首页> 外文期刊>ACM Transaction on Information and System Security >Empowering End Users to Confine Their Own Applications: The Results of a Usability Study Comparing SELinux, AppArmor, and FBAC-LSM
【24h】

Empowering End Users to Confine Their Own Applications: The Results of a Usability Study Comparing SELinux, AppArmor, and FBAC-LSM

机译:使最终用户能够限制自己的应用程序:比较SELinux,AppArmor和FBAC-LSM的可用性研究的结果

获取原文
获取原文并翻译 | 示例

摘要

Protecting end users from security threats is an extremely difficult, but increasingly critical, problem. Traditional security models that focused on separating users from each other have proven ineffective in an environment of widespread software vulnerabilities and rampant malware. However, alternative approaches that provide more finely grained security generally require greater expertise than typical end users can reasonably be expected to have, and consequently have had limited success.The functionality-based application confinement (FBAC) model is designed to allow end users with limited expertise to assign applications hierarchical and parameterised policy abstractions based upon the functionalities each program is intended to perform. To validate the feasibility of this approach and assess the usability of existing mechanisms, a usability study was conducted comparing an implementation of the FBAC model with the widely used Linux-based SELinux and AppArmor security schemes. The results showed that the functionality-based mechanism enabled end users to effectively control the privileges of their applications with far greater success than widely used alternatives. In particular, policies created using FBAC were more likely to be enforced and exhibited significantly lower risk exposure, while not interfering with the ability of the application to perform its intended task. In addition to the success of the functionality-based approach, the usability study also highlighted a number of limitations and problems with existing mechanisms. These results indicate that a functionality-based approach has significant potential in terms of enabling end users with limited expertise to defend themselves against insecure and malicious software.
机译:保护最终用户免受安全威胁是一个极为困难但日益严重的问题。在许多软件漏洞和恶意软件猖environment的环境中,传统的专注于使用户彼此分离的安全模型已被证明是无效的。但是,提供更细粒度安全性的替代方法通常需要比通常的最终用户更多的专业知识,因此,成功的局限性有限。基于功能的应用程序限制(FBAC)模型旨在允许最终用户拥有有限的安全性。基于每个程序要执行的功能为应用程序分配层次结构和参数化策略抽象的专业知识。为了验证该方法的可行性并评估现有机制的可用性,进行了可用性研究,将FBAC模型的实现与广泛使用的基于Linux的SELinux和AppArmor安全方案进行了比较。结果表明,基于功能的机制使最终用户能够有效地控制其应用程序的特权,远比广泛使用的替代方案成功得多。尤其是,使用FBAC创建的策略更有可能得到执行,并且所显示的风险显着降低,同时又不影响应用程序执行其预期任务的能力。除了基于功能的方法的成功之外,可用性研究还强调了现有机制的许多局限性和问题。这些结果表明,基于功能的方法在使具有有限专业知识的最终用户防御不安全和恶意软件方面具有巨大的潜力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号