DocumentCode
2673436
Title
Practical Domain and Type Enforcement for UNIX
Author
Badger, Lee ; Sterne, Daniel F. ; Sherman, David L. ; Walker, Kenneth M. ; Haghighat, Sheila A.
Author_Institution
Trusted Inf. Syst. Inc., Glenwood, MD, USA
fYear
1995
fDate
8-10 May 1995
Firstpage
66
Lastpage
77
Abstract
Type enforcement is a table-oriented mandatory access control mechanism well-suited for confining applications and restricting information flows. Although both flexible and strong, type enforcement alone imposes significant administrative costs and has not been widely adopted. Domain and Type Enforcement (DTE) is an enhanced version of type enforcement designed to provide needed simplicity and compatibility. Two primary techniques distinguish DTE from simple type enforcement: DTE policies are expressed in a high-level language that includes file security attribute associations as well as other access control information; and during system execution, DTE file security attributes are maintained using a concise human-readable format in a runtime DTE policy database, thus removing the need for security-specific low-level data formats. Such formats are a major source of incompatibility for security-enhanced systems. A DTE UNIX prototype system has been implemented to evaluate these primary DTE concepts. This paper presents experiences gained and preliminary results indicating that DTE can provide cost effective security increases to UNIX systems while maintaining a high degree of compatibility with existing programs and media
Keywords
Unix; authorisation; costing; database management systems; security of data; DTE policies; DTE policy database; Domain and Type Enforcement; UNIX; administrative costs; compatibility; cost effective security; file security attribute associations; file security attributes; high-level language; human-readable format; security-enhanced systems; security-specific low-level data formats; system execution; table-oriented mandatory access control; type enforcement; Access control; Control systems; Costs; Data security; Databases; High level languages; Information systems; Operating systems; Prototypes; Runtime;
fLanguage
English
Publisher
ieee
Conference_Titel
Security and Privacy, 1995. Proceedings., 1995 IEEE Symposium on
Conference_Location
Oakland, CA
Print_ISBN
0-8186-7015-0
Type
conf
DOI
10.1109/SECPRI.1995.398923
Filename
398923
Link To Document