首页> 外文OA文献 >Integrating a trusted computing base extension server and secure session server into the Linux operating system
【2h】

Integrating a trusted computing base extension server and secure session server into the Linux operating system

机译:将受信任的计算基础扩展服务器和安全会话服务器集成到Linux操作系统中

摘要

Multilevel Secure Local Area Network (MLS LAN) Project at the Naval Postgraduate Schoolαs, Center for Information Security (INFOSEC) Studies and Research (NPS CISR) is building a trusted network system that is both necessary and sufficient to provide a multilevel networking solution for real world use. The current configuration provides the necessary trusted network services on the TCSEC Class B-3 evaluated XTS-300, which is a combination of the STOP version 4.4.2 multilevel secure operating system, and a Wang-supplied Intel x86 hardware base. The interface for the STOP operating is based on the System V.3 UNIX implementation. System V.3 lacks many of features available in more modern UNIX implementations such as System V.4 and BSD 4.3, and also lacks many of the features in POSIX and ANSI C standards. Finally, the CPU is several generations older than the more current Intel processors. This thesis discusses the port of several MLS trusted network services on the XTS- 300 to a Linux operating system running on an Intel Pentium Processor. The new Linux TCB Server configuration will permit further experimentation with MLS architectural issues in a more modern, flexible and easily modifiable environment. The port was accomplished by identifying and modifying the necessary software modules needed, to adapt to a Linux environment. This thesis proves that XTS-300 TCB services can be ported to Linux system without any negative effects on performance thus allowing a move toward a more security enhanced implementation.
机译:海军研究生院信息安全中心(INFOSEC)研究与研究(NPS CISR)的多层安全局域网(MLS LAN)项目正在构建一个受信任的网络系统,该系统对于提供多层网络解决方案既必要又充分供现实世界使用。当前配置在TCSEC B-3级评估的XTS-300上提供了必要的受信任网络服务,它是STOP版本4.4.2多级安全操作系统和Wang提供的Intel x86硬件基础的组合。 STOP操作的接口基于System V.3 UNIX实现。系统V.3缺少许多更现代的UNIX实现中可用的功能,例如系统V.4和BSD 4.3,并且还缺少POSIX和ANSI C标准中的许多功能。最后,CPU比最新的Intel处理器早几代。本文讨论了XTS-300上多个MLS可信网络服务到运行在Intel Pentium处理器上的Linux操作系统的端口。新的Linux TCB服务器配置将允许在更加现代,灵活且易于修改的环境中对MLS架构问题进行进一步的试验。该端口是通过识别和修改必要的软件模块以适应Linux环境而完成的。本文证明了XTS-300 TCB服务可以移植到Linux系统上,而不会对性能造成任何负面影响,从而允许向更加安全性增强的实施迈进。

著录项

  • 作者

    Glover Mark V.;

  • 作者单位
  • 年度 2001
  • 总页数
  • 原文格式 PDF
  • 正文语种
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号