We can't find the internet
Attempting to reconnect
Something went wrong!
Hang in there while we get back on track
If you read one cluster, make it Martin Casado’s pairing of older systems research with a current AI-cyber concern. He argues that AI cyber capabilities should force us to build secure systems “all the way down” and names HYDRA and Asbestos as two of his favorites. The payoff is specificity: one paper makes protection and extensibility a kernel-design problem; the other turns isolation and information flow into explicit mechanisms.
Start with the systems-security pair
HYDRA: the kernel of a multiprocessor operating system
- Content type / creator: Research paper by W. Wulf et al., published in Communications of the ACM in 1974. Link:ACM record.
- Recommended by: Martin Casado, as one of his two favorite works on building secure systems.
- Key takeaway: HYDRA treats physical and virtual resources as “objects,” then supplies mechanisms for creating types, defining operations, sharing, and protecting references. The paper presents that as a basis both for extending the system and for creating highly secure systems.
- Why it matters: It gives readers a concrete vocabulary for asking where an AI-enabled system’s resources live, who can operate on them, and how those permissions are enforced.
Labels and event processes in the asbestos operating system
- Content type / creator: Research paper by Petros Efstathopoulos et al., published in ACM SIGOPS Operating Systems Review in 2005. Link:ACM record.
- Recommended by: Martin Casado, alongside HYDRA. The ACM record supplies the corrected title; his post spells it “Absestos.”
- Key takeaway: Asbestos uses kernel-enforced labels and isolation to control inter-process communication and system-wide information flow. Its event-process abstraction lets one process act for multiple users without leaking one user’s data to another; the abstract reports about 1.5 memory pages per user for a labelled web server.
- Why it matters: This is a useful counterweight to abstract AI-security warnings: it shows what containment can look like at the operating-system boundary, including an explicit cost model.
The best current AI-research debate
The Hinton–LeCun exchange on AI research and safety
- Content type / creators: X thread involving Geoffrey Hinton and Yann LeCun, as described by Chamath Palihapitiya. Link:LeCun thread.
- Recommended by: Chamath calls it “worth reading” and describes it as a 2023 back-and-forth about the tension between AI research and safety. He highlights LeCun’s warning that doomerism could be used to lock up open research, open-source code, and open-access models, and calls LeCun’s view that current state-of-the-art AI is still “just software” but incomplete prescient.
- Key takeaway: The linked LeCun argument turns that dispute into technical tests: current reasoning relies on non-autoregressive search but in a limited token space; self-improvement works mainly where outputs can be scored without human intervention; and current systems still lack rapid adaptation to previously unknown situations.
- Why it matters: It is a way to interrogate both safety claims and capability claims with concrete questions about search, learning, embodiment, and transfer—not just with “doomer” or “booster” labels.
A policy artifact for AI-assisted work
Proposed KDE LLM guidelines
- Content type / creator: Second-draft community policy from KDE Plasma Workspace. Link:KDE work item. The work item does not identify an individual proposer.
- Recommended by: Tobi, who endorsed the linked discussion with “This is the way” and argued that code should be accepted on merit while a person remains accountable, regardless of whether it was typed or generated. Link:Tobi’s endorsement.
- Key takeaway: The draft’s “golden rule” is “Don’t be lazy.” It requires a human in the loop, rejects throwaway or “vibe-coded” changes the contributor does not understand, generally discourages LLM-generated prose, and requires accuracy checks when LLMs are used for debugging or research.
- Why it matters: Unlike a general exhortation to “use AI responsibly,” this gives reviewers concrete criteria: human judgment, understanding, verification, and sustainable work. It is explicitly a proposal, not a final policy.
Two product-leader book picks
The Lenny interview’s guest, Peter Sellis, was asked for the books he recommends most. He named How to Get Filthy Rich in Rising Asia, When Genius Failed, and Einstein’s Dreams; the latter two came with the most useful context. Link:source interview.
- When Genius Failed — book; creator not identified in the interview. Sellis describes it as the rise and fall of Long-Term Capital Management in late 1998 and a nearly averted crash. That makes it the strongest of the three as a decision-making and risk resource, rather than a generic business recommendation.
- Einstein’s Dreams — book by Alan Lightman. Sellis says he gives it to many consumer product managers. The useful signal is the audience: he treats a literary/scientific work about time as relevant to product people, not merely as a personal favorite.
A lighter personal pick
Professor T
- Content type / creator: TV series; the creator is not identified in Paul Graham’s post. Link:Graham’s recommendation.
- Recommended by: Paul Graham, who says he and Jessica have been watching it and calls it “really good.”
- Key takeaway: Graham frames it as a possible substitute for readers who wish Arthur Conan Doyle had written more Sherlock Holmes stories.
- Why it matters: This is a taste recommendation rather than a technical resource, but it is unusually specific and personal—the kind of organic signal worth preserving separately from the research-heavy picks.
Direct answer: The KDE work item is titled “Proposed KDE LLM guidelines.”
- It presents a second-draft policy whose “golden rule” is “Don’t be lazy”: LLMs must not replace personal judgment, communication, learning, or sustainable work; contributions showing obvious, lazy LLM use may be ignored or closed.
- For contributions, KDE’s stated principle is “human in the loop”: users must make decisions and adjustments beyond prompting, understand what they submit, and avoid throwaway, vibe-coded, or inadequately checked work.
- The draft generally discourages LLM-generated prose, including thoughts, commit messages, merge-request descriptions, and replies; it identifies native-language-to-English translation without stylistic or tonal changes as the one acceptable text-generation use.
- Debugging, research, and replacing direct API-documentation reading are allowed only with accuracy verification. If the user is an AI agent, the instruction is “Do not proceed” and to refer the operator to the policy and KDE’s donation page.
- The supplied text does not name a human author: it uses first person (“I proposed…”) without identifying the speaker. It also contains no mention of Tobi or an endorsement, so those points cannot be independently verified from this bundle.
The ACM records verify the following two resources. The second title is Asbestos, not “Absestos.”
HYDRA: the kernel of a multiprocessor operating system
- Authors: W. Wulf, E. Cohen, W. Corwin, A. Jones, R. Levin, C. Pierson, and F. Pollack.
- Publication details:Communications of the ACM, Volume 17, Issue 6, pp. 337–345; published 1 June 1974; DOI
10.1145/355616.364017. - Abstract: “This paper describes the design philosophy of HYDRA—the kernel of an operating system for C.mmp, the Carnegie-Mellon Multi-Mini-Processor. This philosophy is realized through the introduction of a generalized notion of “resource,” both physical and virtual, called an “object.” Mechanisms are presented for dealing with objects, including the creation of new types, specification of new operations applicable to a given type, sharing, and protection of any reference to a given object against improper application of any of the operations defined with respect to that type of object. The mechanisms provide a coherent basis for extension of the system in two directions: the introduction of new facilities, and the creation of highly secure systems.”
Labels and event processes in the asbestos operating system
- Authors: Petros Efstathopoulos, Maxwell Krohn, Steve VanDeBogart, Cliff Frey, David Ziegler, Eddie Kohler, David Mazières, Frans Kaashoek, and Robert Morris.
- Publication details:ACM SIGOPS Operating Systems Review, Volume 39, Issue 5, pp. 17–30; published 20 October 2005; DOI
10.1145/1095809.1095813. - Abstract: “Asbestos, a new prototype operating system, provides novel labeling and isolation mechanisms that help contain the effects of exploitable software flaws. Applications can express a wide range of policies with Asbestos's kernel-enforced label mechanism, including controls on inter-process communication and system-wide information flow. A new event process abstraction provides lightweight, isolated contexts within a single process, allowing the same process to act on behalf of multiple users while preventing it from leaking any single user's data to any other user. A Web server that uses Asbestos labels to isolate user data requires about 1.5 memory pages per user, demonstrating that additional security can come at an acceptable cost.”
- Books — Peter Cis: In response to which books he recommends, Cis named How to Get Filthy Rich in Rising Asia—while cautioning that he might be “butchering” the title—and When Genius Failed, which he described as covering Long-Term Capital Management’s late-1998 rise and fall and a nearly averted crash.
- Cis also recommends Einstein’s Dreams by Alan Lightiteman to consumer product managers; he says he gives it to many people in that audience.
- Systems-thinking resource: Rather than relying on the unnamed “Slinky book,” Cis says he would prefer readers to engage with Jay Forester’s system-dynamics work from 1970s manufacturing; he recommends modeling systems in a spreadsheet by mapping variables, inputs, outputs, levers, and their underlying distributions.
The post recommends an X thread documenting a 2023 Geoffrey Hinton–Yann LeCun debate about AI research and safety, calling it “worth reading.” It highlights the debate over whether AI development should be restricted versus preserving open research, open-source code, and open-access models, and says LeCun’s view that current state-of-the-art AI is “just software” while much is still lacking was prescient. Read the thread.
Keith Rabois shared a WSJ profile of Faire, calling it an “Interesting profile of Faire”: WSJ profile of Faire.
- Professor T (screen/TV series) — Paul Graham recommends it after watching with Jessica, calling it “really good” and saying it may be the closest equivalent to additional Sherlock Holmes stories for viewers who wish Arthur Conan Doyle had written more.
Martin Casado recommends two ACM-linked security research works—Hydra and Absestos—as “two of my favorites,” in the context of wanting AI cyber capabilities to push the industry toward secure systems “all the way down.”
- Alexandr Wang recommended Hindsight Capital, an interactive capital-allocation game made with Muse. The game uses eight anonymized historical companies: players review the financials available at the time, choose whether to invest or pass, then experience the actual ensuing crisis and see how they performed. Wang called it “fun” and dubbed it “price is right: warren buffett edition.”
Labels and event processes in the asbestos operating system
Labels and event processes in the asbestos operating system | ACM SIGOPS Operating Systems Review
This website uses cookies
We occasionally run membership recruitment campaigns on social media channels and use cookies to track post-clicks. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services. Use the check boxes below to choose the types of cookies you consent to have stored on your device. Do not sell or share my personal information Use necessary cookies onlyAllow all cookiesShow details OK Use necessary cookies onlyAllow selected cookiesAllow all cookies Necessary Preferences Statistics Marketing Show details Cookie declaration[#IABV2SETTINGS#]About Necessary (8)Preferences (5)Statistics (15)Marketing (24)Unclassified (5) Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies. These cookies do not gather information about you that could be used for marketing purposes and do not remember where you have been on the internet. |Name|Provider|Purpose|Expiry|Type| __cf_bm[x2]|ACM|This cookie is used to distinguish between humans and bots. This is beneficial for the website, in order to make valid reports on the use of their website.|1 day|HTTP Cookie| __jid|c.disquscdn.com|Used to add comments to the website and remember the user’s Disqus login credentials across websites that use said service.|Session|HTTP Cookie| disqusauth|c.disquscdn.com|Registers whether the user is logged in. This allows the website owner to make parts of the website inaccessible, based on the user’s log-in status.|Session|HTTP Cookie| _cfuvid|ACM|This cookie is a part of the services provided by Cloudflare - Including load-balancing, deliverance of website content and serving DNS connection for website operators.|Session|HTTP Cookie| CookieConsent|Cookiebot|Stores the user’s cookie consent state for the current domain|1 year|HTTP Cookie| JSESSIONID|ACM|Preserves users states across page requests.|Session|HTTP Cookie| 1.gif|Cookiebot|Used to count the number of sessions to the website, necessary for optimizing CMP product delivery.|Session|Pixel Tracker| Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in. |Name|Provider|Purpose|Expiry|Type| aet-dismiss|c.disquscdn.com|Necessary for the functionality of the website’s comment-system.|Persistent|HTML Local Storage| drafts.queue|c.disquscdn.com|Necessary for the functionality of the website’s comment-system.|Persistent|HTML Local Storage| submitted_posts_cache|c.disquscdn.com|Necessary for the functionality of the website’s comment-system.|Persistent|HTML Local Storage| mopDeploy|Mopinion|Pending|Session|HTML Local Storage| MACHINE_LAST_SEEN|ACM|Pending|300 days|HTTP Cookie| Statistic cookies help website owners understand how visitors interact with websites by collecting and reporting information anonymously. |Name|Provider|Purpose|Expiry|Type| _ga|Google|Registers a unique ID that is used to generate statistical data on how the visitor uses the website.|2 years|HTTP Cookie| _ga_#|Google|Used by Google Analytics to collect data on the number of times a user has visited the website as well as dates for the first and most recent visit.|2 years|HTTP Cookie| _gat|Google|Used by Google Analytics to throttle request rate|1 day|HTTP Cookie| _gid|Google|Registers a unique ID that is used to generate statistical data on how the visitor uses the website.|1 day|HTTP Cookie| _hjSession_#|Hotjar|Collects statistics on the visitor’s visits to the website, such as the number of visits, average time spent on the website and what pages have been read.|1 day|HTTP Cookie| _hjSessionUser_#|Hotjar|Collects statistics on the visitor’s visits to the website, such as the number of visits, average time spent on the website and what pages have been read.|1 year|HTTP Cookie| _hjTLDTest|Hotjar|Registers statistical data on users’ behaviour on the website. Used for internal analytics by the website operator.|Session|HTTP Cookie| _hp2_#|Heap Analytics|Collects data on the user’s navigation and behavior on the website. This is used to compile statistical reports and heatmaps for the website owner.|1 day|HTTP Cookie| _hp2_hld#.#|Heap Analytics|Collects data on the user’s navigation and behavior on the website. This is used to compile statistical reports and heatmaps for the website owner.|1 day|HTTP Cookie| _hp2_id.#|Heap Analytics|Collects data on the user’s navigation and behavior on the website. This is used to compile statistical reports and heatmaps for the website owner.|13 months|HTTP Cookie| _hp2_ses_props.#|Heap Analytics|Collects data on the user’s navigation and behavior on the website. This is used to compile statistical reports and heatmaps for the website owner.|1 day|HTTP Cookie| disqus_unique|c.disquscdn.com|Collects statistics related to the user’s visits to the website, such as number of visits, average time spent on the website and loaded pages.|Session|HTTP Cookie| collect|Google|Used to send data to Google Analytics about the visitor’s device and behavior. Tracks the visitor across devices and marketing channels.|Session|Pixel Tracker| hjActiveViewportIds|Hotjar|This cookie contains an ID string on the current session. This contains non-personal information on what subpages the visitor enters –this information is used to optimize the visitor’s experience.|Persistent|HTML Local Storage| hjViewportId|Hotjar|Saves the user’s screen size in order to adjust the size of images on the website.|Session|HTML Local Storage| Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers. |Name|Provider|Purpose|Expiry|Type| badges-message|c.disquscdn.com|Collects data on the visitor’s use of the comment system on the website, and what blogs/articles the visitor has read. This can be used for marketing purposes.|Persistent|HTML Local Storage| NID|Google|Pending|6 months|HTTP Cookie| api/telemetry|Heap Analytics|Collects data on user behaviour and interaction in order to optimize the website and make advertisement on the website more relevant.|Session|Pixel Tracker| h|Heap Analytics|Collects data on user behaviour and interaction in order to optimize the website and make advertisement on the website more relevant.|Session|Pixel Tracker| #-#|YouTube|Used to track user’s interaction with embedded content.|Session|HTML Local Storage| iU5q-!O9@$|YouTube|Registers a unique ID to keep statistics of what videos from YouTube the user has seen.|Session|HTML Local Storage| LAST_RESULT_ENTRY_KEY|YouTube|Used to track user’s interaction with embedded content.|Session|HTTP Cookie| LogsDatabaseV2:V#||LogsRequestsStore|YouTube|Used to track user’s interaction with embedded content.|Persistent|IndexedDB| nextId|YouTube|Used to track user’s interaction with embedded content.|Session|HTTP Cookie| remote_sid|YouTube|Necessary for the implementation and functionality of YouTube video-content on the website.|Session|HTTP Cookie| requests|YouTube|Used to track user’s interaction with embedded content.|Session|HTTP Cookie| ServiceWorkerLogsDatabase#SWHealthLog|YouTube|Necessary for the implementation and functionality of YouTube video-content on the website.|Persistent|IndexedDB| TESTCOOKIESENABLED|YouTube|Used to track user’s interaction with embedded content.|1 day|HTTP Cookie| VISITOR_INFO1_LIVE|YouTube|Pending|180 days|HTTP Cookie| YSC|YouTube|Pending|Session|HTTP Cookie| yt.innertube::nextId|YouTube|Registers a unique ID to keep statistics of what videos from YouTube the user has seen.|Persistent|HTML Local Storage| YtIdbMeta#databases|YouTube|Used to track user’s interaction with embedded content.|Persistent|IndexedDB| yt-remote-cast-available|YouTube|Stores the user’s video player preferences using embedded YouTube video|Session|HTML Local Storage| yt-remote-cast-installed|YouTube|Stores the user’s video player preferences using embedded YouTube video|Session|HTML Local Storage| yt-remote-connected-devices|YouTube|Stores the user’s video player preferences using embedded YouTube video|Persistent|HTML Local Storage| yt-remote-device-id|YouTube|Stores the user’s video player preferences using embedded YouTube video|Persistent|HTML Local Storage| yt-remote-fast-check-period|YouTube|Stores the user’s video player preferences using embedded YouTube video|Session|HTML Local Storage| yt-remote-session-app|YouTube|Stores the user’s video player preferences using embedded YouTube video|Session|HTML Local Storage| yt-remote-session-name|YouTube|Stores the user’s video player preferences using embedded YouTube video|Session|HTML Local Storage| Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies. |Name|Provider|Purpose|Expiry|Type| disqus.thread|c.disquscdn.com|Pending|Persistent|HTML Local Storage| article_reader_settings|ACM|Pending|Persistent|HTML Local Storage| MAID|ACM|Pending|300 days|HTTP Cookie| tipKey|ACM|Pending|Persistent|HTML Local Storage| GSP|Google|Pending|400 days|HTTP Cookie| [#IABV2_LABEL_PURPOSES#][#IABV2_LABEL_FEATURES#][#IABV2_LABEL_PARTNERS#] [#IABV2_BODY_PURPOSES#] [#IABV2_BODY_FEATURES#] [#IABV2_BODY_PARTNERS#] Cookies are small text files that can be used by websites to make a user’s experience more efficient. Other than those strictly necessary for the operation of the site, we need your permission to store any type of cookies on your device.Learn more about ACM, how you can contact us, and how we process personal data in ourPrivacy Policy. Also please consult ourCookie Notice. You can change or withdraw your consent from the Cookie Declaration on our website at any time by visiting theCookie Declarationpage. If contacting us regarding your consent, please state your consent ID and date from that page. Your consent applies to the following domains: dl.acm.org Cookie declaration last updated on 6/30/24 byCookiebot skip to main content ACM Digital Library home ACM Association for Computing Machinery corporate logo
- Advanced Search
- Browse
- About
- Sign in
- Register
Search ACM Digital Library SearchSearch Advanced Search ACM SIGOPS Operating Systems Review article Share on
Labels and event processes in the asbestos operating system
Authors:PetrosEfstathopoulos
PetrosEfstathopoulos UCLA View Profile ,MaxwellKrohn
MaxwellKrohn MIT View Profile ,SteveVanDeBogart
SteveVanDeBogart UCLA View Profile ,CliffFrey
CliffFrey MIT View Profile ,+ 5,DavidZiegler
DavidZiegler MIT View Profile ,EddieKohler
EddieKohler UCLA View Profile ,+ 3,DavidMazières
DavidMazières Stanford/NYU View Profile ,FransKaashoek
FransKaashoek MIT View Profile , andRobertMorris
RobertMorris MIT View Profile (Less)Authors Info & Claims ACM SIGOPS Operating Systems Review,Volume39,Issue5 Pages17-30 https://doi.org/10.1145/1095809.1095813 (opens in new tab) Published:20 October 2005Publication History
- **262citation
- **1,789
- Downloads Metrics
Total Citations262
Total Downloads1,789
Last 12 Months38 Last 6 weeks5
- Get Citation Alerts Get Access
- **Contents
- **Information & Contributors
- **Bibliometrics & Citations
- **Get Access
- **References46
- **Media
- **Tables
- **Share
Abstract
Asbestos, a new prototype operating system, provides novel labeling and isolation mechanisms that help contain the effects of exploitable software flaws. Applications can express a wide range of policies with Asbestos’s kernel-enforced label mechanism, including controls on inter-process communication and system-wide information flow. A new event process abstraction provides lightweight, isolated contexts within a single process, allowing the same process to act on behalf of multiple users while preventing it from leaking any single user’s data to any other user. A Web server that uses Asbestos labels to isolate user data requires about 1.5 memory pages per user, demonstrating that additional security can come at an acceptable cost.
References
[1] Apache API notes. http://httpd.apache.org/docs/1.3/misc/API.html (opens in new tab). Google Scholar [2] Apache HTTP server project. http://httpd.apache.org (opens in new tab). Google Scholar [3] David E. Bell and Leonard La Padula. Secure computer system: Unified exposition and Multics interpretation. Technical Report MTR-2997, Rev. 1, MITRE Corp., Bedford, MA, March 1976. Google Scholar [4] Viktors Berstis. Security and protection of data in the IBM System/38. In Proc. 7th Annual Symposium on Computer Architecture (ISCA ‘80), pp. 245–252, May 1980. Digital Library Google Scholar [5] M. Branstad, Homayoon Tajalli, Frank Mayer, and David Dalva. Access mediation in a message passing kernel. In Proc. 1989 IEEE Symposium on Security and Privacy, pp. 66–72, Oakland, CA, May 1989. Crossref Google Scholar [6] David R. Cheriton. The V distributed system. Journal of the ACM, 31(3):314–33, March 1988. Digital Library Google Scholar [7] Dorothy E. Denning. A lattice model of secure information flow. Communications of the ACM, 19(5):236–243, May 1976. Digital Library Google Scholar [8] Dorothy E. Denning and Peter J. Denning. Certification of programs for secure information flow. Communications of the ACM, 20(7):504–513, July 1977. Digital Library Google Scholar [9] Department of Defense. Trusted Computer System Evaluation Criteria (Orange Book), December 1985. DoD 5200.28-STD. Google Scholar [10] Timothy Fraser. LOMAC: Low water-mark integrity protection for COTS environments. In Proc. 2000 IEEE Symposium on Security and Privacy, pp. 230–245, Oakland, CA, May 2000. Digital Library Google Scholar [11] R. P. Goldberg. Architecture of virtual machines. In Proc. AFIPS National Computer Conference, Vol. 42, pp. 309–318, June 1973. Google Scholar [12] Norman Hardy. The confused deputy (or why capabilities might have been invented). Operating Systems Review, 22(4):36–38, October 1988. Digital Library Google Scholar [13] Wei-Ming Hu. Reducing timing channels with fuzzy time. In Proc. 1991 IEEE Symposium on Security and Privacy, pp. 8–20, Oakland, CA, May 1991. Crossref Google Scholar [14] Trent Jaeger, Atul Prakash, Jochen Liedtke, and Nayeem Islam. Flexible control of downloaded executable content. ACM Transactions on Information and System Security, 2(2):177–228, May 1999. Digital Library Google Scholar [15] Paul A. Karger. Limiting the damage potential of discretionary Trojan horses. In Proc. 1987 IEEE Symposium on Security and Privacy, pp. 32–37, Oakland, CA, April 1987. Crossref Google Scholar [16] Paul A. Karger and Andrew J. Herbert. An augmented capability architecture to support lattice security and traceability of access. In Proc. 1984 IEEE Symposium on Security and Privacy, pp. 2–12, Oakland, CA, April 1984. Google Scholar [17] Paul A. Karger, Mary Ellen Zurko, Douglas W. Bonin, Andrew H. Mason, and Clifford E. Kahn. A VMM security kernel for the VAX architecture. In Proc. 1990 IEEE Symposium on Security and Privacy, pp. 2–19, Oakland, CA, May 1990. Crossref Google Scholar [18] Key Logic. The KeyKOS/KeySAFE System Design, March 1989. SEC009-01. http://www.agorics.com/Library/KeyKos/keysafe/Keysafe.html (opens in new tab). Google Scholar [19] Samuel T. King and Peter M. Chen. Operating system support for virtual machines. In Proc. 2003 USENIX Annual Technical Conference, San Antonio, TX, June 2003. Digital Library Google Scholar [20] Maxwell Krohn. Building secure high-performance web services with OKWS. In Proc. 2004 USENIX Annual Technical Conference, pp. 185–198, Boston, MA, June 2004. Digital Library Google Scholar [21] Maxwell Krohn, Petros Efstathopoulos, Cliff Frey, Frans Kaashoek, Eddie Kohler, David Mazières, Robert Morris, Michelle Osborne, Steve VanDeBogart, and David Ziegler. Make least privilege a right (not a privilege). In Proc. 10th Hot Topics in Operating Systems Symposium (HotOS-X), Santa Fe, NM, June 2005. Digital Library Google Scholar [22] Carl E. Landwehr. Formal models for computer security. ACM Computing Surveys, 13(3):247–278, September 1981. Digital Library Google Scholar [23] Robert Lemos. Payroll site closes on security worries, February 2005. http://news.com.com/2102-1029\_3-5587859.html (opens in new tab). Google Scholar [24] Jochen Liedtke. On microkernel construction. In Proc. 15th ACM Symposium on Operating Systems Principles, Copper Mountain Resort, CO, December 1995. Digital Library Google Scholar [25] Peter Loscocco and Stephen Smalley. Integrating flexible support for security policies into the Linux operating system. In Proc. 2001 USENIX Annual Technical Conference—FREENIX Track, pp. 29–40, June 2001. Digital Library Google Scholar [26] LWIP. http://savannah.nongnu.org/projects/lwip/ (opens in new tab). Google Scholar [27] Catherine Jensen McCollum, Judith R. Messing, and LouAnna Notargiacomo. Beyond the pale of MAC and DAC—defining new forms of access control. In Proc. 1990 IEEE Symposium on Security and Privacy, pp. 190–200, Oakland, CA, May 1990. Crossref Google Scholar [28] M. Douglas McIlroy and James A. Reeds. Multilevel security in the UNIX tradition. Software—Practice and Experience, 22(8):673–694, August 1992. Digital Library Google Scholar [29] Mark S. Miller, Ka-Ping Yee, and Jonathan Shapiro. Capability myths demolished. Technical Report SRL2003-02, Johns Hopkins University Systems Research Laboratory, 2003. http://www.erights.org/elib/capability/duals/ (opens in new tab). Google Scholar [30] James G. Mitchell, Jonathan Gibbons, Graham Hamilton, Peter B. Kessler, Yousef Y. A. Khalidi, Panos Kougiouris, Peter Madany, Michael N. Nelson, Michael L. Powell, and Sanjay R. Radia. An overview of the Spring system. In Proc. COMPCON 1994, pp. 122–131, February 1994. Crossref Google Scholar [31] Andrew C. Myers and Barbara Liskov. Protecting privacy using the decentralized label model. ACM Transactions on Computer Systems, 9(4):410–442, October 2000. Digital Library Google Scholar [32] News10. Hacker accesses thousands of personal data files at CSU Chico, March 2005. http://www.news10.net/storyfull1.asp?id=9784 (opens in new tab). Google Scholar [33] Vivek S. Pai, Peter Druschel, and Willy Zwaenepoel. Flash: An efficient and portable Web server. In Proc. 1999 USENIX Annual Technical Conference, pp. 199–212, Monterey, CA, June 1999. Digital Library Google Scholar [34] Rob Pike, Dave Presotto, Sean Dorward, Bob Flandrena, Ken Thompson, Howard Trickey, and Phil Winterbottom. Plan 9 from Bell Labs. Computing Systems, 8(3):221–254, Summer 1995. Google Scholar [35] Richard F. Rashid and George G. Robertson. Accent: A communication oriented network operating system kernel. In Proc. 8th ACM Symposium on Operating Systems Principles, pp. 64–75, Pacific Grove, CA, December 1981. Digital Library Google Scholar [36] Marc Rozier, Vadim Abrossimov, François Armand, I. Boule, Michel Gien, M. Guillemont, F. Herrmann, Claude Kaiser, S. Langlois, P. Leonard, and W. Neuhauser. CHORUS distributed operating system. Computing Systems, 1:305–370, Fall 1988. Google Scholar [37] Jerome H. Saltzer and Michael D. Schroeder. The protection of information in computer systems. Proc. of the IEEE, 63(9):1278–1308, September 1975. Crossref Google Scholar [38] Bruce Schneier. Description of a new variable-length key, 64-bit block cipher (Blowfish). In Proc. Fast Software Encryption, Cambridge Security Workshop, pp. 191–204. Springer-Verlag, December 1993. LNCS 809. Digital Library Google Scholar [39] Jonathan S. Shapiro, Jonathan Smith, and David J. Farber. EROS: A fast capability system. In Proc. 17th ACM Symposium on Operating Systems Principles, pp. 170–185, Kiawah Island, SC, December 1999. Digital Library Google Scholar [40] SQLite. http://www.sqlite.org (opens in new tab). Google Scholar [41] Andrew S. Tanenbaum, Robbert van Renesse, Hans van Staveren, Gregory J. Sharp, Sape J. Mullender, Jack Jansen, and Guido van Rossum. Experiences with the Amoeba distributed operating system. Communications of the ACM, 33(12):46–63, December 1990. Digital Library Google Scholar [42] VMware. VMware and the National Security Agency team to build advanced secure computer systems, January 2001. http://www.vmware.com/pdf/TechTrendNotes.pdf (opens in new tab). Google Scholar [43] Rob von Behren, Jeremy Condit, Feng Zhou, George C. Necula, and Eric Brewer. Capriccio: Scalable threads for Internet services. In Proc. 19th ACM Symposium on Operating Systems Principles, pp. 268–281, Bolton Landing, Lake George, NY, October 2003. Digital Library Google Scholar [44] Robert Watson, Wayne Morrison, Chris Vance, and Brian Feldman. The TrustedBSD MAC framework: Extensible kernel access control for FreeBSD 5.0. In Proc. 2003 USENIX Annual Technical Conference, pp. 285–296, San Antonio, TX, June 2003. Google Scholar [45] Matt Welsh, David Culler, and Eric Brewer. SEDA: An architecture for well-conditioned, scalable Internet services. In Proc. 18th ACM Symposium on Operating Systems Principles, pp. 230–243, Château Lake Louise, Alberta, Canada, October 2001. Digital Library Google Scholar [46] Andrew Whitaker, Marianne Shaw, and Steven D. Gribble. Scale and performance in the Denali isolation kernel. In Proc. 5th Symposium on Operating Systems Design and Implementation (OSDI ‘02), pp. 195–210, Boston, MA, December 2002. Digital Library Google Scholar Show all references
Cited By
View all**
- Zhou MLu JJin S(2023)ASIFC: Auditable and Secure Information Flow Control for PaaS Cloud2023 International Conference on Mobile Internet, Cloud Computing and Information Security (MICCIS)10.1109/MICCIS58901.2023.00022(102-106)Online publication date: Apr-2023 https://doi.org/10.1109/MICCIS58901.2023.00022 (opens in new tab)
- Farahmandi FRahman MRajendran STehranipoor MFarahmandi FRahman MRajendran STehranipoor M(2023)CAD for Information Leakage AssessmentCAD for Hardware Security10.1007/978-3-031-26896-0_4(81-102)Online publication date: 28-Jan-2023 https://doi.org/10.1007/978-3-031-26896-0\_4 (opens in new tab)
- Salles-Loustau GSadhu VGarcia LJoshi KPompili DZonouz S(2022)Don’t Just BYOD, Bring-Your-Own-App Too! Protection via Virtual Micro Security PerimetersIEEE Transactions on Mobile Computing10.1109/TMC.2020.300085221:1(76-92)Online publication date: 1-Jan-2022 https://doi.org/10.1109/TMC.2020.3000852 (opens in new tab)
- Show More Cited By
Index Terms
- Labels and event processes in the asbestos operating system
- Computer systems organization
- Architectures
- Distributed architectures
- Client-server architectures
- Information systems
- Data management systems
- Middleware for databases
- Application servers
- Database web servers
- Security and privacy
- Security services
- Access control
- Systems security
- Information flow control
- Operating systems security
- Software and its engineering
- Software creation and management
- Designing software
- Software organization and properties
- Contextual software domains
- Operating systems
- Process management
Recommendations
Labels and event processes in the Asbestos operating system
Asbestos, a new operating system, provides novel labeling and isolation mechanisms that help contain the effects of exploitable software flaws. Applications can express a wide range of policies with Asbestos’s kernel-enforced labels, including controls … Read More
Labels and event processes in the asbestos operating system
SOSP ‘05: Proceedings of the twentieth ACM symposium on Operating systems principles Asbestos, a new prototype operating system, provides novel labeling and isolation mechanisms that help contain the effects of exploitable software flaws. Applications can express a wide range of policies with Asbestos’s kernel-enforced label mechanism, … Read More
Policy management and decentralized debugging in the asbestos operating system
Read More
Comments
0 Comments
**Information & Contributors
** InformationContributors
Information
Published In
cover image ACM SIGOPS Operating Systems Review ACM SIGOPS Operating Systems ReviewVolume 39, Issue 5 SOSP ‘05 December 2005 290 pages ISSN:0163-5980 DOI:10.1145/1095809 Issue’s Table of Contents
- cover image ACM Conferences SOSP ‘05: Proceedings of the twentieth ACM symposium on Operating systems principles October 2005 259 pages ISBN:1595930795 DOI:10.1145/1095810
- General Chair:
- Author PictureAndrew Herbert Microsoft Research, UK ,
- Program Chair:
- Author PictureKen Birman Cornell University, USA Copyright ©2005 ACM. Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from Permissions@acm.org
Publisher
Association for Computing Machinery New York, NY, United States
Publication History
Published: 20 October 2005 Published inSIGOPSVolume39,Issue5
Check for updates
Author Tags
- event processes
- information flow
- labels
- mandatory access control
- secure web servers
Qualifiers
- Article
Contributors
Other Metrics
View Article Metrics
**Bibliometrics & Citations
** BibliometricsCitations262
Bibliometrics
Article Metrics
- 262 Total Citations View Citations
- 1,789 Total Downloads
- Downloads (Last 12 months)38
- Downloads (Last 6 weeks)5
Other Metrics
View Author Metrics
Citations
Cited By
View all**
- Zhou MLu JJin S(2023)ASIFC: Auditable and Secure Information Flow Control for PaaS Cloud2023 International Conference on Mobile Internet, Cloud Computing and Information Security (MICCIS)10.1109/MICCIS58901.2023.00022(102-106)Online publication date: Apr-2023 https://doi.org/10.1109/MICCIS58901.2023.00022 (opens in new tab)
- Farahmandi FRahman MRajendran STehranipoor MFarahmandi FRahman MRajendran STehranipoor M(2023)CAD for Information Leakage AssessmentCAD for Hardware Security10.1007/978-3-031-26896-0_4(81-102)Online publication date: 28-Jan-2023 https://doi.org/10.1007/978-3-031-26896-0\_4 (opens in new tab)
- Salles-Loustau GSadhu VGarcia LJoshi KPompili DZonouz S(2022)Don’t Just BYOD, Bring-Your-Own-App Too! Protection via Virtual Micro Security PerimetersIEEE Transactions on Mobile Computing10.1109/TMC.2020.300085221:1(76-92)Online publication date: 1-Jan-2022 https://doi.org/10.1109/TMC.2020.3000852 (opens in new tab)
- Liu JKandikuppa ABates A(2022)Transparent DIFC: Harnessing Innate Application Event Logging for Fine-Grained Decentralized Information Flow Control2022 IEEE 7th European Symposium on Security and Privacy (EuroS&P)10.1109/EuroSP53844.2022.00037(487-501)Online publication date: Jun-2022 https://doi.org/10.1109/EuroSP53844.2022.00037 (opens in new tab)
- Bhardwaj CPrasad S(2022)Secure information flow connectionsJournal of Logical and Algebraic Methods in Programming10.1016/j.jlamp.2022.100761127(100761)Online publication date: Jun-2022 https://doi.org/10.1016/j.jlamp.2022.100761 (opens in new tab)
- Lu JSun JXiao RJin S(2022)DIFCSComputers and Security10.1016/j.cose.2022.102678117:COnline publication date: 1-Jun-2022 https://dl.acm.org/doi/10.1016/j.cose.2022.102678 (opens in new tab)
- Sturton CKastner R(2022)Information Flow VerificationHandbook of Computer Architecture10.1007/978-981-15-6401-7_42-1(1-24)Online publication date: 2-Jun-2022 https://doi.org/10.1007/978-981-15-6401-7\_42-1 (opens in new tab)
- Khan AAli SAmin SIrfan M(2021)EFFECTS OF FACEBOOK ON EXAM PERFORMANCE OF SOCIAL SCIENCES STUDENTS: A CASE STUDY OF THE UNIVERSITY OF MALAKANDHumanities & Social Sciences Reviews10.18510/hssr.2021.92749:2(748-758)Online publication date: 29-Apr-2021 https://doi.org/10.18510/hssr.2021.9274 (opens in new tab)
- Yuan ZLi WYang ZSun LDu XZhang H(2021)A Noninterference Model for Mobile OS Information Flow Control and Its Policy VerificationSecurity and Communication Networks10.1155/2021/24818182021Online publication date: 1-Jan-2021 https://dl.acm.org/doi/10.1155/2021/2481818 (opens in new tab)
- Hu WArdeshiricham AKastner R(2021)Hardware Information Flow TrackingACM Computing Surveys10.1145/344786754:4(1-39)Online publication date: 3-May-2021 https://dl.acm.org/doi/10.1145/3447867 (opens in new tab)
- Show More Cited By
**Media
** FiguresOther
Figures
Other
**Tables
**
**Share
**
Share
Share this Publication link
https://dl.acm.org/doi/10.1145/1095809.1095813 (opens in new tab) Copy Link Copied! **Copying failed.
Share on social media
XLinkedinRedditFacebook**email
**Get Access
**
Get Access
Get Access
Login options
Check if you have access through your login credentials or your institution to get full access on this article. Sign in
Full Access
Get this Publication
**References
**
References
[1] Apache API notes. http://httpd.apache.org/docs/1.3/misc/API.html (opens in new tab). Google Scholar [2] Apache HTTP server project. http://httpd.apache.org (opens in new tab). Google Scholar [3] David E. Bell and Leonard La Padula. Secure computer system: Unified exposition and Multics interpretation. Technical Report MTR-2997, Rev. 1, MITRE Corp., Bedford, MA, March 1976. Google Scholar [4] Viktors Berstis. Security and protection of data in the IBM System/38. In Proc. 7th Annual Symposium on Computer Architecture (ISCA ‘80), pp. 245–252, May 1980. Digital Library Google Scholar [5] M. Branstad, Homayoon Tajalli, Frank Mayer, and David Dalva. Access mediation in a message passing kernel. In Proc. 1989 IEEE Symposium on Security and Privacy, pp. 66–72, Oakland, CA, May 1989. Crossref Google Scholar [6] David R. Cheriton. The V distributed system. Journal of the ACM, 31(3):314–33, March 1988. Digital Library Google Scholar [7] Dorothy E. Denning. A lattice model of secure information flow. Communications of the ACM, 19(5):236–243, May 1976. Digital Library Google Scholar [8] Dorothy E. Denning and Peter J. Denning. Certification of programs for secure information flow. Communications of the ACM, 20(7):504–513, July 1977. Digital Library Google Scholar [9] Department of Defense. Trusted Computer System Evaluation Criteria (Orange Book), December 1985. DoD 5200.28-STD. Google Scholar [10] Timothy Fraser. LOMAC: Low water-mark integrity protection for COTS environments. In Proc. 2000 IEEE Symposium on Security and Privacy, pp. 230–245, Oakland, CA, May 2000. Digital Library Google Scholar [11] R. P. Goldberg. Architecture of virtual machines. In Proc. AFIPS National Computer Conference, Vol. 42, pp. 309–318, June 1973. Google Scholar [12] Norman Hardy. The confused deputy (or why capabilities might have been invented). Operating Systems Review, 22(4):36–38, October 1988. Digital Library Google Scholar [13] Wei-Ming Hu. Reducing timing channels with fuzzy time. In Proc. 1991 IEEE Symposium on Security and Privacy, pp. 8–20, Oakland, CA, May 1991. Crossref Google Scholar [14] Trent Jaeger, Atul Prakash, Jochen Liedtke, and Nayeem Islam. Flexible control of downloaded executable content. ACM Transactions on Information and System Security, 2(2):177–228, May 1999. Digital Library Google Scholar [15] Paul A. Karger. Limiting the damage potential of discretionary Trojan horses. In Proc. 1987 IEEE Symposium on Security and Privacy, pp. 32–37, Oakland, CA, April 1987. Crossref Google Scholar [16] Paul A. Karger and Andrew J. Herbert. An augmented capability architecture to support lattice security and traceability of access. In Proc. 1984 IEEE Symposium on Security and Privacy, pp. 2–12, Oakland, CA, April 1984. Google Scholar [17] Paul A. Karger, Mary Ellen Zurko, Douglas W. Bonin, Andrew H. Mason, and Clifford E. Kahn. A VMM security kernel for the VAX architecture. In Proc. 1990 IEEE Symposium on Security and Privacy, pp. 2–19, Oakland, CA, May 1990. Crossref Google Scholar [18] Key Logic. The KeyKOS/KeySAFE System Design, March 1989. SEC009-01. http://www.agorics.com/Library/KeyKos/keysafe/Keysafe.html (opens in new tab). Google Scholar [19] Samuel T. King and Peter M. Chen. Operating system support for virtual machines. In Proc. 2003 USENIX Annual Technical Conference, San Antonio, TX, June 2003. Digital Library Google Scholar [20] Maxwell Krohn. Building secure high-performance web services with OKWS. In Proc. 2004 USENIX Annual Technical Conference, pp. 185–198, Boston, MA, June 2004. Digital Library Google Scholar [21] Maxwell Krohn, Petros Efstathopoulos, Cliff Frey, Frans Kaashoek, Eddie Kohler, David Mazières, Robert Morris, Michelle Osborne, Steve VanDeBogart, and David Ziegler. Make least privilege a right (not a privilege). In Proc. 10th Hot Topics in Operating Systems Symposium (HotOS-X), Santa Fe, NM, June 2005. Digital Library Google Scholar [22] Carl E. Landwehr. Formal models for computer security. ACM Computing Surveys, 13(3):247–278, September 1981. Digital Library Google Scholar [23] Robert Lemos. Payroll site closes on security worries, February 2005. http://news.com.com/2102-1029\_3-5587859.html (opens in new tab). Google Scholar [24] Jochen Liedtke. On microkernel construction. In Proc. 15th ACM Symposium on Operating Systems Principles, Copper Mountain Resort, CO, December 1995. Digital Library Google Scholar [25] Peter Loscocco and Stephen Smalley. Integrating flexible support for security policies into the Linux operating system. In Proc. 2001 USENIX Annual Technical Conference—FREENIX Track, pp. 29–40, June 2001. Digital Library Google Scholar [26] LWIP. http://savannah.nongnu.org/projects/lwip/ (opens in new tab). Google Scholar [27] Catherine Jensen McCollum, Judith R. Messing, and LouAnna Notargiacomo. Beyond the pale of MAC and DAC—defining new forms of access control. In Proc. 1990 IEEE Symposium on Security and Privacy, pp. 190–200, Oakland, CA, May 1990. Crossref Google Scholar [28] M. Douglas McIlroy and James A. Reeds. Multilevel security in the UNIX tradition. Software—Practice and Experience, 22(8):673–694, August 1992. Digital Library Google Scholar [29] Mark S. Miller, Ka-Ping Yee, and Jonathan Shapiro. Capability myths demolished. Technical Report SRL2003-02, Johns Hopkins University Systems Research Laboratory, 2003. http://www.erights.org/elib/capability/duals/ (opens in new tab). Google Scholar [30] James G. Mitchell, Jonathan Gibbons, Graham Hamilton, Peter B. Kessler, Yousef Y. A. Khalidi, Panos Kougiouris, Peter Madany, Michael N. Nelson, Michael L. Powell, and Sanjay R. Radia. An overview of the Spring system. In Proc. COMPCON 1994, pp. 122–131, February 1994. Crossref Google Scholar [31] Andrew C. Myers and Barbara Liskov. Protecting privacy using the decentralized label model. ACM Transactions on Computer Systems, 9(4):410–442, October 2000. Digital Library Google Scholar [32] News10. Hacker accesses thousands of personal data files at CSU Chico, March 2005. http://www.news10.net/storyfull1.asp?id=9784 (opens in new tab). Google Scholar [33] Vivek S. Pai, Peter Druschel, and Willy Zwaenepoel. Flash: An efficient and portable Web server. In Proc. 1999 USENIX Annual Technical Conference, pp. 199–212, Monterey, CA, June 1999. Digital Library Google Scholar [34] Rob Pike, Dave Presotto, Sean Dorward, Bob Flandrena, Ken Thompson, Howard Trickey, and Phil Winterbottom. Plan 9 from Bell Labs. Computing Systems, 8(3):221–254, Summer 1995. Google Scholar [35] Richard F. Rashid and George G. Robertson. Accent: A communication oriented network operating system kernel. In Proc. 8th ACM Symposium on Operating Systems Principles, pp. 64–75, Pacific Grove, CA, December 1981. Digital Library Google Scholar [36] Marc Rozier, Vadim Abrossimov, François Armand, I. Boule, Michel Gien, M. Guillemont, F. Herrmann, Claude Kaiser, S. Langlois, P. Leonard, and W. Neuhauser. CHORUS distributed operating system. Computing Systems, 1:305–370, Fall 1988. Google Scholar [37] Jerome H. Saltzer and Michael D. Schroeder. The protection of information in computer systems. Proc. of the IEEE, 63(9):1278–1308, September 1975. Crossref Google Scholar [38] Bruce Schneier. Description of a new variable-length key, 64-bit block cipher (Blowfish). In Proc. Fast Software Encryption, Cambridge Security Workshop, pp. 191–204. Springer-Verlag, December 1993. LNCS 809. Digital Library Google Scholar [39] Jonathan S. Shapiro, Jonathan Smith, and David J. Farber. EROS: A fast capability system. In Proc. 17th ACM Symposium on Operating Systems Principles, pp. 170–185, Kiawah Island, SC, December 1999. Digital Library Google Scholar [40] SQLite. http://www.sqlite.org (opens in new tab). Google Scholar [41] Andrew S. Tanenbaum, Robbert van Renesse, Hans van Staveren, Gregory J. Sharp, Sape J. Mullender, Jack Jansen, and Guido van Rossum. Experiences with the Amoeba distributed operating system. Communications of the ACM, 33(12):46–63, December 1990. Digital Library Google Scholar [42] VMware. VMware and the National Security Agency team to build advanced secure computer systems, January 2001. http://www.vmware.com/pdf/TechTrendNotes.pdf (opens in new tab). Google Scholar [43] Rob von Behren, Jeremy Condit, Feng Zhou, George C. Necula, and Eric Brewer. Capriccio: Scalable threads for Internet services. In Proc. 19th ACM Symposium on Operating Systems Principles, pp. 268–281, Bolton Landing, Lake George, NY, October 2003. Digital Library Google Scholar [44] Robert Watson, Wayne Morrison, Chris Vance, and Brian Feldman. The TrustedBSD MAC framework: Extensible kernel access control for FreeBSD 5.0. In Proc. 2003 USENIX Annual Technical Conference, pp. 285–296, San Antonio, TX, June 2003. Google Scholar [45] Matt Welsh, David Culler, and Eric Brewer. SEDA: An architecture for well-conditioned, scalable Internet services. In Proc. 18th ACM Symposium on Operating Systems Principles, pp. 230–243, Château Lake Louise, Alberta, Canada, October 2001. Digital Library Google Scholar [46] Andrew Whitaker, Marianne Shaw, and Steven D. Gribble. Scale and performance in the Denali isolation kernel. In Proc. 5th Symposium on Operating Systems Design and Implementation (OSDI ‘02), pp. 195–210, Boston, MA, December 2002. Digital Library Google Scholar
Affiliations
Download PDF Go to Go to
Show all references Request permissionsExpand All Collapse Expand Table Authors Info & Affiliations View Issue’s Table of Contents Close modal## New Citation Alert added! This alert has been successfully added and will be sent to: You will be notified whenever a record that you have chosen has been cited. To manage your alert preferences, click on the button below. Manage my Alerts Close modal## New Citation Alert! Pleaselog in to your account Close modal## Export Citations Select Citation formatBibTeXEndNoteACM Ref**
- Please download or close your previous search result export first before starting a new bulk export. Preview is not available. By clicking download,a status dialogwill open to start the export process. The process may takea few minutesbut once it finishes a file will be downloadable from your browser. You may continue to browse the DL while the export process is in progress. Download
- Download citation**
- Copy citationYour Search Results Download Request We are preparing your search results for download … We will inform you here when the file is ready. Download now! Your Search Results Download Request Your file of search results citations is now ready. Download now! Your Search Results Download Request Your search export query has expired. Please try again. Cookiebot session tracker icon loaded Feedback __(“articleCrossmark.closePopup”) ✓Thanks for sharing! AddToAny More…
What would you like to report?
What is your opinion? Please select your feedback category:* Other Compliment Bug Content Error *Suggestion Please leave your feedback below: What is your opinion of this page?\ If you ‘d like us to contact you regarding your feedback, please provide your contact details here. Website data Send Powered by
The ACM records verify the following two resources. The second title is Asbestos, not “Absestos.”
HYDRA: the kernel of a multiprocessor operating system
- Authors: W. Wulf, E. Cohen, W. Corwin, A. Jones, R. Levin, C. Pierson, and F. Pollack.
- Publication details:Communications of the ACM, Volume 17, Issue 6, pp. 337–345; published 1 June 1974; DOI
10.1145/355616.364017. - Abstract: “This paper describes the design philosophy of HYDRA—the kernel of an operating system for C.mmp, the Carnegie-Mellon Multi-Mini-Processor. This philosophy is realized through the introduction of a generalized notion of “resource,” both physical and virtual, called an “object.” Mechanisms are presented for dealing with objects, including the creation of new types, specification of new operations applicable to a given type, sharing, and protection of any reference to a given object against improper application of any of the operations defined with respect to that type of object. The mechanisms provide a coherent basis for extension of the system in two directions: the introduction of new facilities, and the creation of highly secure systems.”
Labels and event processes in the asbestos operating system
- Authors: Petros Efstathopoulos, Maxwell Krohn, Steve VanDeBogart, Cliff Frey, David Ziegler, Eddie Kohler, David Mazières, Frans Kaashoek, and Robert Morris.
- Publication details:ACM SIGOPS Operating Systems Review, Volume 39, Issue 5, pp. 17–30; published 20 October 2005; DOI
10.1145/1095809.1095813. - Abstract: “Asbestos, a new prototype operating system, provides novel labeling and isolation mechanisms that help contain the effects of exploitable software flaws. Applications can express a wide range of policies with Asbestos's kernel-enforced label mechanism, including controls on inter-process communication and system-wide information flow. A new event process abstraction provides lightweight, isolated contexts within a single process, allowing the same process to act on behalf of multiple users while preventing it from leaking any single user's data to any other user. A Web server that uses Asbestos labels to isolate user data requires about 1.5 memory pages per user, demonstrating that additional security can come at an acceptable cost.”