Microsoft is developing an open sandbox isolation system called Litebox

James Morris, maintainer of the Linux kernel security subsystem and head of the 'Linux Emerging Technologies' team at Microsoft, presented the Litebox project, positioned as a security-focused operating system in the form of a Library OS. Litebox can be used in applications or kernels as an additional layer of isolation, blocking access to excessive functionality of kernels or APIs to reduce the attack surface. The project's code is written in Rust and is open under the MIT license.

The idea behind 'Library OS' is that operating system services are directly embedded into the application instead of calling an external OS kernel through system calls. In the context of Litebox, an isolating layer is connected to applications, providing a minimal platform that translates requests to an external fully functional API. External interfaces may include the Linux kernel, protected isolated environments like OP-TEE (Open Portable Trusted Execution Environment), WebAssembly environments, or the standard RustStd library.

Microsoft is developing an open sandbox isolation system called Litebox

The minimal platform formed via Litebox is applicable for running Linux, Windows, and FreeBSD applications, embedded Linux kernels, and LVBS (Linux Virtualization Based Security). Potential use cases for Litebox include enabling unmodified Linux programs to run in Windows, isolating Linux applications on systems with a Linux kernel, running programs over AMD SEV SNP for memory encryption, executing OP-TEE programs in Linux, and isolation using the LVBS concept.

The LVBS project, whose representatives participate in the development of Litebox, develops methods to protect Linux kernel components using hypervisor capabilities and hardware virtualization. For instance, hypervisors can isolate operations for validating modules, verification, and access control for passwords, keys, kernel structures, and other critical resources. If a vulnerability is exploited and the kernel is compromised, the attacker will not be able to access such resources since their handlers are executed outside the current privilege level. Litebox is considered in the context of the LVBS project as a 'secure kernel' that protects the guest system's normal kernel using hardware virtualization.

Źródło: opennet.ru

Kup solidny hosting stron z ochroną przed DDoS, serwery VPS VDS 🔥 Kup solidny hosting stron z ochroną przed DDoS, serwery VPS VDS | ProHoster