节点文献

基于角色模型的Linux文件血统及其安全机制

Linux File Lineage and Security Mechanism Based on Role-Model

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 董红斌周剑卢学裕钱立进

【Author】 Dong Hongbin Zhou Jian Lu Xueyu Qian Lijin(State Key Laboratory of Software Engineering/International School of Software,Wuhan University,Wuhan430072)

【机构】 武汉大学软件工程国家重点实验室/软件学院武汉大学软件工程国家重点实验室/软件学院 武汉430072武汉430072武汉430072

【摘要】 文章分析了Linux系统文件访问授权及控制机制的不足———孤立地看待文件之间的关联关系,借鉴数据血统思想提出了文件血统的概念,用以描述文件的安全关联。角色模型忽略了被访问客体的安全关联,使安全机制存在无法克服的漏洞,文章引入文件血统对角色模型的权限定义、权限配置、权限审查、访问控制四个与系统安全密切相关的问题进行了讨论,重点描述了文件血统和访问控制的结合方法。

【Abstract】 This paper analyses the security defects of the access authorization and controlling mechanism of Linux,which deal with the relationship between files isolatedly.Drawing lessons from the thought of data lineage,the concept of file lineage is put forward to describe the security relationship between files.The role-model ignores this relationship and brings the security mechanism some big bugs.This paper introduces the file lineage to the Role -model and discusses four questions which are related with system security closely.They are permission definitions,permission configuration,permission examination and access controlling.At last,it describes how to combine the file lineage with access controlling.

【关键词】 角色模型数据血统文件血统系统安全
【Key words】 role-modeldata lineagefile lineagesystem security
【基金】 国家自然科学基金(编号:90204011);软件工程国家重点实验室第四批开放基金
  • 【文献出处】 计算机工程与应用 ,Computer Engineering and Applications , 编辑部邮箱 ,2004年23期
  • 【分类号】TP316
  • 【被引频次】4
  • 【下载频次】85
节点文献中: 

本文链接的文献网络图示:

本文的引文网络