首页> 外文OA文献 >Functionality-based application confinement: parameterised hierarchical application restrictions
【2h】

Functionality-based application confinement: parameterised hierarchical application restrictions

机译:基于功能的应用程序限制:参数化的分层应用程序限制

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Traditional user-oriented access control models such as Mandatory Access Control (MAC) and Discretionary Access Control (DAC) cannot differentiate between processes acting on behalf of users and those behaving maliciously. Consequently, these models are limited in their ability to protect users from the threats posed by vulnerabilities and malicious software as all code executes with full access to all of a user's permissions. Application-oriented schemes can further restrict applications thereby limiting the damage from malicious code. However, existing application-oriented access controls construct policy using complex and inflexible rules which are difficult to administer and do not scale well to confine the large number of feature-rich applications found on modern systems. Here a new model, Functionality-Based Application Confinement (FBAC), is presented which confines applications based on policy abstractions that can flexibly represent the functional requirements of applications. FBAC policies are parameterised allowing them to be easily adapted to the needs of individual applications. Policies are also hierarchical, improving scalability and reusability while conveniently abstracting policy detail where appropriate. Furthermore the layered nature of policies provides defence in depth allowing policies from both the user and administrator to provide both discretionary and mandatory security. An implementation FBAC-LSM and its architecture are also introduced.
机译:传统的面向用户的访问控制模型(例如强制访问控制(MAC)和自由访问控制(DAC))无法区分代表用户行为的进程和恶意行为的进程。因此,这些模型在保护用户免受漏洞和恶意软件构成的威胁方面的能力有限,因为在执行所有代码时,必须完全访问用户的所有权限。面向应用程序的方案可以进一步限制应用程序,从而限制了恶意代码的破坏。但是,现有的面向应用程序的访问控制使用复杂且不灵活的规则来构造策略,这些规则难以管理且无法很好地扩展以限制现代系统中发现的大量功能丰富的应用程序。在这里,提出了一个新模型,即基于功能的应用程序限制(FBAC),该模型基于可以灵活地表示应用程序功能要求的策略抽象来限制应用程序。 FBAC策略已参数化,可以轻松地适应单个应用程序的需求。策略也是分层的,提高了可伸缩性和可重用性,同时在适当的地方方便地抽象了策略细节。此外,策略的分层性质提供了深度防御,允许来自用户和管理员的策略提供酌情和强制性安全。还介绍了一种实现FBAC-LSM及其体系结构。

著录项

  • 作者

    Schreuders Z.C.; Payne C.;

  • 作者单位
  • 年度 2008
  • 总页数
  • 原文格式 PDF
  • 正文语种 {"code":"en","name":"English","id":9}
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号