Seccomp
Sign in to saveseccomp (short for secure computing) is a computer security facility in the Linux kernel. seccomp allows a process to make a one-way transition into a "secure" state where it cannot make any system calls except exit(), sigreturn(), read() and write() to already-open file descriptors. Should it attempt any other system calls, the kernel will either just log the event or terminate the process with SIGKILL or SIGSYS. In this sense, it does not virtualize the system's resources but isolates the process from them entirely.
In the Vinony graph
Within Vinony's link graph, Seccomp is referenced by 248 other articles, and connects out to Linux kernel, Google Chrome and Linux Foundation.
Vinony files it under Computer security, Cybersecurity engineering and Linux kernel features.
Its subject is documented across 7 Wikipedia language editions.
Wikidata facts
- Instance of
- free software
- Official website
- code.google.com/p/seccompsandbox/wiki/overview
Show 4 more facts
- copyright license
- GNU General Public License
- operating system
- Linux
- inception
- 2005-03-08
- programmed in
- C
Sources (1)
via Wikidata · CC0
Article · Русский
seccomp (сокр. от англ. secure computing mode) — один из механизмов безопасности ядра Linux, который обеспечивает возможность ограничивать набор доступных системных вызовов для приложений, а также с помощью механизма BPF (Berkeley Packet Filter) производить сложную фильтрацию вызовов и их аргументов. Впервые появился в ядре версии 2.6.12 в 2005 году. Для работы с недоверенными или непроверенными, а поэтому потенциально опасными программами желательно использовать специально выделенные среды, из которых нельзя нанести вред работоспособности системы в целом. В таких средах (песочницах, контейнерах) для запускаемых программ лимитированы многие системные возможности, такие как доступ к сети, устройствам ввода-вывода, взаимодействие с операционной системой. Механизм seccomp определяет для процесса набор разрешённых системных вызовов и блокирует те, которые не были заранее объявлены. В настоящее время используется в ряде браузеров, Linux подобных ОС и некоторых системах виртуализации.
Abstract from DBpedia / Wikipedia · CC BY-SA