节点文献
基于静态分析的强制访问控制框架的正确性验证
Static Analysis Based Correctness Verification for Mandatory Access Control Framework
【摘要】 现阶段对操作系统的强制访问控制框架的正确性验证的研究主要集中于对授权钩子放置的验证.文中基于TrustedBSD MAC框架对强制访问控制框架的正确性验证问题进行了研究,在授权钩子放置验证的基础上,提出了安全标记的完全初始化验证和完全销毁验证.为了实现上述验证,文中提出了一个路径敏感的、基于用户自定义检查规则的静态分析方法.该方法通过对集成于编译器的静态分析工具mygcc进行扩展来验证强制访问控制框架的钩子放置的准确性和完备性.该方法具有完全的路径覆盖性,且具有低的误报率和时间开销.
【Abstract】 Current researches on correctness verification for the mandatory access control framework of operating systems mainly focus on authorization hooks placement verification.Based on TrustedBSD MAC framework,this paper analyses the correctness verification problem for mandatory access control framework,and proposes complete initialization and complete destruction for security labels,as well as complete authorization for access.In order to enforce these verifications,this paper also presents a path-sensitive and user-defined-rule based static analysis approach.This approach verifies the accuracy and completeness of hooks placement of the mandatory access control framework through extending the compiler integrated static analysis tool-mygcc.It achieves high path cover,low false positive rate and time overhead.
【Key words】 correctness verification; static analysis; mandatory access control framework; hooks placement; mygcc;
- 【文献出处】 计算机学报 ,Chinese Journal of Computers , 编辑部邮箱 ,2009年04期
- 【分类号】TP393.08
- 【被引频次】9
- 【下载频次】376