{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2022,4,2]],"date-time":"2022-04-02T06:52:43Z","timestamp":1648882363596},"reference-count":48,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2013,5,12]],"date-time":"2013-05-12T00:00:00Z","timestamp":1368316800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2013,10]]},"DOI":"10.1007\/s10207-013-0199-4","type":"journal-article","created":{"date-parts":[[2013,5,11]],"date-time":"2013-05-11T04:49:30Z","timestamp":1368247770000},"page":"393-422","source":"Crossref","is-referenced-by-count":1,"title":["The functionality-based application confinement model"],"prefix":"10.1007","volume":"12","author":[{"given":"Z. Cliffe","family":"Schreuders","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christian","family":"Payne","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tanya","family":"McGill","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2013,5,12]]},"reference":[{"issue":"1","key":"199_CR1","doi-asserted-by":"crossref","first-page":"91","DOI":"10.1145\/1629175.1629203","volume":"53","author":"B Yee","year":"2010","unstructured":"Yee, B., Sehr, D., Dardyk, G., Chen, J.B., Muth, R., Ormandy, T., Okasaka, S., Narula, N., Fullagar, N.: Native client: a sandbox for portable, utrusted x86 native code. Commun. ACM 53(1), 91\u201399 (2010)","journal-title":"Commun. ACM"},{"key":"199_CR2","unstructured":"Gong, L., Mueller, M., Prafullchandra, H., Schemers, R.: Going beyond the sandbox: an overview of the new security architecture in the Java development kit 1.2. In: Proceedings of the USENIX Symposium on Internet Technologies and Systems, Monterey, CA, USA. Prentice Hall PTR (1997)"},{"key":"199_CR3","doi-asserted-by":"crossref","unstructured":"Whitaker, A., Shaw, M., Gribble, S.D.: Denali: lightweight virtual machines for distributed and networked applications. In: Proceedings of the 5th USENIX Symposium on Operating Systems Design and Implementation, Boston, MA, USA. USENIX Association (2002)","DOI":"10.1145\/1133373.1133375"},{"key":"199_CR4","doi-asserted-by":"crossref","unstructured":"Madnick, S.E., Donovan, J.J.: Application and analysis of the virtual machine approach to information security. In: ACM Workshop on Virtual Computer Systems, Cambridge, MA, USA. Harvard University (1973)","DOI":"10.1145\/800122.803961"},{"key":"199_CR5","unstructured":"Kamp, P.-H., Watson, R.: Jails: confining the omnipotent root. In: Proceedings of the 2nd International System Administration and Networking Conference (SANE 2000), Maastricht, The Netherlands (2000)"},{"key":"199_CR6","unstructured":"Tucker, A., Comay, D.: Solaris zones: operating system support for server consolidation. In: Proceedings of the 3rd Virtual Machine Research and Technology Symposium Works-in-Progress, San Jose, CA, USA (2004)"},{"key":"199_CR7","unstructured":"Boebert, W.E., Kain, R.Y.: A practical alternative to hierarchical integrity policies. In: Proceedings of the 8th National Computer Security Conference, Gaithersburg, MD, USA. NIST (1985)"},{"key":"199_CR8","unstructured":"Goldberg, I., Wagner, D., Thomas, R., Brewer, E.A.: A secure environment for untrusted helper applications: confining the Wily Hacker. In: Proceedings of the 6th USENIX Security Symposium, San Jose, CA, USA. USENIX Association (1996)"},{"key":"199_CR9","unstructured":"Provos, N.: Improving host security with system call policies. In: Proceedings of the 12th USENIX Security Symposium, Washington, DC, USA, USENIX Association, Aug 2002"},{"key":"199_CR10","unstructured":"Cowan, C., Beattie, S., Kroah-Hartman, G., Pu, C., Wagle, P., Gligor, V.: SubDomain: parsimonious server security. In: Proceedings of the USENIX 14th Systems Administration Conference, New Orleans, LA, USA. USENIX Association (2000)"},{"key":"199_CR11","unstructured":"Loscocco, P., Smalley, S.: Integrating flexible support for security policies into the Linux operating system. In: Proceedings of the FREENIX Track: 2001 USENIX Annual Technical Conference, Boston, MA, USA. USENIX Association (2001)"},{"key":"199_CR12","unstructured":"Harada, T., Horie, T., Tanaka, K.: Task oriented management obviates your onus on Linux. In: Proceedings of the Linux Conference, Tokyo, Japan (2004)"},{"key":"199_CR13","unstructured":"Sandhu, R., Ferraiolo, D., Kuhn, R.: Role based access control. American National Standards Institute\/International Committee for Information Technology Standards (ANSI\/INCITS) (2004)"},{"key":"199_CR14","unstructured":"Walker, K., Sterne, D., Badger, M., Petkac, M., Sherman, D., Oostendorp, K.: Confining root programs with domain and type enforcement. In: Proceedings of the 6th USENIX Security Symposium, San Jose, CA, USA, USENIX Association (1996)"},{"key":"199_CR15","unstructured":"Schreuders, Z.C.: A role-based approach to restricting application execution.Thesis, Murdoch University (2005)"},{"key":"199_CR16","unstructured":"Raje, M.: TRCS 99-12: Behavior-Based Confinement of Untrusted Applications. University of California, Oakland, CA (1999)"},{"key":"199_CR17","unstructured":"Acharya, A., Raje, M.: MAPbox: using parameterized behavior classes to confine applications. In: Proceedings of the 9th USENIX Security Symposium, Denver, CO, USA. USENIX Association (2000)"},{"key":"199_CR18","doi-asserted-by":"crossref","unstructured":"Giuri, L., Iglio, P.: Role templates for content-based access control. In: Proceedings of the 2nd ACM Workshop on Role-Based Access Control, Fairfax, VA, USA. ACM Press (1997)","DOI":"10.1145\/266741.266773"},{"key":"199_CR19","doi-asserted-by":"crossref","unstructured":"Yao, W., Moody, K., Bacon, J.: A model of OASIS role-based access control and its support for active security. In: 1997 6th ACM Symposium on Access Control Models and Technologies, Chantilly, VA, USA. ACM Press (2001)","DOI":"10.1145\/373256.373294"},{"key":"199_CR20","unstructured":"Ferraiolo, D., Cugini, J.A., Kuhn, R.: Role-based access control (RBAC): features and motivations. In: Proceedings of the 11th Annual Computer Security Applications Conference (ACSAC), Gaithersburg, MD, USA. IEEE Computer Society Press (1995)"},{"key":"199_CR21","doi-asserted-by":"crossref","unstructured":"Johnson, M., Karat, J., Karat, C.-M., Grueneberg, K.: Optimizing a policy authoring framework for security and privacy policies. In: Proceedings of the 6th Symposium on Usable Privacy and Security (SOUPS), Redmond, Washington, DC, USA. ACM Press (2010)","DOI":"10.1145\/1837110.1837121"},{"key":"199_CR22","unstructured":"Wagner, D.A.: Janus: an approach for confinement of untrusted applications. M.S. thesis. Electrical Engineering and Computer Sciences. University of California, Berkeley, CA (1999)"},{"key":"199_CR23","unstructured":"Berman, A., Bourassa, V., Selberg, E.: TRON: process-specific file protection for the UNIX operating system. In: Proceedings of the Winter USENIX Conference, New Orleans, LA, USA. USENIX Association (1995)"},{"key":"199_CR24","unstructured":"Hallyn, S.E., Kearns, P.: Domain and type enforcement for Linux. In: Proceedings of the 4th Annual Linux Showcase and Conference, Atlanta, GA, USA (2000)"},{"key":"199_CR25","doi-asserted-by":"crossref","unstructured":"Zanin, G., Mancini, L.V.: Towards a formal model for security policies specification and validation in the SELinux system. In: Proceedings of the 9th ACM Symposium on Access Control Models and Technologies, Yorktown Heights, NY, USA. ACM Press (2004)","DOI":"10.1145\/990036.990059"},{"key":"199_CR26","unstructured":"Hallyn, S.E., Morgan, A.G.: Linux capabilities: making them work. In: Proceedings of the Linux Symposium, Ottawa, ON, Canada (2008)"},{"key":"199_CR27","doi-asserted-by":"crossref","unstructured":"Edge, C., Barker, W., Hunter, B., Sullivan, G.: Enterprise Mac Security: Mac OS X Snow Leopard, 2nd edn. Apress, New York (2010)","DOI":"10.1007\/978-1-4302-2731-1"},{"issue":"3","key":"199_CR28","doi-asserted-by":"crossref","first-page":"224","DOI":"10.1145\/501978.501980","volume":"4","author":"DF Ferraiolo","year":"2001","unstructured":"Ferraiolo, D.F., Sandhu, R., Gavrila, S., Kuhn, D.R., Chandramouli, R.: Proposed NIST standard for role-based access control. ACM Trans. Inf. Syst. Secur. (TISSEC) 4(3), 224\u2013274 (2001)","journal-title":"ACM Trans. Inf. Syst. Secur. (TISSEC)"},{"key":"199_CR29","doi-asserted-by":"crossref","unstructured":"Tidswell, J., Potter, J.: An approach to dynamic domain and type enforcement. In: Proceedings of the Australasian Conference on Information Security and Privacy, Syndey, NSW, Australia. Springer (1997)","DOI":"10.1007\/BFb0027941"},{"key":"199_CR30","unstructured":"Ott, A.: The role compatibility security model. In: Proceedings of the 7th Nordic Workshop on Secure IT Systems (NordSec), Karlstad, Sweden (2002)"},{"key":"199_CR31","unstructured":"Hinrichs, S., Naldurg, P.: Attack-based domain transition analysis. In: Proceedings of the 2nd Annual Security Enhanced Linux Symposium, Baltimore, MD, USA (2006)"},{"key":"199_CR32","unstructured":"Hardy, N.: The confused deputy: or why capabilities might have been invented. ACM SIGOPS Oper. Syst. Rev. 22(4), 36\u201338 (1988)"},{"issue":"3","key":"199_CR33","doi-asserted-by":"crossref","first-page":"360","DOI":"10.1145\/641909.641912","volume":"25","author":"C Fournet","year":"2003","unstructured":"Fournet, C., Gordon, A.D.: Stack inspection: theory and variants. ACM Trans. Program. Lang. Syst. (TOPLAS) 25(3), 360\u2013399 (2003)","journal-title":"ACM Trans. Program. Lang. Syst. (TOPLAS)"},{"key":"199_CR34","doi-asserted-by":"crossref","unstructured":"Wallach, D.S., Felten, E.W.: Understanding Java stack inspection. In: Proceedings of the 19th IEEE Symposium on Security and Privacy, Oakland, CA, USA. IEEE Computer Society (1998)","DOI":"10.1109\/SECPRI.1998.674823"},{"key":"199_CR35","doi-asserted-by":"crossref","unstructured":"Besson, F., Blanc, T., Fournet, C., Gordon, A.D.: From stack inspection to access control: a security analysis for libraries. In: Proceedings of the 17th IEEE Computer Security Foundations Workshop, Asilomar, CA, USA IEEE Computer Society (2004)","DOI":"10.1109\/CSFW.2004.1310732"},{"key":"199_CR36","unstructured":"Hunt, G., Larus, J., Abadi, M., Aiken, M., Barham, P., Fhndrich, M., Hawblitzel, C., Hodson, O., Levi, S., Murphy, N., Steensgaard, B., Tarditi, D., Wobber, T., Zill, B.: An overview of the singularity project. Microsoft Research, Redmond, WA, USA (2005)"},{"key":"199_CR37","unstructured":"Schreuders, Z.C.: The functionality-based application confinement model and its Linux prototype FBAC-LSM (presentation). In: linux.conf.au\u2014LCA2009, Tasmania, Australia (2009)"},{"key":"199_CR38","unstructured":"Schreuders, Z.C.: FBAC-LSM: protect yourself from your apps. http:\/\/schreuders.org\/FBAC-LSM (accessed 2011)"},{"key":"199_CR39","unstructured":"Harada, T., Horie, T., Tanaka, K.: Towards a manageable Linux security. In: Proceedings of the Linux conference 2005 (Japanese), Japan (2005)"},{"key":"199_CR40","unstructured":"Morris, J.: Filesystem labeling in SELinux. Linux J. 126, 22\u201324 (2004)"},{"key":"199_CR41","unstructured":"Schaufler, C.: The simplified mandatory access control kernel. http:\/\/schaufler-ca.com\/ (2008)"},{"key":"199_CR42","unstructured":"Department of Defense: Trusted computer security evaluation criteria. DOD 5200.28-STD (1985)"},{"key":"199_CR43","unstructured":"Boebert, W.E., Kain, R.Y.: A practical alternative to hierarchical integrity policies. In: Proceedings of the 8th National Computer Security Conference, pp. 18\u201327 (1985)"},{"key":"199_CR44","doi-asserted-by":"crossref","unstructured":"Schreuders, Z.C., Payne, C.: Reusability of functionality-based application confinement policy abstractions. In: Proceedings of the 10th International Conference on Information and Communications Security (ICICS 2008), Birmingham, UK. Springer (2008)","DOI":"10.1007\/978-3-540-88625-9_14"},{"key":"199_CR45","doi-asserted-by":"crossref","unstructured":"Schreuders, Z.C., Payne, C., McGill, T.: A Policy language for abstraction and automation in application-oriented access controls: the functionality-based application confinement policy language. In: Proceedings of the IEEE International Symposium on Policies for Distributed Systems and Networks (POLICY 2011), Italy, Pisa. IEEE Computer Society (2011)","DOI":"10.1109\/POLICY.2011.11"},{"key":"199_CR46","doi-asserted-by":"crossref","unstructured":"Schreuders, Z.C., Payne, C., McGill, T.: Techniques for automating policy specification for application-oriented access controls. In: Proceedings of the 6th International Conference on Availability, Reliability and Security (ARES 2011), Vienna, Austria. IEEE Computer Society (2011)","DOI":"10.1109\/ARES.2011.47"},{"issue":"1","key":"199_CR47","doi-asserted-by":"crossref","first-page":"57","DOI":"10.4018\/jisp.2012010104","volume":"6","author":"ZC Schreuders","year":"2012","unstructured":"Schreuders, Z.C., McGill, T., Payne, C.: Towards usable application-oriented access controls: qualitative results from a usability study of SELinux, AppArmor and FBAC-LSM. Int. J. Inf. Secur. Priv. 6(1), 57\u201376 (2012)","journal-title":"Int. J. Inf. Secur. Priv."},{"issue":"2","key":"199_CR48","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/2019599.2019604","volume":"14","author":"ZC Schreuders","year":"2011","unstructured":"Schreuders, Z.C., McGill, T., Payne, C.: Empowering end users to confine their own applications: the results of a usability study comparing SELinux, AppArmor and FBAC-LSM. ACM Trans. Inf. Syst. Secur. (TISSEC) 14(2), 1\u201328 (2011)","journal-title":"ACM Trans. Inf. Syst. Secur. (TISSEC)"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-013-0199-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10207-013-0199-4\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-013-0199-4","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,7,13]],"date-time":"2019-07-13T17:41:44Z","timestamp":1563039704000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10207-013-0199-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013,5,12]]},"references-count":48,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2013,10]]}},"alternative-id":["199"],"URL":"https:\/\/doi.org\/10.1007\/s10207-013-0199-4","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"value":"1615-5262","type":"print"},{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2013,5,12]]}}}