DocumentCode :
2561109
Title :
A dynamic end-to-end security for coordinating multiple protections within a Linux desktop
Author :
Briffaut, J. ; Peres, M. ; Toinard, C.
Author_Institution :
ENSI de Bourges, LIFO, Bourges, France
fYear :
2010
fDate :
17-21 May 2010
Firstpage :
509
Lastpage :
515
Abstract :
Currently, application protection models are mostly static and independent. It means that the applications cannot handle multiple domains to manage accordingly the permissions for a given user request. Managing multiple domains is becoming a more and more common issue as desktop applications are growing in complexity to provide better-designed user interfaces. Today, protection systems are almost everywhere. Multiple systems of protection are available from the Linux kernel such as SELinux or PIGA-Protect to get a Mandatory Protection. Those systems provide a per-syscall validation process. Network protections are also available such as the IPtables firewalling mechanism. But, solutions are missing for coordinating the various mechanisms that protect different levels of the global information system. The purpose is to reuse and coordinate efficiently those different levels of protection in order to provide a end-to-end protection that manages dynamically multiple domains. Thus, the same host can support multiple domains for the user requests while providing a transparent end-to-end security that protects against complex scenarios of attack. This paper describes an attempt to deliver such a system for controlling efficiently the user requests.
Keywords :
Linux; security of data; user interfaces; IPtables firewalling mechanism; Linux desktop; PIGA Protect; SELinux; application protection models; dynamic end-to-end security; multiple domains; per syscall validation process; user interfaces; Finance; Information security; Internet; Kernel; Linux; Management information systems; Permission; Postal services; Protection; Uniform resource locators; Linux; coordination; end-to-end security; multi-domains; protection mechanisms;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Collaborative Technologies and Systems (CTS), 2010 International Symposium on
Conference_Location :
Chicago, IL
Print_ISBN :
978-1-4244-6619-1
Type :
conf
DOI :
10.1109/CTS.2010.5478471
Filename :
5478471
Link To Document :
بازگشت