Agreed. I mean, AppArmor and SELinux exist to control file access, perhaps OSes should put more effort into user-friendly overlays to control processes and have audits to warn users when a piece of software has full system access.
As far as network control... We have open-source blacklists for various malicious websites. Perhaps we should also have "known-good" site whitelists and have OS-level blocking for that by default. Like, OSes running DNS-sinkholing of StevenBlack malware lists, and the option to enable "known-good" whitelists as well. Having a hosts file of 450,000 entries to sinkhole can bog down an interface coming up reliably... that process needs optimized.
There's a lot of money in the enterprise world doing similar things.