摘要
提出一种基于信息流控制来保证软件可信运行的方法。首先设计一种信息流控制模型,该模型的访问规则、传播规则和感染规则基本涵盖了软件在操作系统运行过程中产生信息流的主要类型。其次,设计一种策略描述语言,该语言使软件管理者可以以一种较为直观的方式描述所期望的软件信息流。在Linux内核部分实现原型系统,实验证明该方法可以控制软件所产生的信息流,从信息流角度保证软件的可信运行。
A scheme is proposed in this paper which ensures the trusted running of software based on information flow control.First,we design an information flow control model,its access rules,propagation rules and infection rules basically cover main types of software's information flow generated in running process of operating system.Secondly,we design a policy depiction language which enables software administrators describe the expected software information flow in a more intuitive way.We partially implement the prototype system in the Linux kernel.Experiment demonstrates that the scheme is able to control information flow generated by the software,and ensures the trusted running of software in terms of information flow.
出处
《计算机应用与软件》
CSCD
2011年第4期289-293,共5页
Computer Applications and Software
关键词
信息流
可信
操作系统
标签
Information flow Trust Operating system Label