Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Linux Foundation

Sandboxing in Linux with Zero Lines of Code

Linux Foundation via YouTube

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore Linux sandboxing techniques without writing code in this 49-minute conference talk by Ignat Korchagin from Cloudflare. Delve into the problem of process isolation, understand process startup stages, and examine a concrete example. Learn about protecting against readbystand, distributing lib sandbox, combining approaches, including dynamic libraries, filtering and collecting system calls, and setting sandbox limits. Discover how to modify allowed or blocked system calls and understand the implications of sandboxing executables. Gain valuable insights into enhancing security and process isolation in Linux environments through this informative presentation from the Linux Foundation.

Syllabus

Introduction
The Problem
Overview
Process Startup Stages
Concrete Example
Questions
Answering Questions
How do you protect against readbystand
Is lib sandbox distributed by distros
Can we use both approaches
How to include dynamic libraries
How to filter system calls
How to collect system calls
How to sandboxify a limit
Can you change allowed or blocked system calls
What happens when you try to sandbox an executable
Out of question
Outro

Taught by

Linux Foundation

Reviews

Start your review of Sandboxing in Linux with Zero Lines of Code

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.