|
ABSTRACT
Mobile code and mobile agents are generally associated with security vulnerabilities, rather than with increased security. This paper describes an approach in which mobile agents are confined, in order to allow content providers to retain control over how their data is exported while allowing agents to search the full content of this data locally. This approach offers increased control and security compared to the traditional client-server technologies commonly used for building distributed systems. We describe a new system, called Mansion, which implements confinement of mobile agents, and describe a number of applications of the confinement model to illustrate its potential.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
S. Vinoski. CORBA: Integrating Diverse Applications Within Distributed Heterogeneous Environments. IEEE Communications Magazine, 14(2), February 1997.
|
| |
2
|
|
| |
3
|
|
| |
4
|
IBM. Web Services Security (WS-Security). 2002. http://www-106.ibm.com/developerworks/webservices/library/ws-secure/.
|
| |
5
|
I. Cox; J. Kilian; T. Leighton; T. Shamoon. Secure Spread Spectrum Watermarking for Multimedia. IEEE Transactions on Image Processing vol. 6, no. 12, pages 1673--1687, 1997.
|
| |
6
|
A. M. Eskicioglu; J. Town; E. J. Delp. Security of Digital Entertainment Content from Creation to Consumption. Signal Processing: Image Communication, 18(4), pages 237--262, 2003.
|
| |
7
|
|
| |
8
|
|
| |
9
|
|
| |
10
|
G. J. van 't Noordende; F. M. T. Brazier; A. S. Tanenbaum. Security in a Mobile Agent System. 1st IEEE Symposium on Multi-Agent Security and Survivability, 2004. Philadelphia, PA.
|
| |
11
|
G. J. van 't Noordende; A. Balogh; R. F. H. Hofman; F. M. T. Brazier; A. S. Tanenbaum. A Secure and Portable Jailing System. Technical Report IR-CS-025, Vrije Universiteit, October 2006.
|
| |
12
|
T. Garfinkel. Traps and Pitfalls: Practical Problems in System Call Interception Based Security Tools. Proc. Symposium on Network and Distributed System Security (NDSS), 2003. pp. 163--176.
|
| |
13
|
|
 |
14
|
Bruce Walker , Gerald Popek , Robert English , Charles Kline , Greg Thiel, The LOCUS distributed operating system, Proceedings of the ninth ACM symposium on Operating systems principles, p.49-70, October 10-13, 1983, Bretton Woods, New Hampshire, United States
|
| |
15
|
Niranjan Suri , Jeffrey Bradshaw , Maggie R. Breedy , Paul T. Groth , Gregory A. Hill , Renia Jeffers, Strong Mobility and Fine-Grained Resource Control in NOMADS, Proceedings of the Second International Symposium on Agent Systems and Applications and Fourth International Symposium on Mobile Agents, p.2-15, September 13-15, 2000
|
| |
16
|
|
| |
17
|
A. J. Chakravarti; X. Wang; J. O. Hallstrom; G. Baumgartner. Implementation of Strong Mobility for Multi-Threaded Agents in Java. Proc. International Conference on Parallel Processing (ICPP), 2003.
|
| |
18
|
|
| |
19
|
|
 |
20
|
Walter Binder , Jane G. Hulaas , Alex Villazón, Portable resource control in Java, Proceedings of the 16th ACM SIGPLAN conference on Object oriented programming, systems, languages, and applications, p.139-155, October 14-18, 2001, Tampa Bay, FL, USA
|
 |
21
|
|
| |
22
|
J. E. White. Telescript Technology: Mobile Agents. White paper, General Magic, 1996.
|
| |
23
|
J. Baumann; F. Hohl; M. Strasser; K. Rothermel. Mole - Concepts of a Mobile Agent System. Technical Report, Universität Stuttgart, August 1997.
|
| |
24
|
|
| |
25
|
|
| |
26
|
|
| |
27
|
|
| |
28
|
|
| |
29
|
|
| |
30
|
|
| |
31
|
|
| |
32
|
T. Garfinkel; B. Pfaff; M. Rosenblum. Ostia: A Delegating Architecture for Secure System Call Interposition. Proc. ISOC Network and Distributed System Security Symposium (NDSS), 2004.
|
| |
33
|
Ian Goldberg , David Wagner , Randi Thomas , Eric A. Brewer, A secure environment for untrusted helper applications confining the Wily Hacker, Proceedings of the 6th conference on USENIX Security Symposium, Focusing on Applications of Cryptography, p.1-1, July 22-25, 1996, San Jose, California
|
| |
34
|
K. Jain; R. Sekar. User-Level Infrastructure for System Call Interposition: A Platform for Intrusion detection and Confinement. ISOC Network and Distributed System Security Symposium (NDSS), 2000. pp. 19--34.
|
| |
35
|
T. Shinagawa; K. Kono; T. Masuda. Flexible and Efficient Sandboxing Based on Fine-Grained Protection Domains. ISSS, 2002. pp. 172--184.
|
| |
36
|
|
 |
37
|
|
| |
38
|
Godmar Back , Wilson C. Hsieh , Jay Lepreau, Processes in KaffeOS: isolation, resource management, and sharing in java, Proceedings of the 4th conference on Symposium on Operating System Design & Implementation, p.23-23, October 22-25, 2000, San Diego, California
|
|