计算机科学 ›› 2010, Vol. 37 ›› Issue (1): 75-78.

• 计算机网络与信息安全 • 上一篇    下一篇

基于信息流的多级安全策略模型研究

王辉,贾宗璞,申自浩,卢碧波   

  1. (河南理工大学计算机科学与技术学院 焦作454000)
  • 出版日期:2018-12-01 发布日期:2018-12-01

Research of Multi-level Security Policy Model Based on Information Flow

WANG Hui,JIA Zong-pu,SHEN Zi-hao,LU Bi-bo   

  • Online:2018-12-01 Published:2018-12-01

摘要: 内部威胁是企业组织面临的非常严重的安全问题,作为企业最贵重的信息资产—文档,是内部滥用的主要目标。以往的粗粒度安全策略,如最小权限原则、职责分离等,都不足以胜任文档安全化的内部威胁问题。提出了一个崭新的多级安全策略模型,引入了文档信息流和信息流图概念,并提出了相关算法。它能依据系统上下文环境的变化,动态地产生信息流的约束条件,屏蔽可能产生的隐藏信息流通道。

关键词: 内部威胁,安全策略,信息流,安全级别,信息流图

Abstract: Insider threat is widely recognized as an utmost important issue for organization security management As the most important information asset (documents),they are the chief target of insider misuse. The former coarse grained security policies that operate on "the principle of least privilege" or "separate of duty" are not enough to address documenu security about insider threat issue. We presented a novel multi-level security policy model and related algorithms,and defined the concept of document information flow and information flow graph. According to system context’s change,it will generate dynamic restriction conditions about information flow. And its aim is to prohibit these probable hiding channels of information flow.

Key words: Insider threat, Security policy, Information flow, Security level, Information flow graph

No related articles found!
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!