{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,28]],"date-time":"2025-09-28T20:26:32Z","timestamp":1759091192905,"version":"3.41.0"},"reference-count":20,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2012,3,1]],"date-time":"2012-03-01T00:00:00Z","timestamp":1330560000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Commun. ACM"],"published-print":{"date-parts":[[2012,3]]},"abstract":"<jats:p>\n            Capsicum is a lightweight operating system (OS) capability and sandbox framework planned for inclusion in FreeBSD 9. Capsicum extends, rather than replaces, UNIX APIs, providing new kernel primitives (sandboxed\n            <jats:italic>capability mode<\/jats:italic>\n            and\n            <jats:italic>capabilities<\/jats:italic>\n            ) and a userspace sandbox API. These tools support decomposition of monolithic UNIX applications into compartmentalized logical applications, an increasingly common goal that is supported poorly by existing OS access control primitives. We demonstrate our approach by adapting core FreeBSD utilities and Google's Chromium Web browser to use Capsicum primitives, and compare the complexity and robustness of Capsicum with other sandboxing techniques.\n          <\/jats:p>","DOI":"10.1145\/2093548.2093572","type":"journal-article","created":{"date-parts":[[2012,2,22]],"date-time":"2012-02-22T18:42:36Z","timestamp":1329936156000},"page":"97-104","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":23,"title":["A taste of Capsicum"],"prefix":"10.1145","volume":"55","author":[{"given":"Robert N. M.","family":"Watson","sequence":"first","affiliation":[{"name":"University of Cambridge, Cambridge, U.K."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jonathan","family":"Anderson","sequence":"additional","affiliation":[{"name":"University of Cambridge, Cambridge, U.K."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ben","family":"Laurie","sequence":"additional","affiliation":[{"name":"Google UK Ltd., London, U.K."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kris","family":"Kennaway","sequence":"additional","affiliation":[{"name":"Google UK Ltd., London, U.K."}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2012,3]]},"reference":[{"key":"e_1_2_1_1_1","volume-title":"M","author":"Accetta M.","year":"1986","unstructured":"Accetta , M. , Baron , R. , Golub , D. , Rashid , R. , Tevanian , A. , Young , M . Mach : A New Kernel Foundation for UNIX Development. Technical report, Computer Science Department, Carnegie Mellon University , Pittsburgh, PA, Aug. 1986 . Accetta, M., Baron, R., Golub, D., Rashid, R., Tevanian, A., Young, M. Mach: A New Kernel Foundation for UNIX Development. Technical report, Computer Science Department, Carnegie Mellon University, Pittsburgh, PA, Aug. 1986."},{"key":"e_1_2_1_2_1","volume-title":"Proceedings of the 5th USENIX Symposium on Networked Systems Design and Implementation","author":"Bittau A.","year":"2008","unstructured":"Bittau , A. , Marchenko , P. , Handley , M. , Karp , B. Wedge : Splitting applications into reduced-privilege compartments . In Proceedings of the 5th USENIX Symposium on Networked Systems Design and Implementation ( 2008 ), USENIX Association, 309--322. Bittau, A., Marchenko, P., Handley, M., Karp, B. Wedge: Splitting applications into reduced-privilege compartments. In Proceedings of the 5th USENIX Symposium on Networked Systems Design and Implementation (2008), USENIX Association, 309--322."},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/800213.806532"},{"key":"e_1_2_1_4_1","volume-title":"Proceedings of the Internet Society","author":"Garfinkel T.","year":"2003","unstructured":"Garfinkel , T. , Pfa , B. , Rosenblum , M. Ostia : A delegating architecture for secure system call interposition . In Proceedings of the Internet Society ( 2003 ). Garfinkel, T., Pfa, B., Rosenblum, M. Ostia: A delegating architecture for secure system call interposition. In Proceedings of the Internet Society (2003)."},{"volume-title":"Design Documents: OS X Sandboxing Design","author":"Google","key":"e_1_2_1_5_1","unstructured":"Google , Inc. The Chromium Project : Design Documents: OS X Sandboxing Design . http:\/\/dev.chromium.org\/developers\/design-documents\/sandbox\/osx-sandboxing-design, Oct. 2010. Google, Inc. The Chromium Project: Design Documents: OS X Sandboxing Design. http:\/\/dev.chromium.org\/developers\/design-documents\/sandbox\/osx-sandboxing-design, Oct. 2010."},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/858336.858337"},{"key":"e_1_2_1_7_1","volume-title":"Proceedings of USENIX Annual Technical Conference","author":"Kilpatrick D.","year":"2003","unstructured":"Kilpatrick , D. Privman : A library for partitioning applications . In Proceedings of USENIX Annual Technical Conference ( 2003 ), USENIX Association, 273--284. Kilpatrick, D. Privman: A library for partitioning applications. In Proceedings of USENIX Annual Technical Conference (2003), USENIX Association, 273--284."},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/224056.224075"},{"key":"e_1_2_1_9_1","volume-title":"Proceedings of the USENIX Annual Technical Conference (June","author":"Loscocco P.A.","year":"2001","unstructured":"Loscocco , P.A. , Smalley , S.D. Integrating flexible support for security policies into the Linux operating system . In Proceedings of the USENIX Annual Technical Conference (June 2001 ), USENIX Association, 29--42. Loscocco, P.A., Smalley, S.D. Integrating flexible support for security policies into the Linux operating system. In Proceedings of the USENIX Annual Technical Conference (June 2001), USENIX Association, 29--42."},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/1355284.1355292"},{"key":"e_1_2_1_11_1","volume-title":"Its Applications, and Proofs","author":"Neumann P.G.","year":"1980","unstructured":"Neumann , P.G. , Boyer , R.S. , Feiertag , R.J. , Levitt , K.N. , Robinson , L. A Provably Secure Operating System: The System , Its Applications, and Proofs , Second Edition. Technical Report CSL-116, Computer Science Laboratory, SRI International, Menlo Park, CA , May 1980 . Neumann, P.G., Boyer, R.S., Feiertag, R.J., Levitt, K.N., Robinson, L. A Provably Secure Operating System: The System, Its Applications, and Proofs, Second Edition. Technical Report CSL-116, Computer Science Laboratory, SRI International, Menlo Park, CA, May 1980."},{"key":"e_1_2_1_12_1","volume-title":"Proceedings of the 12th USENIX Security Symposium","author":"Provos N.","year":"2003","unstructured":"Provos , N. , Friedl , M. , Honeyman , P. Preventing privilege escalation . In Proceedings of the 12th USENIX Security Symposium ( 2003 ), USENIX Association. Provos, N., Friedl, M., Honeyman, P. Preventing privilege escalation. In Proceedings of the 12th USENIX Security Symposium (2003), USENIX Association."},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1519065.1519090"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/PROC.1975.9939"},{"key":"e_1_2_1_15_1","volume-title":"Proceedings of the 18th Annual Computer Security Applications Conference","author":"Sami Saydjari O.","year":"2002","unstructured":"Sami Saydjari , O. Lock : An historical perspective . In Proceedings of the 18th Annual Computer Security Applications Conference ( 2002 ), IEEE Computer Society. Sami Saydjari, O. Lock: An historical perspective. In Proceedings of the 18th Annual Computer Security Applications Conference (2002), IEEE Computer Society."},{"key":"e_1_2_1_16_1","volume-title":"Plash: Tools for practical least privilege","author":"Seaborn M.","year":"2007","unstructured":"Seaborn , M. Plash: Tools for practical least privilege , 2007 . http:\/\/plash.beasts.org\/ Seaborn, M. Plash: Tools for practical least privilege, 2007. http:\/\/plash.beasts.org\/"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/319151.319163"},{"key":"e_1_2_1_18_1","volume-title":"Proceedings of the 19th USENIX Security Symposium","author":"Watson R.N.M.","year":"2010","unstructured":"Watson , R.N.M. , Anderson , J. , Laurie , B. , Kennaway , K. Capsicum : Practical capabilities for UNIX . In Proceedings of the 19th USENIX Security Symposium ( 2010 ), USENIX Association, Berkeley, CA. Watson, R.N.M., Anderson, J., Laurie, B., Kennaway, K. Capsicum: Practical capabilities for UNIX. In Proceedings of the 19th USENIX Security Symposium (2010), USENIX Association, Berkeley, CA."},{"key":"e_1_2_1_19_1","volume-title":"Proceedings of the Third DARPA Information Survivability Conference and Exhibition (DISCEX) (April","author":"Watson R.N.M.","year":"2003","unstructured":"Watson , R.N.M. , Feldman , B. , Migus , A. , Vance , C. Design and implementation of the TrustedBSD MAC framework . In Proceedings of the Third DARPA Information Survivability Conference and Exhibition (DISCEX) (April 2003 ), IEEE. Watson, R.N.M., Feldman, B., Migus, A., Vance, C. Design and implementation of the TrustedBSD MAC framework. In Proceedings of the Third DARPA Information Survivability Conference and Exhibition (DISCEX) (April 2003), IEEE."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.5555\/1098638"}],"container-title":["Communications of the ACM"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2093548.2093572","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2093548.2093572","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T09:54:48Z","timestamp":1750240488000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2093548.2093572"}},"subtitle":["practical capabilities for UNIX"],"short-title":[],"issued":{"date-parts":[[2012,3]]},"references-count":20,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2012,3]]}},"alternative-id":["10.1145\/2093548.2093572"],"URL":"https:\/\/doi.org\/10.1145\/2093548.2093572","relation":{},"ISSN":["0001-0782","1557-7317"],"issn-type":[{"type":"print","value":"0001-0782"},{"type":"electronic","value":"1557-7317"}],"subject":[],"published":{"date-parts":[[2012,3]]},"assertion":[{"value":"2012-03-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}