posted by Thom Holwerda on Sat 9th Sep 2006 17:19 UTC, submitted by anonymous
IconAsbestos, a new prototype operating system, provides labeling and isolation mechanisms that help contain the effects of exploitable software flaws. Applications can express a wide range of policies with Asbestos's kernel-enforced label mechanism, including controls on inter-process communication and system-wide information flow. A new event process abstraction provides lightweight, isolated contexts within a single process, allowing the same process to act on behalf of multiple users while preventing it from leaking any single user's data to any other user. Initial tests have been promising, and Eddie Kohler, Asbestos's creator, hopes that within a few years, Asbestos will be an alternative to server operating systems such as Linux and Windows.
e p (2)    32 Comment(s)

Related Articles

posted by Thom Holwerda on Tue 6th Jan 2009 16:43 submitted by Matthew Whitworth
posted by weildish on Wed 31st Dec 2008 23:52
posted by Thom Holwerda on Wed 31st Dec 2008 18:26