posted by Thom Holwerda on Sat 9th Sep 2006 17:19 UTC, submitted by anonymous
IconAsbestos, a new prototype operating system, provides labeling and isolation mechanisms that help contain the effects of exploitable software flaws. Applications can express a wide range of policies with Asbestos's kernel-enforced label mechanism, including controls on inter-process communication and system-wide information flow. A new event process abstraction provides lightweight, isolated contexts within a single process, allowing the same process to act on behalf of multiple users while preventing it from leaking any single user's data to any other user. Initial tests have been promising, and Eddie Kohler, Asbestos's creator, hopes that within a few years, Asbestos will be an alternative to server operating systems such as Linux and Windows.
e p (2)    32 Comment(s)

Related Articles

posted by David Adams on Sat 11th Oct 2008 16:38, submitted by poundsmack
posted by Amjith Ramanujam on Sat 27th Sep 2008 01:16 submitted by J
posted by Amjith Ramanujam on Fri 26th Sep 2008 22:53