• DocumentCode
    2014971
  • Title

    Analysis and Study of Security Mechanisms inside Linux Kernel

  • Author

    Zhai, Gaoshou ; Li, Yaodong

  • Author_Institution
    Sch. of Comput. & Inf. Technol., Beijing Jiaotong Univ., Beijing, China
  • fYear
    2008
  • fDate
    13-15 Dec. 2008
  • Firstpage
    58
  • Lastpage
    61
  • Abstract
    It´s very important to analyze and study security mechanisms provided by an operating system. Currently, Linux is becoming one of the most popular operating systems because of its excellent performance and open source philosophy. Since lots of individuals and enterprises are switching to Linux, access control mechanism of Linux has been improved from time to time for new security requirements. For instance, SELinux sub-system can enforce a policy based Mandatory Access Control (MAC) and provide flexible security policy configuration. However, there are still some defects in current Linux access control mechanism. In this paper, available Linux security mechanisms are analyzed at first, while permission division principle is summarized. Then a new MAC mechanism is devised based on some popular information security models such as RBAC, DTE and etc and it is characteristic of cross-layered permission assignment. Finally, a corresponding prototype system is implemented and further research directions are summarized.
  • Keywords
    Linux; authorisation; operating system kernels; DTE; Linux kernel; RBAC; cross-layered permission division assignment; mandatory access control mechanism; operating system; prototype system; security policy configuration mechanism; Access control; Computer security; Data security; Information analysis; Information security; Kernel; Linux; Management information systems; Operating systems; Permission; ACL; Linux kernel; SELinux; Security mechanisms; capabilities; discretionary access control; mandatory access control;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security Technology, 2008. SECTECH '08. International Conference on
  • Conference_Location
    Hainan Island
  • Print_ISBN
    978-0-7695-3486-2
  • Type

    conf

  • DOI
    10.1109/SecTech.2008.17
  • Filename
    4725344