首页> 外文OA文献 >The Inlined Reference Monitor Approach to Security Policy Enforcement
【2h】

The Inlined Reference Monitor Approach to Security Policy Enforcement

机译:内联参考监视器方法来执行安全策略

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Embedding security enforcement code into applications is an alternative to traditional security mechanisms. This dissertation supports the thesis that such Inlined Reference Monitors, or IRMs, offer many advantages and are a practical option in modern systems. IRMs enable flexible general-purpose enforcement of security policies, and they are especially well suited for extensible systems and other non-traditional platforms. IRMs can exhibit similar, or even better, performance than previous approaches and can help increase assurance by contributing little to the size of a trusted computing base. Moreover, IRMs' agility in distributed settings allows for their cost-effective and trustworthy deployment in many scenarios. In this dissertation, IRM implementations are derived from formal automata-based specifications of security policies. Then, an IRM toolkit for Java is described in detail. This Java IRM toolkit uses an imperative policy language that allows a security policy, in combination with the details of its enforcement, to be given in a single complete specification. Various example policies, including the stack-inspection policy of Java, illustrate the approach. These examples shed light on practical issues in policy specification, the support needed from an IRM toolkit, and the advantages of the IRM approach.
机译:将安全实施代码嵌入到应用程序中是对传统安全机制的替代。本文支持这样的论点,即这种内联参考监控器(IRM)具有许多优点,并且是现代系统中的一种实用选择。 IRM支持灵活,通用的安全策略实施,特别适合可扩展系统和其他非传统平台。 IRM与以前的方法相比,可以表现出相似甚至更好的性能,并且对可信计算基础的贡献很小,因此可以帮助提高可靠性。此外,IRM在分布式环境中的敏捷性使其可以在许多情况下以经济高效且值得信赖的方式进行部署。本文从基于正式的基于自动机的安全策略规范中得出了IRM实现。然后,将详细描述Java的IRM工具包。此Java IRM工具箱使用命令式策略语言,该语言允许在一个完整的规范中给出安全策略及其实施细节。各种示例策略(包括Java的堆栈检查策略)说明了该方法。这些示例阐明了策略规范中的实际问题,IRM工具包所需的支持以及IRM方法的优点。

著录项

  • 作者

    Erlingsson Ulfar;

  • 作者单位
  • 年度 2003
  • 总页数
  • 原文格式 PDF
  • 正文语种 en_US
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号