license":[{"start":{"date-parts":[[2012,1,1]],"date-time":"2012-01-01T00:00:00Z","timestamp":1325376000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012]]},"DOI":"10.1007\/978-3-642-33167-1_48","type":"book-chapter","created":{"date-parts":[[2012,8,18]],"date-time":"2012-08-18T10:07:05Z","timestamp":1345284425000},"page":"842-858","source":"Crossref","is-referenced-by-count":12,"title":["JVM-Portable Sandboxing of Java\u2019s Native Libraries"],"prefix":"10.1007","author":[{"given":"Mengtao","family":"Sun","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gang","family":"Tan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"48_CR1","unstructured":"Liang, S.: Java Native Interface: Programmer\u2019s Guide and Reference. Addison-Wesley Longman Publishing Co., Inc. (1999)"},{"key":"48_CR2","unstructured":"Tan, G., Croft, J.: An empirical security study of the native code in the JDK. In: 17th Usenix Security Symposium, pp. 365\u2013377 (2008)"},{"key":"48_CR3","doi-asserted-by":"crossref","unstructured":"Siefers, J., Tan, G., Morrisett, G.: Robusta: Taming the native beast of the JVM. In: 17th ACM Conference on Computer and Communications Security (CCS), pp. 201\u2013211 (2010)","DOI":"10.1145\/1866307.1866331"},{"key":"48_CR4","first-page":"203","volume-title":"ACM SIGOPS Symposium on Operating Systems Principles (SOSP)","author":"R. Wahbe","year":"1993","unstructured":"Wahbe, R., Lucco, S., Anderson, T., Graham, S.: Efficient software-based fault isolation. In: ACM SIGOPS Symposium on Operating Systems Principles (SOSP), pp. 203\u2013216. ACM Press, New York (1993)"},{"key":"48_CR5","doi-asserted-by":"crossref","unstructured":"Blackburn, S.M., Garner, R., Hoffmann, C., Khan, A.M., McKinley, K.S., Bentzur, R., Diwan, A., Feinberg, D., Frampton, D., Guyer, S.Z., Hirzel, M., Hosking, A.L., Jump, M., Lee, H.B., Moss, J.E.B., Phansalkar, A., Stefanovic, D., VanDrunen, T., von Dincklage, D., Wiedermann, B.: The dacapo benchmarks: java benchmarking development and analysis. In: ACM Conference on Object-Oriented Programming, Systems, Languages, and Applications (OOPSLA), pp. 169\u2013190 (2006)","DOI":"10.1145\/1167473.1167488"},{"key":"48_CR6","unstructured":"McGraw, G., Felten, E.W.: Securing Java: Getting Down to Business with Mobile Code. John Wiley & Sons (1999)"},{"key":"48_CR7","unstructured":"Schoenefeld, M.: Denial-of-service holes in JDK 1.3.1 and 1.4.1_01 (2003), http:\/\/www.illegalaccess.org\/java\/ZipBugs.php (retrieved April 26, 2008)"},{"key":"48_CR8","unstructured":"US-CERT: Vulnerability note VU#939609: Sun Java JRE vulnerable to arbitrary code execution via an unspecified error, Credit goes to Chris Evans (January 2007)"},{"key":"48_CR9","unstructured":"US-CERT: Vulnerability note VU#138545: Java Runtime Environment image parsing code buffer overflow vulnerability, Credit goes to Chris Evans (June 2007)"},{"key":"48_CR10","doi-asserted-by":"crossref","unstructured":"Yee, B., Sehr, D., Dardyk, G., Chen, B., Muth, R., Ormandy, T., Okasaka, S., Narula, N., Fullagar, N.: Native client: A sandbox for portable, untrusted x86 native code. In: IEEE Symposium on Security and Privacy (S&P) (May 2009)","DOI":"10.1109\/SP.2009.25"},{"key":"48_CR11","unstructured":"Oracle: JVM tool interface, version 1.0, http:\/\/docs.oracle.com\/javase\/1.5.0\/docs\/guide\/jvmti\/jvmti.html (2010)"},{"key":"48_CR12","doi-asserted-by":"crossref","unstructured":"Lee, B., Hirzel, M., Grimm, R., Wiedermann, B., McKinley, K.S.: Jinn: Synthesizing a dynamic bug detector for foreign language interfaces. In: ACM Conference on Programming Language Design and Implementation (PLDI), pp. 36\u201349 (2010)","DOI":"10.1145\/1809028.1806601"},{"key":"48_CR13","doi-asserted-by":"crossref","unstructured":"Wallach, D.S., Felten, E.W.: Understanding java stack inspection. In: IEEE Symposium on Security and Privacy, pp. 52\u201363 (1998)","DOI":"10.1109\/SECPRI.1998.674823"},{"key":"48_CR14","doi-asserted-by":"crossref","unstructured":"Erlingsson, \u00da., Schneider, F.: SASI enforcement of security policies: A retrospective. In: Proceedings of the New Security Paradigms Workshop (NSPW), pp. 87\u201395. ACM Press (1999)","DOI":"10.1145\/335169.335201"},{"key":"48_CR15","unstructured":"McCamant, S., Morrisett, G.: Evaluating SFI for a CISC architecture. In: 15th Usenix Security Symposium (2006)"},{"key":"48_CR16","unstructured":"Ford, B., Cox, R.: Vx32: Lightweight user-level sandboxing on the x86. In: USENIX Annual Technical Conference, pp. 293\u2013306 (2008)"},{"key":"48_CR17","doi-asserted-by":"crossref","unstructured":"Castro, M., Costa, M., Martin, J.P., Peinado, M., Akritidis, P., Donnelly, A., Barham, P., Black, R.: Fast byte-granularity software fault isolation. In: ACM SIGOPS Symposium on Operating Systems Principles (SOSP), pp. 45\u201358 (2009)","DOI":"10.1145\/1629575.1629581"},{"key":"48_CR18","doi-asserted-by":"crossref","unstructured":"Efstathopoulos, P., Krohn, M., Vandebogart, S., Frey, C., Ziegler, D., Kohler, E., Mazi\u00e8res, D., Kaashoek, M.F., Morris, R.: Labels and event processes in the Asbestos operating system. In: ACM SIGOPS Symposium on Operating Systems Principles (SOSP), pp. 17\u201330 (2005)","DOI":"10.1145\/1095809.1095813"},{"key":"48_CR19","unstructured":"Zeldovich, N., Boyd-Wickizer, S., Kohler, E., Mazi\u00e8res, D.: Making information flow explicit in HiStar. In: USENIX Symposium on Operating Systems Design and Implementation (OSDI), pp. 263\u2013278 (2006)"},{"key":"48_CR20","doi-asserted-by":"crossref","unstructured":"Krohn, M., Yip, A., Brodsky, M., Cliffer, N., Kaashoek, M.F., Kohler, E., Morris, R.: Information flow control for standard OS abstractions. In: ACM SIGOPS Symposium on Operating Systems Principles (SOSP), pp. 321\u2013334 (2007)","DOI":"10.1145\/1323293.1294293"},{"key":"48_CR21","unstructured":"Bittau, A., Marchenko, P., Handley, M., Karp, B.: Wedge: splitting applications into reduced-privilege compartments. In: Proceedings of the 5th USENIX Symposium on Networked Systems Design and Implementation, pp. 309\u2013322 (2008)"},{"key":"48_CR22","unstructured":"Watson, R., Anderson, J., Laurie, B., Kennaway, K.: Capsicum: Practical capabilities for UNIX. In: 19th Usenix Security Symposium, pp. 29\u201346 (2010)"},{"key":"48_CR23","doi-asserted-by":"crossref","unstructured":"Cox, R.S., Gribble, S.D., Levy, H.M., Hansen, J.G.: A safety-oriented platform for web applications. In: IEEE Symposium on Security and Privacy (S&P), pp. 350\u2013364 (2006)","DOI":"10.1109\/SP.2006.4"},{"key":"48_CR24","unstructured":"Miller, M.: Robust composition: towards a unified approach to access control and concurrency control. PhD thesis, Johns Hopkins University, Baltimore, MD (2006)"},{"key":"48_CR25","unstructured":"Mettler, A., Wagner, D., Close, T.: Joe-E: A security-oriented subset of Java. In: Network and Distributed Systems Symposium, NDSS (2010)"},{"key":"48_CR26","doi-asserted-by":"crossref","unstructured":"Krishnamurthy, A., Mettler, A., Wagner, D.: Fine-grained privilege separation for web applications. In: Proceedings of the 19th International Conference on World Wide Web (WWW 2010), pp. 551\u2013560 (2010)","DOI":"10.1145\/1772690.1772747"},{"issue":"3","key":"48_CR27","doi-asserted-by":"publisher","first-page":"527","DOI":"10.1145\/319301.319345","volume":"21","author":"G. Morrisett","year":"1999","unstructured":"Morrisett, G., Walker, D., Crary, K., Glew, N.: From System F to typed assembly language. ACM Transactions on Programming Languages and Systems\u00a021(3), 527\u2013568 (1999)","journal-title":"ACM Transactions on Programming Languages and Systems"},{"key":"48_CR28","doi-asserted-by":"crossref","unstructured":"Witchel, E., Rhee, J., Asanovi\u0107, K.: Mondrix: memory isolation for linux using Mondriaan memory protection. In: ACM SIGOPS Symposium on Operating Systems Principles (SOSP), pp. 31\u201344 (2005)","DOI":"10.1145\/1095809.1095814"},{"key":"48_CR29","unstructured":"Neumann, P., Watson, R.: Capabilities revisited: A holistic approach to bottom-to-top assurance of trustworthy systems. In: Fourth Layered Assurance Workshop (2010)"},{"key":"48_CR30","unstructured":"PPAPI, http:\/\/code.google.com\/p\/ppapi\/wiki\/Concepts"},{"key":"48_CR31","doi-asserted-by":"crossref","unstructured":"Cappos, J., Dadgar, A., Rasley, J., Samuel, J., Beschastnikh, I., Barsan, C., Krishnamurthy, A., Anderson, T.E.: Retaining sandbox containment despite bugs in privileged memory-safe code. In: 17th ACM Conference on Computer and Communications Security (CCS), pp. 212\u2013223 (2010)","DOI":"10.1145\/1866307.1866332"}],"container-title":["Lecture Notes in Computer Science","Computer Security \u2013 ESORICS 2012"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-33167-1_48","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,6]],"date-time":"2025-04-06T23:44:09Z","timestamp":1743983049000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-33167-1_48"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012]]},"ISBN":["9783642331664","9783642331671"],"references-count":31,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-33167-1_48","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012]]}}}