<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" media="screen" href="/styles/xslt/rss.xslt"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:c9="http://channel9.msdn.com">
<channel>
	<title>Comment Feed for Channel 9 - Drawbridge: A new form of virtualization for application sandboxing</title>
	<atom:link rel="self" type="application/rss+xml" href="http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System/RSS"></atom:link>
	<image>
		<url>http://ak.channel9.msdn.com/ch9/f427/abf131e6-cd47-4335-94d8-9e8d000bf427/MSRDrawbridgeAppVirtualizationResearch_100_ch9.jpg</url>
		<title>Channel 9 - Drawbridge: A new form of virtualization for application sandboxing</title>
		<link></link>
	</image>
	<description>Drawbridge is a research prototype of a new form of virtualization for application sandboxing. Drawbridge combines two core technologies: First, a picoprocess, which is a process-based isolation container with a minimal kernel API surface. Second, a library OS, which is a version of Windows enlightened to run efficiently within a picoprocess. Drawbridge combines two ideas from the literature, the picoprocess and the library OS, to provide a new form of computing, which retains the benefits of secure isolation, persistent compatibility, and execution continuity, but with drastically lower resource overheads.  The Drawbridge library OS is an experimental&amp;nbsp;Windows 7 library OS - a research project and proving ground&amp;nbsp;for a larger concept: application virtualization and sandboxing.&amp;nbsp;Drawbridge is capable of&amp;nbsp;running the latest releases of major Windows applications such as Microsoft Excel, PowerPoint, and Internet Explorer with very little overhead compared to the traditional virtualization techniques. The experiment is going well! Now, what&#39;s going on here, exactly? Drawbridge research&amp;nbsp;team members Galen Hunt, Reuben Olinsky and&amp;nbsp;Jon Howell&amp;nbsp;dig into some of the details, including project&amp;nbsp;rationale and OS&amp;nbsp;architecture, of research project Drawbridge. Paper: http://research.microsoft.com/apps/pubs/default.aspx?id=141071 &amp;nbsp; </description>
	<link></link>
	<language>en</language>
	<pubDate>Wed, 19 Jun 2013 22:58:37 GMT</pubDate>
	<lastBuildDate>Wed, 19 Jun 2013 22:58:37 GMT</lastBuildDate>
	<generator>Rev9</generator>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[<p>Enlightened? That's the opposite of &quot;embiggened&quot;, right?</p><p>posted by aldie_lab</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634544709325912395</link>
		<pubDate>Mon, 17 Oct 2011 17:55:32 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634544709325912395</guid>
		<dc:creator>aldie_lab</dc:creator>
	</item>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[<p>@<a href="/Shows/Going&#43;Deep/Drawbridge-An-Experimental-Library-Operating-System#c634544709325912395">aldie_lab</a>: No. Enlightened as in the operating system (in&nbsp;this case, a library OS, which is a modified Windows 7 used for experimentation in the Drawbridge research experiment)&nbsp;is aware of and capable of running inside&nbsp;picoprocesses. So, enlightenments are <em>enhancements</em> to the OS&nbsp;which help reduce the cost of certain OS functions (like running inside a picoprocess). <br><br>C</p><p>posted by Charles</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634544717887159755</link>
		<pubDate>Mon, 17 Oct 2011 18:09:48 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634544717887159755</guid>
		<dc:creator>Charles</dc:creator>
	</item>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[<p>this video is finally out ! very interesting <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-1.gif?v=c9' alt='Smiley' /></p><p>posted by felix9</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634544740104860998</link>
		<pubDate>Mon, 17 Oct 2011 18:46:50 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634544740104860998</guid>
		<dc:creator>felix9</dc:creator>
	</item>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[<p>IE9 RC? ;P</p><p>This means that we might finally get native code on the web(again)?</p><p>posted by philjay</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634544754491011596</link>
		<pubDate>Mon, 17 Oct 2011 19:10:49 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634544754491011596</guid>
		<dc:creator>philjay</dc:creator>
	</item>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[Interesting video&#33; Thanks Charles&#33; Always impressive with what new ideas the people at MSR come up&#33; Great to put the spotlight on researchers.<br><br>Unrelated&#58; Would love to see Singularity&#39;s ideas go mainstream. Singularity&#39;s &#42;the single most interesting&#42; idea and implementation I&#39;ve seen in a long time in OS research. While it might not have been the first approach it was very well executed &#40;and documented&#41;.<p>posted by Simon</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634544764410419060</link>
		<pubDate>Mon, 17 Oct 2011 19:27:21 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634544764410419060</guid>
		<dc:creator>Simon</dc:creator>
	</item>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[<p>Interesting interview but would have been nice to have a little deeper questions:</p><p>If app&nbsp;consists of multiple sequential or parallel executables, so that eg. excel.exe starts excel2.exe and then excel.exe terminates and excel2 starts multiple different exes with their own windows and excel2.exe terminates... will this kind of thing work with this model? What if there's also some LPC or shared memory IPC between these before the termination?</p><p>If app uses CreateFile to open <a>\\.\C</a>: (hope i got that right)&nbsp;or a PhysicalDisk&nbsp;and in order to run needs to be able to write and read somewhere on the disk without going through the filesystem apis, will your security layer virtualize this or will the app fail to run?</p><p>How do you &quot;install&quot; app onto this sandbox? Lot of talk about lack of 3D/HW support but would have been many more interesting questions about how to handle things related to what eg. game installers do, such as &quot;sony rootkit drm&quot;, would that rootkit drm game install fine even if it was just 2D non-accelerated game. Also, would this approach work to enable better compatibility with Windows 3 &amp; 95/98 apps/games using old DX apis?</p><p>Getting old windows games and apps to run is oft more pain than dos games in dosbox. If MS were to productize this research, it could end up like the current app compat layer, which can require a bunch (too much) of fiddling just to find the app you want to run is not going to run since even if you put compat mode &quot;XP&quot;, the broken stuff tends to stay broken unless it was specifically tested by people in MS.</p><p>I think this type of legacy compatibility thing may be better using a hybrid development model: paid core team developing the long term goal deliveries and then allow the community using the product develop their own minor fixes and improvements that could be easily patched&nbsp;(by users, so simply that no instructions are needed) into the product on need basis. eg.&nbsp;if I as user&nbsp;run appX, it will check for community made fixes for appX and allow me to install those in the sandboxing layer or something, ensuring longevity and broadening compatibility as time goes on even if MS stops active development on the sandbox. Just a thought...</p><p>posted by androidi</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634544785219880627</link>
		<pubDate>Mon, 17 Oct 2011 20:02:01 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634544785219880627</guid>
		<dc:creator>androidi</dc:creator>
	</item>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[<p>@<a href="/Shows/Going&#43;Deep/Drawbridge-An-Experimental-Library-Operating-System#c634544785219880627">androidi</a>: &quot;It would have been great if the conversation centered around the specific technical&nbsp;topics I'm most curious about&quot;. OK. Maybe next time...<br><br>At any rate, you have a place to ask questions now.&nbsp;&nbsp;The Drawbridge people&nbsp;also have a place to look for&nbsp;questions to&nbsp;anwser.</p><p>C</p><p>posted by Charles</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634544790805073747</link>
		<pubDate>Mon, 17 Oct 2011 20:11:20 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634544790805073747</guid>
		<dc:creator>Charles</dc:creator>
	</item>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[<p>The video in the SL player is not playing... download works though</p><p>posted by Minh</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634544931983456716</link>
		<pubDate>Tue, 18 Oct 2011 00:06:38 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634544931983456716</guid>
		<dc:creator>Minh</dc:creator>
	</item>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[<p>@<a href="/Shows/Going&#43;Deep/Drawbridge-An-Experimental-Library-Operating-System#c634544931983456716">Minh</a>:Weird. Republishing.<br>C</p><p>posted by Charles</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634544933352571348</link>
		<pubDate>Tue, 18 Oct 2011 00:08:55 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634544933352571348</guid>
		<dc:creator>Charles</dc:creator>
	</item>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[<p>The possibility that I could start working one something on my home machine (say in VS) &quot;hibernate&quot; it and transfer that state to a cloud service and then pick up again right where I left off on any internet-enabled (and RDP enabled) device is quite intriguing to say the least; as well as very useful.</p><p>Not to mention the&nbsp;possibilities&nbsp;as far as backward compatibility is concerned.</p><p>posted by rstat1</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634545132464603496</link>
		<pubDate>Tue, 18 Oct 2011 05:40:46 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634545132464603496</guid>
		<dc:creator>rstat1</dc:creator>
	</item>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[<p>There is a concept called 'AppContainer' for Metro-style apps in Windows 8, which is very strict sandboxing / isolation, I guess it could be a good basis to incorporate the library OS idea. can you compare the AppContainer and the Picoprocess approach ? or AppV ? ThinApp ?</p><p>posted by felix9</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634545132916608046</link>
		<pubDate>Tue, 18 Oct 2011 05:41:31 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634545132916608046</guid>
		<dc:creator>felix9</dc:creator>
	</item>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Comment Permalink" href="/Shows/Going&#43;Deep/Drawbridge-An-Experimental-Library-Operating-System#c634544933352571348">16 hours&nbsp;ago</a>, <a href="/Niners/Charles">Charles</a> wrote</p><p>@<a href="/Shows/Going&#43;Deep/Drawbridge-An-Experimental-Library-Operating-System#c634544931983456716">Minh</a>:Weird. Republishing.<br>C</p><p></p></div></blockquote><p></p><p>Still not working here either. other videos work fine...</p><p>posted by giovanni</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634545538076209874</link>
		<pubDate>Tue, 18 Oct 2011 16:56:47 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634545538076209874</guid>
		<dc:creator>giovanni</dc:creator>
	</item>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[<p>@<a href="/Shows/Going&#43;Deep/Drawbridge-An-Experimental-Library-Operating-System#c634545538076209874">giovanni</a>: Working on it. My apologies. <br>C</p><p>posted by Charles</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634545560204019846</link>
		<pubDate>Tue, 18 Oct 2011 17:33:40 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634545560204019846</guid>
		<dc:creator>Charles</dc:creator>
	</item>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[<p>Nice. So in the future, a user could hit a exception, then &quot;click-dump&quot; the process (as a button in the exception window)&nbsp;and email to me. I could open that in VS debuging and be right in the context of the issue and even see what happened before the exception.&nbsp; Probably could also add a 20 sec reply window replay&nbsp;what user was doing 20 seconds before the issue for even more local context.&nbsp; Now that itself&nbsp;is a game changer. Also a neat way to publish working VS solutions for samples and demos, or office documents. The&nbsp;target user does not even have to have office installed&nbsp;and could even open from&nbsp;over the web. Big game changer. Nice what senerios that could enable.</p><p>posted by staceyw</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634545623234807877</link>
		<pubDate>Tue, 18 Oct 2011 19:18:43 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634545623234807877</guid>
		<dc:creator>staceyw</dc:creator>
	</item>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Comment Permalink" href="/Shows/Going&#43;Deep/Drawbridge-An-Experimental-Library-Operating-System#c634545623234807877">11 minutes&nbsp;ago</a>, <a href="/Niners/staceyw">staceyw</a> wrote</p><p>Nice. So in the future, a user could hit a exception, then &quot;click-dump&quot; the process (as a button in the exception window)&nbsp;and email to me. I could open that in VS debuging and be right in the context of the issue and even see what happened before the exception.</p><p></p></div></blockquote><p></p><p>If you want to resume hibernation, you need hiberfil.sys as well as your intact filesystem. You can't just send hiberfil.sys to another machine and resume your OS there.</p><p>posted by JohnSawyer</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634545669862416268</link>
		<pubDate>Tue, 18 Oct 2011 20:36:26 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634545669862416268</guid>
		<dc:creator>JohnSawyer</dc:creator>
	</item>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[<p>@<a href="/Shows/Going&#43;Deep/Drawbridge-An-Experimental-Library-Operating-System#c634545560204019846">Charles</a>: Fixed! <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-1.gif?v=c9' alt='Smiley' /></p><p>C</p><p>posted by Charles</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634545757611870390</link>
		<pubDate>Tue, 18 Oct 2011 23:02:41 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634545757611870390</guid>
		<dc:creator>Charles</dc:creator>
	</item>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[<p>Strangely, I&nbsp;found this about 10 minutes after watching the video.</p><p><a href="http://technet.microsoft.com/en-us/appvirtualization/dd146065">http://technet.microsoft.com/en-us/appvirtualization/dd146065</a></p><p>The move from kernel mode to user mode comments stood out.</p><p>Very cool stuff!</p><p>I'm&nbsp;curious how (in conceptual terms) the&nbsp;Drawbridge&nbsp;compares&nbsp;to a technology&nbsp;like Thinapp (previously Thinstall), I suppose other than the obvious ability to rearrange the OS.. <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-5.gif?v=c9' alt='Wink' /></p><p>&nbsp;</p><p>posted by Scottee</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634545916009827209</link>
		<pubDate>Wed, 19 Oct 2011 03:26:40 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634545916009827209</guid>
		<dc:creator>Scottee</dc:creator>
	</item>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[<p>I watched the video yesterday. But it got me thinking - how exactly is rearranging the OS better than using a Hyper-V VM with memory deduplication on EPT/Nested Pages?</p><p>This keeps memory usage low. How many instances of IIS would you be able to run in VMs using memory deduplication, as opposed to the number in Drawbridge? How well does Drawbridge perform CPU-wise, as opposed to running on bare metal hypervisor?</p><p>There were also some scenarios mentioned, such as:<br>- using it to keep compatibility with XP<br>- sandboxing</p><p>Well, I don't think it is easy to refactor an outdated OS and to keep compatibility for every single system call. Would you use XP RTM, XP SP1, XP SP2 or XP SP3 as the baseline?</p><p>With an upgrade to a new OS version, your existing applications get a new look, since they blend with the OS's redesigned UI elements. This is very much desirable, as opposed to keeping it at the version &quot;they were designed for&quot;. Then there's WinRT. I guess &quot;desktop mode&quot; APIs will stay Win7 compatible for a very long time, since most innovation will be in the WinRT world.</p><p>As to sandboxing, using a processor security feature (ie VM mode) is much more secure than it is to use existing ring protection. Unless you decide to use PL1 and PL2 <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-2.gif?v=c9' alt='Big Smile' /> (how's with ARM compatibility then)?</p><p>posted by JohnSawyer</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634546072630121883</link>
		<pubDate>Wed, 19 Oct 2011 07:47:43 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634546072630121883</guid>
		<dc:creator>JohnSawyer</dc:creator>
	</item>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[<p>Really cool! Very interesting. I was imaginating you could like &quot;transfer&quot; a program from a computer to a tablet (Just an example) in the very near future. Just an example tho <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-1.gif?v=c9' alt='Smiley' />&nbsp;</p><p>posted by martinmine</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634546451066376827</link>
		<pubDate>Wed, 19 Oct 2011 18:18:26 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634546451066376827</guid>
		<dc:creator>martinmine</dc:creator>
	</item>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[Linux Containers &#40;http&#58;&#47;&#47;lxc.sourceforge.net&#47;&#41; anyone&#63;<p>posted by James</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634546477057258478</link>
		<pubDate>Wed, 19 Oct 2011 19:01:45 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634546477057258478</guid>
		<dc:creator>James</dc:creator>
	</item>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Comment Permalink" href="/Shows/Going&#43;Deep/Drawbridge-An-Experimental-Library-Operating-System#c634546477057258478">20 hours&nbsp;ago</a></p><p>Linux Containers (<a href="http://lxc.sourceforge.net/">http&#58;&#47;&#47;lxc.sourceforge.net&#47;</a>) anyone?</p><p></p></div></blockquote><p></p><p>@<a href="/Shows/Going&#43;Deep/Drawbridge-An-Experimental-Library-Operating-System#c634546477057258478">James</a>: As you point out, there is a rich history of sandboxing technologies that operate at the scale of an application (chroot, zones, jails, containers, etc.).&nbsp;These were all important advances.&nbsp;Our contribution is to marry application sandboxing with the library OS concept. If you want to read more detail, our <a title="Paper on research.microsoft.com" href="http://research.microsoft.com/apps/pubs/default.aspx?id=141071" target="_self">ASPLOS 2011 paper</a>&nbsp;provides some comparison with existing technologies.</p><p>As far as we know, Drawbridge is the first in this class to provide not just isolation, but also <em>persistent compatibility</em> and <em>execution continuity</em>.&nbsp;When packaged with its library OS, a Drawbridge application can run across many different host OS versions.&nbsp; And,&nbsp;a running Drawbridge application can move from one host machine to another (without losing its state).</p><p>posted by galen</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634547205784005418</link>
		<pubDate>Thu, 20 Oct 2011 15:16:18 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634547205784005418</guid>
		<dc:creator>galen</dc:creator>
	</item>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[<p>@<a href="/Shows/Going&#43;Deep/Drawbridge-An-Experimental-Library-Operating-System#c634545560204019846">Charles</a>: Perfect, thank you!</p><p>posted by giovanni</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634547382101991827</link>
		<pubDate>Thu, 20 Oct 2011 20:10:10 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634547382101991827</guid>
		<dc:creator>giovanni</dc:creator>
	</item>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[<p>Wow, it's like that Galen guy and his team get to work on magic...</p><p>&nbsp;</p><p>I'm jealous of their lifestyle.</p><p>posted by B3NT</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634552301877716089</link>
		<pubDate>Wed, 26 Oct 2011 12:49:47 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634552301877716089</guid>
		<dc:creator>B3NT</dc:creator>
	</item>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Comment Permalink" href="/Shows/Going&#43;Deep/Drawbridge-An-Experimental-Library-Operating-System#c634546072630121883">Oct 19, 2011 at 12:47&nbsp;AM</a>, <a href="/Niners/JohnSawyer">JohnSawyer</a> wrote</p><p>I watched the video yesterday. But it got me thinking - how exactly is rearranging the OS better than using a Hyper-V VM with memory deduplication on EPT/Nested Pages?</p><p>This keeps memory usage low. How many instances of IIS would you be able to run in VMs using memory deduplication, as opposed to the number in Drawbridge? How well does Drawbridge perform CPU-wise, as opposed to running on bare metal hypervisor?</p><p></p></div></blockquote><p></p><p>Any benchmarks yet?</p><p>posted by JohnSawyer</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634552502193661796</link>
		<pubDate>Wed, 26 Oct 2011 18:23:39 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634552502193661796</guid>
		<dc:creator>JohnSawyer</dc:creator>
	</item>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[In the paper &#34;Exterminate All Operating System Abstractions&#34; &#40;www.stanford.edu&#47;&#126;engler&#47;hotos-jeremiad.ps&#41; they talk about an &#34;application-level operating system&#34;&#59; would you say that that is, or can be seen as, related to DrawBridge&#63;<p>posted by James</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634556055139612459</link>
		<pubDate>Sun, 30 Oct 2011 21:05:13 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634556055139612459</guid>
		<dc:creator>James</dc:creator>
	</item>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Comment Permalink" href="/Shows/Going&#43;Deep/Drawbridge-An-Experimental-Library-Operating-System#c634556055139612459">Oct 30, 2011 at 2:05&nbsp;PM</a></p><p>In the paper &quot;Exterminate All Operating System Abstractions&quot; (www.stanford.edu/~engler/hotos-jeremiad.ps) they talk about an &quot;application-level operating system&quot;; would you say that that is, or can be seen as, related to DrawBridge?</p><p></p></div></blockquote><p></p><p>Yes, Engler et. al invented the idea of a library OS (an &quot;application-level operating system&quot;).&nbsp; Our academic contribution was to show 1) how the interface between the library OS and the host OS can be modified to enable persistent compatibility, 2) how the it can enable migration, and 3) that Windows can be used to create a library OS.</p><p>By the way, our paper mentioned above discusses the related work in more detail.</p><p>posted by galen</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634582670612296661</link>
		<pubDate>Wed, 30 Nov 2011 16:24:21 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634582670612296661</guid>
		<dc:creator>galen</dc:creator>
	</item>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Comment Permalink" href="/Shows/Going&#43;Deep/Drawbridge-An-Experimental-Library-Operating-System#c634544764410419060">Oct 17, 2011 at 12:27&nbsp;PM</a></p><p>Unrelated: Would love to see Singularity's ideas go mainstream. Singularity's *the single most interesting* idea and implementation I've seen in a long time in OS research. While it might not have been the first approach it was very well executed (and documented).</p><p></p></div></blockquote><p></p><p>Thanks!&nbsp; We are very proud of our Singularity work as well.&nbsp; Interesting, several of the great ideas from Singularity were reused in Drawbridge.&nbsp; For example, the Drawbridge ABI (application binary interface) is very similar to the Singularity ABI.&nbsp; Also, Drawbridge employs many of the program manifest and packaging ideas that we pioneered in Drawbridge.</p><p>posted by galen</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634582671980214652</link>
		<pubDate>Wed, 30 Nov 2011 16:26:38 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634582671980214652</guid>
		<dc:creator>galen</dc:creator>
	</item>
	<item>
		<title>Re: Drawbridge: A new form of virtualization for application sandboxing</title>
		<description>
			<![CDATA[<p>I like the way you can suspend a process or fork it across the network. That's quite impressive!</p><p>posted by ajasmin</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634620317478215593</link>
		<pubDate>Fri, 13 Jan 2012 06:09:07 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Going+Deep/Drawbridge-An-Experimental-Library-Operating-System#c634620317478215593</guid>
		<dc:creator>ajasmin</dc:creator>
	</item>
</channel>
</rss>