loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
1995 IEEE Symposium on Security and Privacy
Practical Domain and Type Enforcement for UNIX
Oakland, CA
May 08-May 10
ISBN: 0-8186-7015-0
L. Badger, Trusted Inf. Syst. Inc., Glenwood, MD, USA
D.F. Sterne, Trusted Inf. Syst. Inc., Glenwood, MD, USA
D.L. Sherman, Trusted Inf. Syst. Inc., Glenwood, MD, USA
K.M. Walker, Trusted Inf. Syst. Inc., Glenwood, MD, USA
S.A. Haghighat, Trusted Inf. Syst. Inc., Glenwood, MD, USA
Abstract: Type enforcement is a table-oriented mandatory access control mechanism well-suited for confining applications and restricting information flows. Although both flexible and strong, type enforcement alone imposes significant administrative costs and has not been widely adopted. Domain and Type Enforcement (DTE) is an enhanced version of type enforcement designed to provide needed simplicity and compatibility. Two primary techniques distinguish DTE from simple type enforcement: DTE policies are expressed in a high-level language that includes file security attribute associations as well as other access control information; and during system execution, DTE file security attributes are maintained using a concise human-readable format in a runtime DTE policy database, thus removing the need for security-specific low-level data formats. Such formats are a major source of incompatibility for security-enhanced systems. A DTE UNIX prototype system has been implemented to evaluate these primary DTE concepts. This paper presents experiences gained and preliminary results indicating that DTE can provide cost effective security increases to UNIX systems while maintaining a high degree of compatibility with existing programs and media.
Index Terms:
Unix; authorisation; database management systems; costing; security of data; Domain and Type Enforcement; UNIX; table-oriented mandatory access control; type enforcement; administrative costs; DTE policies; high-level language; file security attribute associations; system execution; file security attributes; human-readable format; DTE policy database; security-specific low-level data formats; security-enhanced systems; cost effective security; compatibility
Citation:
L. Badger, D.F. Sterne, D.L. Sherman, K.M. Walker, S.A. Haghighat, "Practical Domain and Type Enforcement for UNIX," sp, pp.0066, 1995 IEEE Symposium on Security and Privacy, 1995
Usage of this product signifies your acceptance of the Terms of Use.