Skip to Main Content (Press Enter)

Logo UNIBG
  • ×
  • Home
  • Corsi
  • Insegnamenti
  • Persone
  • Pubblicazioni
  • Strutture
  • Terza Missione
  • Attività
  • Competenze

UNI-FIND
Logo UNIBG

|

UNI-FIND

unibg.it
  • ×
  • Home
  • Corsi
  • Insegnamenti
  • Persone
  • Pubblicazioni
  • Strutture
  • Terza Missione
  • Attività
  • Competenze
  1. Pubblicazioni

Sandboxing and Data Protection in Cloud Computing Environments

Libro
Data di Pubblicazione:
2026
Citazione:
(2026). Sandboxing and Data Protection in Cloud Computing Environments . Retrieved from https://hdl.handle.net/10446/330565 Retrieved from http://dx.doi.org/10.13122/978-88-97253-40-2
Abstract:
Cloud systems provide a flexible and efficient approach to managing modern applications and services. Their adaptability enables developers to define interactions among services, allocate resources as needed, and support scalable application development. However, the complexity of these systems, along with the sensitive data they often handle, necessitates robust security and data protection mechanisms.
This book presents novel approaches to enhancing security in cloud environments by leveraging Linux kernel modules to enforce sandboxing on running processes. The proposed solutions aim to strengthen existing security and data protection techniques in cloud computing by enabling the definition and enforcement of fine-grained security policies, ultimately improving system resilience and trustworthiness.
To achieve this goal, the proposed solutions leverage modern Linux Security Modules (LSMs), such as Landlock LSM, eBPF LSM, and Seccomp, to enforce a security sandbox compliant with the principle of least privilege, thereby restricting access to the underlying system for JavaScript- and TypeScript-based runtimes. Their flexibility and transparency enable the definition of developer-friendly policies that can be enforced at different levels of granularity (e.g., system resources, inter-process communication, and network resources), contributing to reducing the operating system’s attack surface and enhancing its protection.
A similar protection model is also proposed for more modern runtimes based on WebAssembly and the WebAssembly System Interface (WASI). Finally, a technique to enhance data protection in decentralized networks is introduced, leveraging the cryptographic properties of All-or-Nothing Transforms.
Tipologia CRIS:
1.9.03 Collana della Scuola di Alta Formazione Dottorale
Elenco autori:
Abbadini, Marco
Autori di Ateneo:
ABBADINI Marco
Link alla scheda completa:
https://aisberg.unibg.it/handle/10446/330565
Link al Full Text:
https://aisberg.unibg.it/retrieve/handle/10446/330565/974174/CollanaSAFD_Volume85_2026.pdf
Pubblicato in:
COLLANA DELLA SCUOLA DI ALTA FORMAZIONE DOTTORALE
Series
  • Ricerca

Ricerca

Settori (2)


PE6_5 - Security, privacy, cryptology, quantum cryptography - (2024)

Settore IINF-05/A - Sistemi di elaborazione delle informazioni
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 26.7.2.0