首页> 外文期刊>ACM Transaction on Information and System Security >Combining Discretionary Policy with Mandatory Information Flow in Operating Systems
【24h】

Combining Discretionary Policy with Mandatory Information Flow in Operating Systems

机译:结合自由裁量权政策与操作系统中的强制性信息流

获取原文
获取原文并翻译 | 示例

摘要

Discretionary Access Control (DAC) is the primary access control mechanism in today's major operating systems. It is, however, vulnerable to Trojan Horse attacks and attacks exploiting buggy software. We propose to combine the discretionary policy in DAC with the dynamic information flow techniques in MAC, therefore achieving the best of both worlds, that is, the DAC's easy-to-use discretionary policy specification and MAC's defense against threats caused by Trojan Horses and buggy programs. We propose the Information Flow Enhanced Discretionary Access Control (IFEDAC) model that implements this design philosophy. We describe our design of IFEDAC, and discuss its relationship with the Usable Mandatory Integrity Protection (UMIP) model proposed earlier by us. In addition, we analyze their security property and their relationships with other protection systems. We also describe our implementations of IFEDAC in Linux and the evaluation results and deployment experiences of the systems.
机译:自由访问控制(DAC)是当今主要操作系统中的主要访问控制机制。但是,它容易受到Trojan Horse攻击和利用越野车软件的攻击。我们建议将DAC中的自主策略与MAC中的动态信息流技术相结合,从而实现两全​​其美,即DAC的易于使用的自主策略规范以及MAC对特洛伊木马和越野车造成的威胁的防御程式。我们提出了实现此设计理念的信息流增强型自由裁量访问控制(IFEDAC)模型。我们描述了IFEDAC的设计,并讨论了它与我们先前提出的可用强制完整性保护(UMIP)模型的关系。此外,我们分析了它们的安全性及其与其他保护系统的关系。我们还描述了我们在Linux上实现IFEDAC的方法以及评估结果和系统的部署经验。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号