MMP: Mondrian memory protection.
In constrast to earlier page-based systems, MMP allows arbitrary permissions control at granularity of individual words.
Evaluation: zero-copy networking underneath the standard read
system call interface, where packet payload fragements are connected together by the translation system to avoid data copying.
If you could revise
the fundmental principles of
computer system design
to improve security...
... what would you change?