Skip to main content

Sandboxing - Isolating Untrusted Code Safely

About 2 min read

A sandbox is a security technique that runs a program in an isolated environment to prevent it from affecting the entire system. It is used to safely analyze suspicious files and programs, and even if malware executes, no harm reaches systems outside the sandbox. This concept is also applied to browser tab isolation and the permission management of mobile apps.

What to Do with the Time Spent Waiting for a Verdict

Analysis in a sandbox differs from a check that matches against known patterns: it actually runs the item and observes its behavior. By nature, some amount of time passes before a verdict is available, so when it is placed in the middle of a flow such as an email delivery path, how to handle that waiting time becomes a design choice. Holding delivery until the verdict arrives is the safer side, since a dangerous attachment never reaches the recipient, but it introduces delays in daily work, and the delay is skewed - the attachments that are harder to analyze are the ones that arrive latest. Delivering first and retracting afterwards avoids the delay, but it leaves room for the recipient to open the message before the verdict exists, and retraction does not undo what has already been opened. In addition, observation yields only the behavior that occurred while it was being observed, so a specimen that does nothing right after launch offers little material for a decision. Preparing an isolated environment therefore does not make things safe automatically; it works as a defense only once it has been decided where in the workflow that waiting time is absorbed.

The Concept of a Sandbox

Sandbox (isolated environment)
Run suspicious program
Monitor and log behavior
↕ Access restriction
Host OS, file system, network (protected targets)

How a Sandbox Works

A sandbox uses virtualization or container technology to create an isolated execution environment. A program can access only the resources inside the sandbox, and its access to the file system and network is restricted. Security vendors analyze the behavior of malware in a sandbox and create detection signatures.

Concrete Usage Scenarios

A common misconception is that "a sandbox is a tool used only by security professionals." In reality, the browsers we use every day (such as Chrome and Edge) apply a sandbox to each tab, preventing malicious websites from affecting other tabs or the system.

In corporate security teams, it is common to automatically run email attachments in a sandbox and check for suspicious behavior (such as file encryption or communication with external servers) before delivering them. However, some advanced malware has "sandbox evasion" techniques that detect the sandbox environment and change its behavior, so defense in depth that does not rely on the sandbox alone is important.

Everyday Use

When opening a suspicious file, it is safe to check it in a sandbox environment. Using the "Windows Sandbox" feature of Windows 10/11, you can safely open files in an isolated environment. By combining the management of strong passwords with sandbox-based protection, you can achieve multilayered security.

Related Terms

Was this article helpful?