Publication Date:
2026
Short description:
(2026). Sandboxing and Data Protection in Cloud Computing Environments . Retrieved from https://hdl.handle.net/10446/330565 Retrieved from http://dx.doi.org/10.13122/978-88-97253-40-2
abstract:
Cloud systems provide a flexible and efficient approach to managing modern applications and services. Their adaptability enables developers to define interactions among services, allocate resources as needed, and support scalable application development. However, the complexity of these systems, along with the sensitive data they often handle, necessitates robust security and data protection mechanisms.
This book presents novel approaches to enhancing security in cloud environments by leveraging Linux kernel modules to enforce sandboxing on running processes. The proposed solutions aim to strengthen existing security and data protection techniques in cloud computing by enabling the definition and enforcement of fine-grained security policies, ultimately improving system resilience and trustworthiness.
To achieve this goal, the proposed solutions leverage modern Linux Security Modules (LSMs), such as Landlock LSM, eBPF LSM, and Seccomp, to enforce a security sandbox compliant with the principle of least privilege, thereby restricting access to the underlying system for JavaScript- and TypeScript-based runtimes. Their flexibility and transparency enable the definition of developer-friendly policies that can be enforced at different levels of granularity (e.g., system resources, inter-process communication, and network resources), contributing to reducing the operating system’s attack surface and enhancing its protection.
A similar protection model is also proposed for more modern runtimes based on WebAssembly and the WebAssembly System Interface (WASI). Finally, a technique to enhance data protection in decentralized networks is introduced, leveraging the cryptographic properties of All-or-Nothing Transforms.
This book presents novel approaches to enhancing security in cloud environments by leveraging Linux kernel modules to enforce sandboxing on running processes. The proposed solutions aim to strengthen existing security and data protection techniques in cloud computing by enabling the definition and enforcement of fine-grained security policies, ultimately improving system resilience and trustworthiness.
To achieve this goal, the proposed solutions leverage modern Linux Security Modules (LSMs), such as Landlock LSM, eBPF LSM, and Seccomp, to enforce a security sandbox compliant with the principle of least privilege, thereby restricting access to the underlying system for JavaScript- and TypeScript-based runtimes. Their flexibility and transparency enable the definition of developer-friendly policies that can be enforced at different levels of granularity (e.g., system resources, inter-process communication, and network resources), contributing to reducing the operating system’s attack surface and enhancing its protection.
A similar protection model is also proposed for more modern runtimes based on WebAssembly and the WebAssembly System Interface (WASI). Finally, a technique to enhance data protection in decentralized networks is introduced, leveraging the cryptographic properties of All-or-Nothing Transforms.
Iris type:
1.9.03 Collana della Scuola di Alta Formazione Dottorale
List of contributors:
Abbadini, Marco
Full Text:
Published in: