首页    期刊浏览 2024年07月05日 星期五
登录注册

文章基本信息

  • 标题:Algorithms for Automatic Analysis of SELinux Security Policy
  • 本地全文:下载
  • 作者:Gaoshou Zhai ; Tong Wu ; Jing Bai
  • 期刊名称:International Journal of Security and Its Applications
  • 印刷版ISSN:1738-9976
  • 出版年度:2013
  • 卷号:7
  • 期号:1
  • 出版社:SERSC
  • 摘要:Configuration of security policies is an important but complicated work for running of secure operating systems. On the one hand, completely correct and consistent configuration is the necessary prerequisite for secure and credible system operation. On the other hand, errors and bugs are incidental anywhere within configuration at all time. Therefore, algorithms for automatic analysis of SELinux security policy are studied in this paper. Based on an improved analysis model similar to SELAC model, both algorithms for validity analysis and integrity analysis are designed. So that any access relations among subjects and objects with specified security contexts can be identified correctly by using the former algorithm. And all rules that could potentially influence integrity of subjects and objects can be detected based on the latter algorithm. Furthermore, a corresponding prototype is implemented in C Language and a security policy configuration as to an application system called Student-Teacher system is designed based on the architecture of reference policy in order to test the prototype. Results are satisfactory and it shows that related algorithms are potential to be used to build an appropriate tool to assist people to perform configuration work and to complete correct and reliable configuration.
  • 关键词:Validity analysis; Integrity analysis; Security policy; SELinux; Access control; Secure operating systems
国家哲学社会科学文献中心版权所有