What Is Seccomp: The Linux Mechanism That Limits What a Process Can Ask the Kernel
Seccomp, short for Secure Computing, is a Linux kernel feature that restricts which system calls a process is permitted to make. System calls are the only way user-space processes can request privileged operations from the kernel, such as reading files, creating sockets, or spawning new processes. By default, a Linux process has access to hundreds of system calls, creating a broad attack surface if the process is compromised. Seccomp allows developers to define a policy that sits between a process and the kernel, blocking any system call not explicitly permitted. This limits the potential damage an attacker can cause even after gaining control of a vulnerable process.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in