1 Introduction
Users of commodity operating systems often need to execute
untrustworthy software. In fact, this is the common
case: due to errors or malicious intent, software regularly
does not behave as expected. The Principle of Least Privilege
(POLP) [31] requires that software should be given
only the authority it needs to accomplish its functionality.
If adhered to, this principle (also known as the Principle
of Least Authority) can help protect systems from erroneous
or malicious software.