10.07.2015 Views

How To Prevent Rolling Spam Factories

How To Prevent Rolling Spam Factories

How To Prevent Rolling Spam Factories

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Linux Containers (LxC)• Userland Application to configure Linux Kernel isolation features• Not a virtualization solution– Does not protect from user to kernel privilege escalation attacks• Allows isolating processes in different ways:– Process Namespace: Isolate processes from seeing one another– IPC Namespace: Ensures processes cannot share IPC’s– UID Namespace: Separate UID tables– Network Namespace: Separate network devices– UTSName Namespace: Separate host names– Mount Namespace: Separate mounted devices• Can be combined with filesystem snapshots (btrfs) to createdisposable environments25 SSG System Software Division

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!