首页> 外国专利> METHOD FOR ILLEGAL PRIVILEGE FLOW PREVENTION AND MANDATORY ACCESS CONTROL USING THE STATE TRANSITION MODEL OF SECURITY ROLE IN Unix/Linux SYSTEM

METHOD FOR ILLEGAL PRIVILEGE FLOW PREVENTION AND MANDATORY ACCESS CONTROL USING THE STATE TRANSITION MODEL OF SECURITY ROLE IN Unix/Linux SYSTEM

机译:Unix / Linux系统中使用安全角色的状态转换模型的非法特权流和强制访问控制的方法

摘要

A method for blocking illegal right transfer and controlling access forcibly by using a security role state transition model of a Unix/Linux system is provided to control the access forcibly in a kernel level by setting security property and applying a modified MLS(Multi-Level Security) policy to a user and a file system. A user security property setting part(101) sets, modifies, and deletes user security property, and stores the set user security property to a user security property database. A file system security property setting part sets(102) modifies, and deletes file system security property, and stores the set file system security property to a file system security property database. A system call controller(103) intercepts a system call related to access control. A security role transition state setting/controlling part forms a process security property table including a process security role state by using the user security property database when the process related to the intercepted system call is generated. A security role access controller determines permission, refuse, or comparison by comparing the security role states of the process and file system security property tables, and transfers an event determined by the comparison to a forcible access controller.
机译:提供一种通过使用Unix / Linux系统的安全角色状态转换模型来阻止非法权限转移并强制控制访问的方法,以通过设置安全属性并应用修改的MLS(多层安全性)来在内核级别强制控制访问。 )对用户和文件系统的策略。用户安全属性设置部分(101)设置,修改和删除用户安全属性,并将设置的用户安全属性存储到用户安全属性数据库中。文件系统安全性属性设置部分sets(102)修改和删除文件系统安全性属性,并将所设置的文件系统安全性属性存储到文件系统安全性属性数据库中。系统调用控制器(103)拦截与访问控制有关的系统调用。安全角色转换状态设置/控制部分在生成与拦截的系统调用相关的过程时,通过使用用户安全属性数据库来形成包括过程安全角色状态的过程安全属性表。安全角色访问控制器通过比较进程和文件系统安全属性表的安全角色状态来确定许可,拒绝或比较,并将通过比较确定的事件传输到强制访问控制器。

著录项

  • 公开/公告号KR100853722B1

    专利类型

  • 公开/公告日2008-08-25

    原文格式PDF

  • 申请/专利权人

    申请/专利号KR20060131826

  • 发明设计人 김기현;김상철;

    申请日2006-12-21

  • 分类号G06F21/22;G06F9/06;

  • 国家 KR

  • 入库时间 2022-08-21 19:51:42

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号