DocumentCode :
2756025
Title :
Usable Mandatory Integrity Protection for Operating Systems
Author :
Li, Ninghui ; Mao, Ziqing ; Chen, Hong
Author_Institution :
Dept. of Comput. Sci., Purdue Univ., West Lafayette, IN
fYear :
2007
fDate :
20-23 May 2007
Firstpage :
164
Lastpage :
178
Abstract :
Existing mandatory access control systems for operating systems are difficult to use. We identify several principles for designing usable access control systems and introduce the usable mandatory integrity protection (UMIP) model that adds usable mandatory access control to operating systems. The UMIP model is designed to preserve system integrity in the face of network-based attacks. The usability goals for UMIP are twofold. First, configuring a UMIP system should not be more difficult than installing and configuring an operating system. Second, existing applications and common usage practices can still be used under UMIP. UMIP has several novel features to achieve these goals. For example, it introduces several concepts for expressing partial trust in programs. Furthermore, it leverages information in the existing discretionary access control mechanism to derive file labels for mandatory integrity protection. We also discuss our implementation of the UMIP model for Linux using the Linux Security Modules framework, and show that it is simple to configure, has low overhead, and effectively defends against a number of network-based attacks.
Keywords :
Linux; authorisation; systems analysis; Linux security module framework; mandatory usable access control system; network-based attack; operating system; usable mandatory integrity protection; Access control; Computer security; Information security; Intrusion detection; Linux; Operating systems; Permission; Power system security; Protection; Usability;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Security and Privacy, 2007. SP '07. IEEE Symposium on
Conference_Location :
Berkeley, CA
ISSN :
1081-6011
Print_ISBN :
0-7695-2848-1
Type :
conf
DOI :
10.1109/SP.2007.37
Filename :
4223222
Link To Document :
بازگشت