摘要
重点分析了基于信息保密的BLP(Bell-LaPadula)模型和基于信息完整性的Biba模型,基于这两个模型设计了兼顾系统保密性和完整性需求的强制访问控制模型,并结合Windows文件过滤驱动程序开发了一个基于该强制访问控制模型的文件安全监控系统,对其主要模块和关键技术进行了详细介绍。该文件安全监控系统可有效地维护文件系统的保密性和完整性,检测并阻断本地与网络的入侵。
Bell-Lapadula model based on information confidentiality and Biba model based on information integrity were introduced. Then a new Mandatory Access Control (MAC) model based on the two modules above was designed. By using Windows NT file filter driver, a file watching system which adopted this new MAC model was developed, and the components and key technologies of it were given in detail. This file watching system has the advantages of protecting information confidentiality and integrity, and resisting the attacks from both local and remote users.
出处
《计算机应用》
CSCD
北大核心
2006年第12期2941-2944,共4页
journal of Computer Applications
基金
航空基金资助项目(04C52009)
国防工业基础基金资助项目(Q172005A001)
关键词
强制访问控制
模型
文件过滤驱动
文件监控系统
Mandatory Access Control (MAC)
model
NT file filter driver
file watching system