首页> 外文OA文献 >Improving Host Security with System Call Policies
【2h】

Improving Host Security with System Call Policies

机译:使用系统调用策略改善主机安全性

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

We introduce a system that eliminates the need to run programs in privileged process contexts. Using our system, programs run unprivileged but may execute certain operations with elevated privileges as determined by a configurable policy eliminating the need for suid or sgid binaries. We present the design and analysis of the "Systrace" facility which supports fine grained process confinement, intrusion detection, auditing and privilege elevation. It also facilitates the often difficult process of policy generation. With Systrace, it is possible to generate policies automatically in a training session or generate them interactively during program execution. The policies describe the desired behavior of services or user applications on a system call level and are enforced to prevent operations that are not explicitly permitted. We show that Systrace is efficient and does not impose significant performance penalties.
机译:我们介绍了一种无需在特权进程上下文中运行程序的系统。使用我们的系统,程序可以无特权地运行,但可以通过可配置的策略确定以提升的特权执行某些操作,从而无需suid或sgid二进制文件。我们介绍“ Systrace”工具的设计和分析,该工具支持细粒度的进程限制,入侵检测,审计和特权提升。它还促进了通常很困难的政策制定过程。使用Systrace,可以在培训课程中自动生成策略,或者在程序执行过程中以交互方式生成策略。这些策略在系统调用级别上描述了服务或用户应用程序的期望行为,并执行了这些策略以防止未明确允许的操作。我们证明Systrace是有效的,并且不会造成明显的性能损失。

著录项

  • 作者

    Provos Niels;

  • 作者单位
  • 年度 2002
  • 总页数
  • 原文格式 PDF
  • 正文语种
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号