首页> 外文会议>IEEE Symposium on Security and Privacy >Ensuring continuity during dynamic security policy reconfiguration in DTE
【24h】

Ensuring continuity during dynamic security policy reconfiguration in DTE

机译:在DTE中的动态安全策略重新配置期间确保连续性

获取原文

摘要

Operating system kernels capable of simultaneously enforcing multiple security policies provide economic benefits over those that cannot: they allow a single kernel to concurrently provide its costly or unique resources to a number of projects, each with its own individual security requirements. The additional ability to dynamically reconfigure its policy during run time allows a kernel to take on new projects and their policies and to remove old ones without disturbing those that remain. Unfortunately, the policy added to govern a new project may conflict with the kernel's existing policy components, invalidating their security properties and negating the protection they pro vide. This danger is an obstacle to the practical operation of these kernels. The paper describes how the Domain and Type Enforcement (DTE) prototype kernel implements automatic safeguards to reject policy extensions which would invalidate BLP, Ring, Strict Integrity, Clark-Wilson, and Assured Pipeline security properties of its existing policy.
机译:能够同时执行多个安全策略的操作系统内核提供了对那些不能:它们允许单个内核同时提供其昂贵或独特资源的经济效益,每个项目都具有自己的个人安全要求。在运行时动态重新配置其策略的额外能力允许内核接受新项目及其策略,并在不打扰保留的情况下删除旧的项目。不幸的是,为管理新项目添加的策略可能会与内核的现有策略组件冲突,使其安全性属性无效并否定他们提供的保护。这种危险是这些核的实际操作的障碍。本文介绍了域和类型强制(DTE)原型内核如何实现自动保障措施,以拒绝策略扩展,该策略扩展将使BLP,Ring,严格的完整性,Clark-Wilson和保证其现有政策的保证管道安全性质无效。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号