首页> 外文会议>International Conference on ICT Systems Security and Privacy Protection >RootAsRole: Towards a Secure Alternative to sudo/su Commands for Home Users and SME Administrators
【24h】

RootAsRole: Towards a Secure Alternative to sudo/su Commands for Home Users and SME Administrators

机译:rootasrole:对家庭用户和中小企业管理员的Sudo / Su命令的安全替代方案

获取原文

摘要

The typical way to run an administrative task on Linux is to execute it in the context of a super user. This breaks the principle of least privilege on access control. Other solutions, such as SELinux and AppArmor, are available but complex to use. In this paper, a new Linux module, named RootAsRole, is proposed to allow users to fine-grained control the privileges they grant to Linux commands as capabilities. It adopts a role-based access control (RBAC) [14], in which administrators can define a set of roles and the capabilities that are assigned to them. Administrators can then define the rules controlling what roles users or groups can assign to themselves. Each time a Linux user wants to execute a program that necessitates one or more capabilities, (s)he should assign the role to him/herself that contains the needed capabilities, providing there is a rule that allows it. A pilot implementation on Linux systems is illustrated in detail.
机译:在Linux上运行管理任务的典型方式是在超级用户的上下文中执行它。 这会破坏访问控制上最小权限的原则。 其他解决方案,如SELinux和Apparmor,可用但是使用复杂。 在本文中,提出了一个名为COOTASOLE的新的Linux模块,以允许用户对其授予Linux命令的权限进行微粒控制作为功能。 它采用基于角色的访问控制(RBAC)[14],其中管理员可以定义一组角色和分配给它们的功能。 然后,管理员可以定义控制用户或组可以分配的角色的规则。 每次一个Linux用户都想要执行需要一个或多个能力的程序,他应该将角色分配给他/ herself,其中包含所需的功能,提供允许它的规则。 Linux系统上的导频实现将详细说明。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号