摘要
利用Markov状态机形式化地描述了一种多级的、基于模式转换的安全系统模型 ,该模型利用系统可分性构筑 ,将一个多级的安全系统划分成多个运行模式 ,利用该模型可提高所设计系统的灵活性 ,但该模型存在隐通道问题 .利用香农信息论和广义图灵测试模型证明该模型中隐通道流量存在上限并给出定量分析 ,从而为达到可控的系统安全性和灵活性平衡提供了理论基础 .采用该系统模型和隐通道流量分析 ,通过限制模式转换频率和限制参与转换的资源数目等方法可控制隐通道隐患 .
A multilevel system model, which is mode transition based and gives formal description in Markov state machine,is introduced. Based on system separability,this model is constructed to separate the multilevel system into multiple parts. Employing this model the designed system is flexible;but with covert channel. By using the classical information theory and the general turning test model it is demonstrated that there exists an upper bound of covert channel capacity,and a quantitative analysis is provided. The practical meaning of this model and the analysis of its covert channel are given finally.
出处
《西安交通大学学报》
EI
CAS
CSCD
北大核心
2002年第10期1075-1078,共4页
Journal of Xi'an Jiaotong University
基金
国家自然科学基金资助项目 (60 1 730 58) .