首页> 外文会议>Internaitonal conference on trusted systems >SCIATool: A Tool for Analyzing SELinux Policies Based on Access Control Spaces, Information Flows and CPNs
【24h】

SCIATool: A Tool for Analyzing SELinux Policies Based on Access Control Spaces, Information Flows and CPNs

机译:SCIATool:一种用于基于访问控制空间,信息流和CPN分析SELinux策略的工具

获取原文

摘要

Although security policies configuration is crucial for operating systems to constrain applications' operations and to protect the confidentiality and integrity of sensitive resources inside the systems, it is an intractable work for security administrators to accomplish correctly and consistently solely by hands. Thus policies analysis methods are becoming research hotspots. A great deal of such researches are focused on SELinux, which is a security-enhanced module of open-source and popular Linux. Among various analysis methods for SELinux policies, those based on access control spaces, information flows and colored Petri-nets (CPNs) can be thought as the three most valuable methods and they can be exploited together and complementarily. In this paper, a prototype of SELinux policies Configuration Integrated Analysis Tool, i.e. SCIATool, is designed and implemented by integrating these three methods together. Test results are provided and further researches as to construct a computer-aided configuration tool for SELinux policies are discussed.
机译:尽管安全策略配置对于操作系统限制应用程序的操作以及保护系统内部敏感资源的机密性和完整性至关重要,但对于安全管理员而言,仅靠人工就可以正确,一致地完成它是一项艰巨的工作。因此,政策分析方法已成为研究热点。大量此类研究集中在SELinux上,它是开源和流行Linux的安全性增强模块。在SELinux策略的各种分析方法中,基于访问控制空间,信息流和有色Petri网(CPN)的分析方法可以被认为是三种最有价值的方法,并且可以一起使用和补充使用。在本文中,通过将这三种方法集成在一起,设计并实现了SELinux策略配置集成分析工具(即SCIATool)的原型。提供了测试结果,并讨论了为SELinux策略构建计算机辅助配置工具的进一步研究。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号