计算机科学 ›› 2012, Vol. 39 ›› Issue (12): 290-294.

• 体系结构 • 上一篇    下一篇

基于可变标签的访问控制策略设计与实现

李大明,曹万华,张焕   

  1. (武汉数字工程研究所 武汉430074)
  • 出版日期:2018-11-16 发布日期:2018-11-16

New Label Alterable Access Control Policy

  • Online:2018-11-16 Published:2018-11-16

摘要: 仅提供了自主访问控制级安全防护能力的Windows操作系统的安全性受到用户广泛关注,而作为一项重要的信息安全技术,强制访问控制能够有效实现操作系统安全加固。访问控制策略的选择与设计是成功实施强制访问控制的关键。针对安全项目的需要,分析了结合经典访问控制模型BLP与Biba的优势,提出了依据进程可信度动态调整的可变标签访问控制策略,解决了因I3工尹与Biba模型的简单叠加而导致的系统可用性问题,最终实现了对进程访问行为进行控制的简单原型系统。实验表明,可变标签访问控制策略的引入在对操作系统安全加固的基础上显著提高了系统的可用性。

关键词: BLP,Biba,安全标签,标签调整,进程可信度

Abstract: The security of Windows operating system which only provides discretional access control (DAC) capability has riveted far and wide attention. As an important information security technology,mandatory access control (MAC) can effectively enhance security of system, and the design of access control policy plays a key role in successful implementation of MAC. In order to satisfy the needs for secure projects in Windows operating system ultimately, combining advantages of classical access control models BLP and Biba,a new access control policy which adjusts security label of subjects based on its credibility was presented to solve poor usability caused by superposition of BI_P and Biba. And finally the prototypal system based on access from process to file shows that the usability and security of system are improved effectively.

Key words: BLP, Biba, Security label, I_abcl adj usting, Process credit

No related articles found!
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!