Technical Tuesday – 4 December 2012 – Sandboxing finally becomes mainstream – the new security paradigm for host based security by Alan Bollinger of OnSystem Logic
Least privilege application control (often referred to as sandboxing and more formally called mandatory access control) is emerging as this decade’s leading approach to securing host systems and applications. This technology, based on trusted operating system principles developed in the mid-90’s, is finally making its way into commercial IT environments and applications and significantly improving host security using non-signature based techniques. Least privilege containment is proving to be highly effective in preventing attacks and limiting potential damage even when an infection has occurred.
The “sandbox” concept is a simple one — restrict a process such that it only has access to the resources needed to perform its intended function and enforce these restrictions via policy control so they cannot be bypassed. While this approach seems obvious from a security perspective, the reality is that most enterprise systems deployed by IT today (Windows, UNIX, Linux) rely on discretionary (i.e., modifiable) access controls that allow malware to “land and expand” using the privileges of the process’s user account.
For example, without sandboxing even the most benign applications such as a PDF Viewer can be the conduit for malware to own a machine by exploiting the privileges of a user (such as root or admin) who has opened an infected document. Likewise, vulnerabilities in services and daemons are the entry points for malware to enter the system and then expand by exploiting the account privileges to access or modify critical resources.
Vendors are now actively promoting the security benefits of sandboxing for hardening operating systems and applications. Google is offering $1M in prize money for anyone demonstrating exploits than can break out of its Chrome Browser sandbox. Adobe is championing the sandbox paradigm in its Acrobat Reader X product. Apple introduced sandboxing APIs to Mac OS X last year and now mandates that all applications sold through its Mac App store must implement sandboxing. SELinux is a standard component of Red Hat distributions. Newer mobile operating system platforms (such as Android and IOS) also implement and require sandboxing by default.
Least privilege containment has become a security best practice for the industry. It is proving equally effective in protecting high value servers such as Domain Controllers, Web servers, and databases as well as laptops, mobile devices and other endpoints. Use of system wide sandboxing across an enterprise can yield significant operational savings by reducing the number of security incidents and their associated remediation costs as well as reducing the number of patch cycles.
This presentation highlights this sandboxing trend and the implications to enterprises, application developers and security planners. Topics include how to compare sandbox alternatives, who makes and updates the sandbox rules, who enforces the sandbox, what controls are available to tune the sandbox, and how to implement these solutions to dramatically improve the security posture of existing enterprise systems. Sandboxing should be seen as another protection layer in a “defense in depth” approach to host security that complements perimeter defenses as well as the other endpoint security technologies such as antivirus, intrusion detection and data loss prevention.
The effectiveness of system-wide sandbox solutions will be shown using a commercial product (Symantec’s Critical System Protection) to instantly harden unpatched Windows systems using default policies. Protection against notorious attacks from the past and present (including Stuxnet) including exploits from the Metasploit pen testing community toolkit will be demonstrated.
Presented by: Alan Bollinger of OnSystem Logic
Alan has more than 30 years of industry IT experience in systems architecture, design, development, security, and operations. He is co-founder and CTO of OnSystem Logic, an IT security consulting, training, and engineering firm in Columbia, MD. Formed in 2008, OnSystem Logic specializes in protecting the critical IT assets within Fortune 500 enterprises and government agencies using the most effective solutions available. Alan has an extensive background both building sandboxing technology and consulting with enterprises to incorporate this technology as part of an integrated security solution.
Alan previously worked for Symantec Engineering as Chief Architect for its endpoint security products including Critical System Protection (CSP) and Endpoint Protection (SEP). He came to Symantec via the acquisition of Platform Logic in 2004 where he was CTO and Product Manager. Platform Logic was an innovative leader in applying least privilege, trusted operating system principles to harden general purpose (Windows, UNIX and Linux) operating systems and its AppFire product became the foundation for Symantec’s CSP product.
Alan has alternated between senior technical leadership roles at Fortune 100 companies (including Oracle, DEC and GE) and small technology startups. Alan also has extensive US federal government experience including multi-year enterprise implementation projects at Census, NASA, Social Security Administration and DOD agencies. Alan holds a BS in Computer Science from the University of Maryland and a MS in Computer Science from Johns Hopkins University.
