Microsoft is developing an open Sandbox isolation system called Litebox

James Morris, the maintainer of the Linux kernel security subsystem and head of the Linux Emerging Technologies team at Microsoft, introduced the Litebox project, positioned as a security-focused operating system in the form of a Library OS. Litebox can be used in programs or kernels as an additional isolation layer that blocks access to unnecessary kernel functionality or APIs, thereby reducing the attack surface. The project's code is written in Rust and is open under the MIT license.

The idea of a Library OS is that operating system services are directly embedded into the application instead of calling an external OS kernel through system calls. In the context of Litebox, an isolating layer is connected to the applications, providing a minimal platform that translates requests to an external full-fledged programming interface. Such external interfaces can include the Linux kernel, secure isolated environments like OP-TEE (Open Portable Trusted Execution Environment), WebAssembly environments, or the standard Rust library (RustStd).

Microsoft is developing an open Sandbox isolation system called Litebox

The minimal platform provided by Litebox is applicable for running applications on Linux, Windows, and FreeBSD, including nested Linux kernels and Linux Virtualization Based Security (LVBS). Potential applications of Litebox include running unmodified Linux programs on Windows, isolating the execution of Linux applications on systems with a Linux kernel, executing programs over AMD SEV SNP for memory encryption, running OP-TEE programs in Linux, and using isolation based on the LVBS concept.

The LVBS project, whose representatives are involved in developing Litebox, is advancing methods for protecting Linux kernel components by leveraging hypervisor capabilities and hardware virtualization. For example, a hypervisor can isolate operations related to module authentication, verification, access control to passwords, keys, kernel structures, and other critical resources. In case of an exploitation of a vulnerability and kernel compromise, an attacker will not be able to access such resources, as their handlers are executed outside the current privilege level. Litebox is viewed in the context of the LVBS project as a 'secure kernel' that protects the ordinary kernel of the guest system through hardware virtualization.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster