Content-Based Isolation: Rethinking Isolation Policy in Modern Client Systems

نویسندگان

  • Alexander Moshchuk
  • Helen J. Wang
  • Yunxin Liu
چکیده

Modern client platforms, such as iOS, Android, Windows Phone 7, and Windows 8, have progressed from a per-user isolation policy, where users are isolated, but a user’s applications run in the same isolation container, to an application isolation policy, where different applications are isolated from one another. However, this is not enough because mutually distrusting content can interfere with one another inside a single application. For example, an attacker-crafted image may compromise a photo editor application and steal all images processed by the editor. In this paper, we advocate a content-based principal model in which the OS treats content owners as its principals and isolates content of different owners from one another. Our key contribution is to generalize the contentbased principal model from web browsers, namely, the same-origin policy, into an isolation policy that is suitable for all applications. The key challenge we faced is to support flexible isolation granularities while remaining compatible with the web. In this paper, we present the design, implementation, and evaluation of our prototype system that tackles the challenge.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Social Marginalization of Patients with Ostomy: A Content- Based Analysis

Background: A few studies have addressed the impact of stoma on patients’ social life. This study aimed to understand the problems leading to social isolation of patients undergoing ostomy. Methods: A conventional qualitative content analysis by unstructured interviews was conducted on 27 patients with intestinal or urinary diversion ostomy recruited from the Iranian Ostomy&nbs...

متن کامل

Degrees of Transaction Isolation in SQL*Cache: A Predicate-based Client-side Caching System

A caching scheme that uses query predicates to cache data on the client-side in a client-server relational database system was presented in [15]. The client-side cache (henceforth referred to as a SQL*Cache), loads query results dynamically in the course of transaction execution, and formulates a cache description based on the query predicates. SQL*Cache is associative in nature, in that it sup...

متن کامل

The Prediction of Distress Tolerance based on Brain-Behavioral Systems, HEXACO Personality Characteristics and Social Isolation in Substance-Dependent Individuals

Objective: The aim of this study was to predict distress tolerance based on brain-behavioral systems, HEXACO personality characteristics and social isolation in substance-dependent individuals. Method: The present study was descriptive-correlational. The statistical population of this study included all substance-dependent men referred to addiction treatment centers in Tehran in 2020. According...

متن کامل

Base Isolation Systems – A State of the Art Review According to Their Mechanism

Seismic isolation is a method to reduce the destructive effects of earthquakes on a structure in which the structure is separated from its foundation by devices called seismic isolators. As a result, the horizontal movements of the earthquake transmitted to the structure are reduced. The seismic isolation is used for both newly constructed structures as well as for retrofitting the existing bui...

متن کامل

Seeing is Believing: A Client-Centric Specification of Database Isolation

This paper introduces the first state-based formalization of isolation guarantees. Our approach is premised on a simple observation: applications view storage systems as black-boxes that transition through a series of states, a subset of which are observed by applications. Defining isolation guarantees in terms of these states frees definitions from implementation-specific assumptions. It makes...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2012