Cloud systems provide a flexible and efficient approach to managing modern applications and services. Their adaptability enables developers to define interactions among services, allocate resources as needed, and support scalable application development. However, the complexity of these systems, along with the sensitive data they often handle, necessitates robust security and data protection mechanisms. This book presents novel approaches to enhancing security in cloud environments by leveraging Linux kernel modules to enforce sandboxing on running processes. The proposed solutions aim to strengthen existing security and data protection techniques in cloud computing by enabling the definition and enforcement of fine-grained security policies, ultimately improving system resilience and trustworthiness. To achieve this goal, the proposed solutions leverage modern Linux Security Modules (LSMs), such as Landlock LSM, eBPF LSM, and Seccomp, to enforce a security sandbox compliant with the principle of least privilege, thereby restricting access to the underlying system for JavaScript- and TypeScript-based runtimes. Their flexibility and transparency enable the definition of developer-friendly policies that can be enforced at different levels of granularity (e.g., system resources, inter-process communication, and network resources), contributing to reducing the operating system’s attack surface and enhancing its protection. A similar protection model is also proposed for more modern runtimes based on WebAssembly and the WebAssembly System Interface (WASI). Finally, a technique to enhance data protection in decentralized networks is introduced, leveraging the cryptographic properties of All-or-Nothing Transforms.
(2026). Sandboxing and Data Protection in Cloud Computing Environments . Retrieved from https://hdl.handle.net/10446/330565 Retrieved from http://dx.doi.org/10.13122/978-88-97253-40-2
Sandboxing and Data Protection in Cloud Computing Environments
Abbadini, Marco
2026-07-13
Abstract
Cloud systems provide a flexible and efficient approach to managing modern applications and services. Their adaptability enables developers to define interactions among services, allocate resources as needed, and support scalable application development. However, the complexity of these systems, along with the sensitive data they often handle, necessitates robust security and data protection mechanisms. This book presents novel approaches to enhancing security in cloud environments by leveraging Linux kernel modules to enforce sandboxing on running processes. The proposed solutions aim to strengthen existing security and data protection techniques in cloud computing by enabling the definition and enforcement of fine-grained security policies, ultimately improving system resilience and trustworthiness. To achieve this goal, the proposed solutions leverage modern Linux Security Modules (LSMs), such as Landlock LSM, eBPF LSM, and Seccomp, to enforce a security sandbox compliant with the principle of least privilege, thereby restricting access to the underlying system for JavaScript- and TypeScript-based runtimes. Their flexibility and transparency enable the definition of developer-friendly policies that can be enforced at different levels of granularity (e.g., system resources, inter-process communication, and network resources), contributing to reducing the operating system’s attack surface and enhancing its protection. A similar protection model is also proposed for more modern runtimes based on WebAssembly and the WebAssembly System Interface (WASI). Finally, a technique to enhance data protection in decentralized networks is introduced, leveraging the cryptographic properties of All-or-Nothing Transforms.| File | Dimensione del file | Formato | |
|---|---|---|---|
|
CollanaSAFD_Volume85_2026.pdf
accesso aperto
Versione:
publisher's version - versione editoriale
Licenza:
Creative commons
Dimensione del file
2.12 MB
Formato
Adobe PDF
|
2.12 MB | Adobe PDF | Visualizza/Apri |
Pubblicazioni consigliate
Aisberg ©2008 Servizi bibliotecari, Università degli studi di Bergamo | Terms of use/Condizioni di utilizzo

