Skip to main navigation Skip to search Skip to main content

StemJail: Dynamic role compartmentalization

  • ANSSI

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

While users tend to indiscriminately use the same device to address every need, exfiltration of information becomes the end game of attackers. Average users need realistic and practical solutions to enable them to mitigate the consequences of a security breach in terms of data leakage. We present StemJail, an open-source security solution to isolate groups of processes pertaining to the same activity into an environment exposing only the relevant subset of user data. At the heart of our solution lies dynamic activity discovery, allowing seamless integration of StemJail into the user workow. Our userland access control framework only relies on the ability of user to organize data in directories. Thus, it is easily configurable and requires very little user interaction once set up. Moreover, StemJail is designed to run without intrusive changes to the system and to be configured and used by any unprivileged user thanks to the Linux user namespaces.

Original languageEnglish
Title of host publicationASIA CCS 2016 - Proceedings of the 11th ACM Asia Conference on Computer and Communications Security
PublisherAssociation for Computing Machinery, Inc
Pages865-876
Number of pages12
ISBN (Electronic)9781450342339
DOIs
Publication statusPublished - 30 May 2016
Event11th ACM Asia Conference on Computer and Communications Security, ASIA CCS 2016 - Xi'an, China
Duration: 30 May 20163 Jun 2016

Publication series

NameASIA CCS 2016 - Proceedings of the 11th ACM Asia Conference on Computer and Communications Security

Conference

Conference11th ACM Asia Conference on Computer and Communications Security, ASIA CCS 2016
Country/TerritoryChina
CityXi'an
Period30/05/163/06/16

Keywords

  • Compartmentalization
  • Dynamic policy
  • Linux
  • Namespaces
  • Role
  • Sandbox
  • User activity

Fingerprint

Dive into the research topics of 'StemJail: Dynamic role compartmentalization'. Together they form a unique fingerprint.

Cite this