Principles, Technologies, and Secure Isolation
Introduction: When Isolation Fails
- The Promise of Sandboxing
- What This Book Covers
- What This Book Does Not Cover
- How to Read This Book
- A Note on the Evolving Landscape
Chapter 1: Why Sandboxing? — The Threat Model and the Promise of Isolation
- The Cost of Unbounded Execution: Real Incidents
- Blast Radius and the Defense-in-Depth Philosophy
- A Taxonomy of Isolation Mechanisms
- What This Book Will (and Won’t) Cover
Chapter 2: The Kernel as Enforcer — Namespaces, Cgroups, and the Linux Sandboxing Stack
- Namespaces: Partitioning What You See
- Cgroups: Controlling What You Can Do
- User Namespaces and Unprivileged Containers
- Composing Isolation: From Primitives to Containers
- Limitations and Known Gaps in Linux Isolation
Chapter 3: Mandatory Access Control — SELinux, AppArmor, and Smack
- Discretionary vs Mandatory Access Control
- SELinux: Architecture and Policy Model
- AppArmor: Profile-Based Protection
- Smack and Alternative MAC Frameworks
- Operational Challenges and Adoption Barriers
Chapter 4: System Call Filtering — seccomp, Landlock, and Capability Dropping
- Linux Capabilities: Fine-Grained Privilege Splitting
- seccomp-bpf: Filtering the System Call Surface
- Landlock: A New Era of Unprivileged Sandboxing
- Composing Filters with Capability Dropping
- Real-World seccomp Profiles and Case Studies
Chapter 5: eBPF — The Universal Sandbox Primitive
- From TCPdump to Trusted Kernel Runtime: The eBPF Revolution
- How eBPF Works: Verifier, Programs, and Maps
- eBPF for Network and Filesystem Sandboxing
- Observability-Driven Security with eBPF
- Trust Boundaries and the eBPF Threat Model
- The eBPF Security Model in Practice
Chapter 6: Container Runtimes and the OCI Ecosystem
- The OCI Standard: Making Containers Portable
- Docker Architecture Deep Dive
- containerd and CRI-O: Kubernetes-Native Runtimes
- Rootless Containers and User Namespace Remapping
- Storage Drivers and Image Layers
Chapter 7: Virtual Machines and MicroVMs — Hardware-Level Isolation
- Virtualization Fundamentals and the Hypervisor Stack
- KVM and QEMU: The Linux Virtualization Foundation
- MicroVMs: Firecracker, Crosvm, and the Edge of Performance
- Security Comparison: VMs vs Containers
- When to Choose Hardware Isolation Over OS-Level Sandboxing
Chapter 8: Desktop and Mobile Sandboxes — macOS, Windows, Android, iOS, and Browsers
- macOS Sandbox: Seatbelt and Entitlements
- Windows AppContainer and Virtual-Based Sandboxing
- Android’s Per-App Isolation Model
- iOS Application Sandboxing and Entitlements
- Browser Sandboxes: Process Isolation and Site Separation
Chapter 9: Language and Runtime Sandboxes — From chroot to WebAssembly
- chroot: The Oldest Trick in the Book
- FreeBSD Jails: BSD’s Isolation Philosophy
- LXC and LXD: System Containers on Linux
- WebAssembly and WASI: Sandboxing at the Bytecode Level
- Language and Runtime Sandboxing Approaches
Chapter 10: Sandbox Escapes — How Isolation Fails and What to Do About It
- Container Escape Techniques and Case Studies
- VM Escape: Hypervisor Vulnerabilities and Side Channels
- Browser Sandbox Bypasses
- Desktop OS Sandbox Escapes
- Defense Strategies and the Ongoing Arms Race
Chapter 11: Designing and Operating Sandboxed Environments
- Threat Modeling Your Sandboxing Strategy
- Selecting Isolation Technology for Different Workloads
- Hardening Container Images and Runtimes
- Network Segmentation and Zero-Trust Networking
- Observability, Debugging, and Operational Excellence
Chapter 12: The Future of Sandboxing — Serverless, Confidential Computing, and Beyond
- Serverless Isolation: The Function-as-a-Service Model
- Confidential Computing: When the Kernel Can’t Be Trusted
- WebAssembly’s Expanding Sandbox Horizon
- The Convergence Playbook: Containers, VMs, and Wasm Together
- Open Challenges and Where the Field Is Heading