Approaches for Designing Flexible Mandatory System .ppt
《Approaches for Designing Flexible Mandatory System .ppt》由会员分享,可在线阅读,更多相关《Approaches for Designing Flexible Mandatory System .ppt(23页珍藏版)》请在麦多课文档分享上搜索。
1、Approaches for Designing Flexible Mandatory System Security Policies,Trent Jaeger IBM Research July 8, 2004,Linux 2.6 Has LSM and SELinux,Linux Security Modules Framework Reference monitor interface w/i kernel No problems with redundant parsing or races Enforce mandatory access control (MAC) Restric
2、ts discretionary permissions Noteworthy LSM Features Comprehensive MAC enforcement 200+ hooks Control access to 29 kernel data typesSELinux module Supports comprehensive MAC Enhanced Type Enforcement policy: roles, subject types, transitions, etc. Large “example” policy (25,000+ permission assignmen
3、ts) Requires customization to security target,Integrity,Subject,Perm,Subject,Perm,High Subject,Object Read,Low Subject,Object Write,Low Subject Can Modify Input To High,SELinux & Integrity,Subject Type,Subject Attr,Attr Perm,Perm,Subject Type,Subject Attr,Attr Perm,Perm,SELinux Integrity Problem,fil
4、e_type read,sshd_tmp read,lastlog write,sysadm,sshd,logrotate,logfile read,setfiles,user_ssh rw,lastlog read,sshd_tmp rw,user_ssh rw,user,httpd admin,xdm,High Subject Type,Attr Perm,Perm,Perm,Low Subject Type,Conflict,Integrity Models,Biba Integrity No high integrity subject may depend on low integr
5、ity data/code Implication: No information flow from low integrity to high LOMAC The integrity level of a subject is equal to lowest integrity input Implication: same as Biba Caernarvon The integrity level of a subject or object is specified by a range Implication: Subjects may depend on/modify a ran
6、ge of integrity levels Clark-Wilson Only high integrity Transformation Procedures modify high integrity data Implication: Can read low integrity data if they can upgrade or discard only,Our Integrity Goal,Use flexible policy expression SELinuxs extended Type Enforcement policy Defines all relevant p
7、olicy decisionsFind integrity problems Information flows that satisfy Biba are permitted “Resolve” others remove or manage (Clark-Wilson)Compute information to assist in resolution Find problems: Minimal cover set Identify solutions: Resolutions Determine solutions: Impact,Minimal Cover Set for Inte
8、grity Violations,Subject Type,Subject Attr,Attr Perm,Perm,Subject Type,Perm,Subject-Permission Assignment,Minimal Cover Set,file_type read,sshd_tmp read,lastlog write,sysadm,sshd,logrotate,logfile read,setfiles,user_ssh rw,lastlog read,sshd_tmp rw,user_ssh rw,user,httpd admin,xdm,High Subject Type,A
9、ttr Perm,Perm,Perm,Low Subject Type,Conflict,S-P Assign,S-P Assign,Integrity Resolutions,Remove Subject Type or Object Type Reclassify Subject Type of Object Type Change Subject Type-Permission assignment Clark-Wilson reads Allow reading of low integrity data that meet Clark-Wilson No dependency rea
10、d (move file) Deny Object Access Track low integrity writes per object LOMAC Subject Type (sysadm) Reduce integrity level of subject when reading low integrity data,Example Resolutions,file_type read,sshd_tmp read,lastlog write,sysadm,sshd,logrotate,logfile read,setfiles,user_ssh rw,lastlog read,ssh
11、d_tmp rw,user_ssh rw,user,httpd admin,xdm,High Subject Type,Attr Perm,Perm,Perm,Conflict,S-P Assign,S-P Assign,Low Subject Type,Resolution Independence,file_type read,sshd_tmp read,lastlog write,sysadm,sshd,logrotate,logfile read,setfiles,user_ssh rw,lastlog read,sshd_tmp rw,user_ssh rw,user,httpd a
12、dmin,xdm,High Subject Type,Attr Perm,Perm,Perm,Conflict,S-P Assign,S-P Assign,Low Subject Type,X,Resolution Impact,Basic resolution impact Number of conflicts that result from a flow assignment or node Real resolution impact Number of conflicts that are eliminated by removal of an assignment or node
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
2000 积分 0人已下载
| 下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- APPROACHESFORDESIGNINGFLEXIBLEMANDATORYSYSTEMPPT
麦多课文档分享所有资源均是用户自行上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作他用。
链接地址:http://www.mydoc123.com/p-378525.html



GB T 30305-2013 工业用1,6-己二醇.pdf

