期刊文献+

基于程序资源访问建模的安全增强

Resource Access Model Based Security Improvement
下载PDF
导出
摘要 在传统的访问控制系统中,程序执行时需要的权限和程序执行者拥有的权限并不完全一致。一般后者的权限大于前者,这一点也导致了很多安全漏洞的出现。文章针对传统访问控制系统的这一缺陷,设计了一套程序资源访问控制系统(pRM),它通过对程序执行过程中访问到的系统资源,如文件、目录等,进行建模和实时的监控,较为精确地限定了程序执行期间的权限,增强了程序的安全性能。 The privileges that programs need during their execution are not the same as that of users or user groups, while the traditional access control systems always grant programs privileges according to that of users or groups. Because of this limitation of traditional access system many security holes emerged in modern operation systems. This paper introduces a system named pRM (Process Resource Monitor) which can monitor and control the access to the system resources at rnntime. By using pRM more precise authorizing of privileges to processes can be carried out according to what they need during their execution. Through the experiments on many applications such as Apache the paper shows that pRM is efficient and does not impose significant performance penalties.
出处 《计算机工程》 EI CAS CSCD 北大核心 2005年第22期149-151,共3页 Computer Engineering
基金 国家"863"计划基金资助项目"安全操作系统"(863-2003AA144010)
关键词 精确授权 程序行为 异常检测 误用检测 资源访问 Precision-authorization Program behavior Abuse detection Misuse detection Resource access
  • 相关文献

参考文献5

  • 1Somayaji A, Forrest S. Automated Response Using System-call Delays. In: Proceedings of the 9^th USEN1X Security Symposium,2000-08.
  • 2Anderson D, Frivold T, Valdes A.Next-generation Intrusion Detection Expert System (NIDES): A Summary. Technical Report SRI-CSL-95-07, Computer Science Laboratory, SRI International, 1995-05.
  • 3Bach M J. The Design of the UNIX Operating System. Prentice-Hall,Englewood Cliffs, NJ, 1986.
  • 4Provos N. Improving Host Security with System Call Policies. Center for Information Technology Integration, University of Michigan,2001-08.
  • 5Acharya A, Raje M. MAPbox: Using Parameterized Behavior Classes to Confine Applications. In: Proceedings of the 9^th USENIX Security Symposium, 2000-08.

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部