首页> 外文会议>The Eighth IEEE computer security foundations workshop >Implementation of a Discretionary Access Control Model for Script-based Systems
【24h】

Implementation of a Discretionary Access Control Model for Script-based Systems

机译:基于脚本的系统的自由访问控制模型的实现

获取原文
获取原文并翻译 | 示例

摘要

Powerful applications can be implemented using command scripts. A command script is a program written by one user, called a writer, and made available to another user, called the reader, who executes the script. For instance, command scripts could be used by Mosaic, the popular World-wide Web browsing tool, to provide fancy interfaces to services, such as banking, shopping, etc. However, the use of command scripts presents a serious security problem. A command script is run with the reader's access rights, so a writer can use a command script to gain unauthorized access to the reader's data and applications. Existing solutions to the problem either severely restrict I/O capability of scripts, limiting the range of applications that can be supported, or permit all I/O to scripts, potentially compromising the security of the reader's data. We define a discretionary access control model that permits users to flexibly limit the access rights of the processes that execute a command script. We use this model in a prototype system that safely executes command scripts available from Mosaic.
机译:强大的应用程序可以使用命令脚本来实现。命令脚本是由一个称为编写器的用户编写的程序,并且可供执行该脚本的另一个称为读取器的用户使用。例如,流行的万维网浏览工具Mosaic可以使用命令脚本来为诸如银行,购物等服务​​提供精美的界面。但是,命令脚本的使用带来了严重的安全性问题。命令脚本以读取者的访问权限运行,因此编写者可以使用命令脚本对读取者的数据和应用程序进行未经授权的访问。该问题的现有解决方案要么严重限制了脚本的I / O功能,限制了可以支持的应用程序范围,要么允许所有I / O进行脚本处理,从而有可能损害阅读器数据的安全性。我们定义了自由访问控制模型,该模型允许用户灵活地限制执行命令脚本的进程的访问权限。我们在可安全执行Mosaic的命令脚本的原型系统中使用此模型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号