{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T15:42:52Z","timestamp":1785512572741,"version":"3.56.0"},"reference-count":33,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2011,9,1]],"date-time":"2011-09-01T00:00:00Z","timestamp":1314835200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Inf. Syst. Secur."],"published-print":{"date-parts":[[2011,9]]},"abstract":"<jats:p>Protecting end users from security threats is an extremely difficult, but increasingly critical, problem. Traditional security models that focused on separating users from each other have proven ineffective in an environment of widespread software vulnerabilities and rampant malware. However, alternative approaches that provide more finely grained security generally require greater expertise than typical end users can reasonably be expected to have, and consequently have had limited success.<\/jats:p>\n          <jats:p>The functionality-based application confinement (FBAC) model is designed to allow end users with limited expertise to assign applications hierarchical and parameterised policy abstractions based upon the functionalities each program is intended to perform. To validate the feasibility of this approach and assess the usability of existing mechanisms, a usability study was conducted comparing an implementation of the FBAC model with the widely used Linux-based SELinux and AppArmor security schemes. The results showed that the functionality-based mechanism enabled end users to effectively control the privileges of their applications with far greater success than widely used alternatives. In particular, policies created using FBAC were more likely to be enforced and exhibited significantly lower risk exposure, while not interfering with the ability of the application to perform its intended task. In addition to the success of the functionality-based approach, the usability study also highlighted a number of limitations and problems with existing mechanisms. These results indicate that a functionality-based approach has significant potential in terms of enabling end users with limited expertise to defend themselves against insecure and malicious software.<\/jats:p>","DOI":"10.1145\/2019599.2019604","type":"journal-article","created":{"date-parts":[[2011,10,4]],"date-time":"2011-10-04T13:24:18Z","timestamp":1317734658000},"page":"1-28","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":27,"title":["Empowering End Users to Confine Their Own Applications"],"prefix":"10.1145","volume":"14","author":[{"given":"Z. Cliffe","family":"Schreuders","sequence":"first","affiliation":[{"name":"Murdoch University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tanya","family":"McGill","sequence":"additional","affiliation":[{"name":"Murdoch University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christian","family":"Payne","sequence":"additional","affiliation":[{"name":"Murdoch University"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2011,9]]},"reference":[{"key":"e_1_2_1_1_1","volume-title":"Proceedings of the Security Enhanced Linux Symposium.","author":"Athey J.","unstructured":"Athey , J. , Ashworth , C. , Mayer , F. , and Miner , D . 2007. Towards intuitive tools for managing SELinux: Hiding the details but retaining the power . In Proceedings of the Security Enhanced Linux Symposium. Athey, J., Ashworth, C., Mayer, F., and Miner, D. 2007. Towards intuitive tools for managing SELinux: Hiding the details but retaining the power. In Proceedings of the Security Enhanced Linux Symposium."},{"key":"e_1_2_1_2_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy. IEEE Computer Society.","author":"Badger L.","unstructured":"Badger , L. , Sterne , D. F. , Sherman , D. L. , Walker , K. M. , and Haghighat , S. A . 1995. Practical domain and type enforcement for UNIX . In Proceedings of the IEEE Symposium on Security and Privacy. IEEE Computer Society. Badger, L., Sterne, D. F., Sherman, D. L., Walker, K. M., and Haghighat, S. A. 1995. Practical domain and type enforcement for UNIX. In Proceedings of the IEEE Symposium on Security and Privacy. IEEE Computer Society."},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1080\/10447310802205776"},{"key":"e_1_2_1_4_1","volume-title":"Proceedings of the Winter USENIX Conference. USENIX Association.","author":"Berman A.","unstructured":"Berman , A. , Bourassa , V. , and Selberg , E . 1995. TRON: Process-specific file protection for the UNIX operating system . In Proceedings of the Winter USENIX Conference. USENIX Association. Berman, A., Bourassa, V., and Selberg, E. 1995. TRON: Process-specific file protection for the UNIX operating system. In Proceedings of the Winter USENIX Conference. USENIX Association."},{"key":"e_1_2_1_5_1","volume-title":"SUS: A quick and dirty usability scale. In Usability Evaluation in Industry","author":"Brooke J.","year":"1996","unstructured":"Brooke , J. 1996 . SUS: A quick and dirty usability scale. In Usability Evaluation in Industry , P. W. Jordan, B. Thomas, B. A. Weerdmeester, and I. L. McClelland Eds. Taylor & Francis , London , 189--194. Brooke, J. 1996. SUS: A quick and dirty usability scale. In Usability Evaluation in Industry, P. W. Jordan, B. Thomas, B. A. Weerdmeester, and I. L. McClelland Eds. Taylor & Francis, London, 189--194."},{"key":"e_1_2_1_6_1","volume-title":"Proceedings of the USENIX 14th Systems Administration Conference (LISA). USENIX Association.","author":"Cowan C.","unstructured":"Cowan , C. , Beattie , S. , Kroah-Hartman , G. , Pu , C. , Wagle , P. , and Gligor , V . 2000. SubDomain: Parsimonious server security . In Proceedings of the USENIX 14th Systems Administration Conference (LISA). USENIX Association. Cowan, C., Beattie, S., Kroah-Hartman, G., Pu, C., Wagle, P., and Gligor, V. 2000. SubDomain: Parsimonious server security. In Proceedings of the USENIX 14th Systems Administration Conference (LISA). USENIX Association."},{"key":"e_1_2_1_7_1","unstructured":"Cranor L. and Garfinkel S. 2005. Security and Usability: Designing Secure Systems That People Can Use. O\u2019Reilly Media Inc. Cranor L. and Garfinkel S. 2005. Security and Usability: Designing Secure Systems That People Can Use . O\u2019Reilly Media Inc."},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/1143120.1143122"},{"key":"e_1_2_1_9_1","volume-title":"Proceedings of the 10th Network and Distributed System Security Symposium.","author":"Garfinkel T.","year":"2003","unstructured":"Garfinkel , T. 2003 . Traps and pitfalls: Practical problems in system call interposition based security tools . In Proceedings of the 10th Network and Distributed System Security Symposium. Garfinkel, T. 2003. Traps and pitfalls: Practical problems in system call interposition based security tools. In Proceedings of the 10th Network and Distributed System Security Symposium."},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1037\/0033-2909.83.2.314"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1016\/0167-4048(95)97088-R"},{"key":"e_1_2_1_12_1","volume-title":"Proceedings of the 2nd International System Administration and Networking Conference (SANE\u201900)","author":"Kamp P.-H.","unstructured":"Kamp , P.-H. and Watson , R . 2000. Jails: Confining the omnipotent root . In Proceedings of the 2nd International System Administration and Networking Conference (SANE\u201900) . Kamp, P.-H. and Watson, R. 2000. Jails: Confining the omnipotent root. In Proceedings of the 2nd International System Administration and Networking Conference (SANE\u201900)."},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1280680.1280697"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-02806-9_12"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/1455526.1455527"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/800122.803961"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-31845-3_2"},{"key":"e_1_2_1_18_1","volume-title":"Proceedings of the 23rd Large Installation System Administration Conference (LISA). USENIX Association.","author":"Nakamura Y.","unstructured":"Nakamura , Y. , Sameshima , Y. , and Tabata , T . 2009. SEEdit: SELinux security policy configuration system with higher level language . In Proceedings of the 23rd Large Installation System Administration Conference (LISA). USENIX Association. Nakamura, Y., Sameshima, Y., and Tabata, T. 2009. SEEdit: SELinux security policy configuration system with higher level language. In Proceedings of the 23rd Large Installation System Administration Conference (LISA). USENIX Association."},{"key":"e_1_2_1_19_1","unstructured":"Novell AppArmor and SELinux Comparison. http:\/\/www.novell.com\/linux\/security\/apparmor\/selinux_comparison.html. Novell AppArmor and SELinux Comparison . http:\/\/www.novell.com\/linux\/security\/apparmor\/selinux_comparison.html."},{"key":"e_1_2_1_20_1","unstructured":"Ott A. 2002. The Role Compatibility Security Model. Ott A. 2002. The Role Compatibility Security Model."},{"key":"e_1_2_1_21_1","volume-title":"Proceedings of the 21st Large Installation System Administration Conference (LISA\u201907)","author":"Potter S.","unstructured":"Potter , S. , Nieh , J. , and Selsky , M . 2007. Secure isolation of untrusted legacy applications . In Proceedings of the 21st Large Installation System Administration Conference (LISA\u201907) . USENIX Association. Potter, S., Nieh, J., and Selsky, M. 2007. Secure isolation of untrusted legacy applications. In Proceedings of the 21st Large Installation System Administration Conference (LISA\u201907). USENIX Association."},{"key":"e_1_2_1_22_1","volume-title":"Proceedings of the 12th USENIX Security Symposium. USENIX Association.","author":"Provos N.","year":"2002","unstructured":"Provos , N. 2002 . Improving host security with system call policies . In Proceedings of the 12th USENIX Security Symposium. USENIX Association. Provos, N. 2002. Improving host security with system call policies. In Proceedings of the 12th USENIX Security Symposium. USENIX Association."},{"key":"e_1_2_1_23_1","unstructured":"Rubin J. and Chisnell D. 2004. How to plan design and conduct effective tests. In Handbook of Usability Testing. Wiley India Pvt. Ltd. 129. Rubin J. and Chisnell D. 2004. How to plan design and conduct effective tests. In Handbook of Usability Testing . Wiley India Pvt. Ltd. 129."},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/PROC.1975.9939"},{"key":"e_1_2_1_25_1","volume-title":"Proceedings of the International Conference on Security and Cryptography (SECRYPT\u201908)","author":"Schreuders Z. C.","unstructured":"Schreuders , Z. C. and Payne , C . 2008a. Functionality-based application confinement: parameterised hierarchical application restrictions . In Proceedings of the International Conference on Security and Cryptography (SECRYPT\u201908) . INSTICC Press. Schreuders, Z. C. and Payne, C. 2008a. Functionality-based application confinement: parameterised hierarchical application restrictions. In Proceedings of the International Conference on Security and Cryptography (SECRYPT\u201908). INSTICC Press."},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-88625-9_14"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2011.47"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/1151030.1151033"},{"key":"e_1_2_1_29_1","volume-title":"Proceedings of the 3rd Virtual Machine Research and Technology Symposium Works-in-Progress.","author":"Tucker A.","unstructured":"Tucker , A. and Comay , D . 2004. Solaris zones: Operating system support for server consolidation . In Proceedings of the 3rd Virtual Machine Research and Technology Symposium Works-in-Progress. Tucker, A. and Comay, D. 2004. Solaris zones: Operating system support for server consolidation. In Proceedings of the 3rd Virtual Machine Research and Technology Symposium Works-in-Progress."},{"key":"e_1_2_1_30_1","unstructured":"Vance C. and Salamon W. 2001. Implementing SELinux as a Linux security module. NAI Labs rep. #01-043 NSA. Vance C. and Salamon W. 2001. Implementing SELinux as a Linux security module. NAI Labs rep. #01-043 NSA."},{"key":"e_1_2_1_31_1","volume-title":"Janus: An approach for confinement of untrusted applications. Tech. rep. CSD-99-1056","author":"Wagner D. A.","year":"1999","unstructured":"Wagner , D. A. 1999 . Janus: An approach for confinement of untrusted applications. Tech. rep. CSD-99-1056 , University of California , Berkeley. Wagner, D. A. 1999. Janus: An approach for confinement of untrusted applications. Tech. rep. CSD-99-1056, University of California, Berkeley."},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/990036.990059"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/304851.304859"}],"container-title":["ACM Transactions on Information and System Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2019599.2019604","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2019599.2019604","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T19:07:42Z","timestamp":1750273662000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2019599.2019604"}},"subtitle":["The Results of a Usability Study Comparing SELinux, AppArmor, and FBAC-LSM"],"short-title":[],"issued":{"date-parts":[[2011,9]]},"references-count":33,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2011,9]]}},"alternative-id":["10.1145\/2019599.2019604"],"URL":"https:\/\/doi.org\/10.1145\/2019599.2019604","relation":{},"ISSN":["1094-9224","1557-7406"],"issn-type":[{"value":"1094-9224","type":"print"},{"value":"1557-7406","type":"electronic"}],"subject":[],"published":{"date-parts":[[2011,9]]},"assertion":[{"value":"2010-09-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2011-06-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2011-09-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}