节点文献

SELinux的安全机制和安全模型

Security mechanism and security model of SELinux

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 肖永康纪翠玲谢宝恂何珺

【Author】 XIAO Yong-kang 1,JI Cui-ling 2,XIE Bao-xun1,HE Jun1(1.College of Information Science and Technology,Beijing Normal University,Beijing 100875,China;2.Training Center,China Meteorological Administration,Beijing 100081,China)

【机构】 北京师范大学信息科学与技术学院中国气象局培训中心

【摘要】 SELinux是美国安全局发布的一个集成在Linux内核中的新型强制访问控制(MAC)机制。为了提供细粒度的访问控制,SELinux采用RBAC模型和TE模型为主体和客体之间的交互设计了大量的安全策略,有效解决了自主访问控制(DAC)的脆弱性和传统MAC的不灵活性等问题。详细研究了SELinux的体系结构、安全模型和安全上下文,并以Apache服务器为例,介绍了如何定制SELinux以实现安全增强。

【Abstract】 Security-enhanced Linux(SELinux) is a modern Mandatory Access Control(MAC) mechanism in the Linux kernel,which was spearheaded by the Nation Security Agency(NSA) of America.To support fine-grained access control,SELinux implements a combination of Type Enforcement(TE) and Role-based Access Control(RBAC) to design a lot of security policies for the interactions between subjects and objects.It effectively resolves the weakness of the Discretionary Access Control(DAC) and the inflexibleness of the traditional MAC.The architecture,security models and security context of SELinux was studied in detail,and as an example,how to customize the Apache HTTP SELinux policy to enhance system security was also demonstrated.

【关键词】 SELinuxRBAC模型TE模型安全上下文
【Key words】 security-enhanced LinuxRBAC modelTE modelsecurity context
【基金】 国家自然科学基金资助项目(60603068)
  • 【文献出处】 计算机应用 ,Journal of Computer Applications , 编辑部邮箱 ,2009年S1期
  • 【分类号】TP393.08
  • 【被引频次】28
  • 【下载频次】620
节点文献中: 

本文链接的文献网络图示:

本文的引文网络