Dynamic mandatory access control for multiple stakeholders

Dynamic mandatory access control for multiple stakeholders
复制标题

多个利益相关者的动态强制访问控制

DOI:
--
复制
发表时间:
2009
期刊:
ACM Symposium on Access Control Models and Technologies
影响因子:
--
通讯作者:
T. Jaeger
T. Jaeger
中科院分区:
--
文献类型:
--
作者:
Vikhyath Rao;T. Jaeger

文献摘要

被引文献

相似文献

在本文中,我们提出了一个强制性的访问控制系统,使用多个利益相关者的输入组成的政策的基础上运行时的信息。在新兴的开放式蜂窝电话系统环境中,许多设备运行其访问权限取决于多个利益相关者(诸如设备所有者、服务提供商、应用所有者等)的软件,而不是单个系统管理员。然而,当前的访问控制管理仍然是任意的,允许运行的和可能受损的进程管理权限,或者是强制的,要求系统管理员知道所有可能的法律的运行的所有权限。一个关键的问题是,用户可以下载任意程序到他们的设备,要求系统包含这样的程序,同时允许一些合理的功能。然而,这样的程序可能需要访问权限,该权限与其他冲突的权限结合可能导致攻击,例如允许IP语音呼叫。在我们的方法中,我们使用一个“软”沙盒机制,首先包含这样的进程,请求利益相关者授权的沙箱之外的操作,不禁止的政策,并保持一个运行时执行角色的进程,以确定其访问状态的利益相关者。我们定义了一个代理策略服务器,缓存和利益相关者的政策相结合,使这样的访问决策。我们的框架是通过修改SELinux模块并使用远程代理策略服务器实现的,尽管本地代理策略服务器也是可能的。仅当需要咨询涉众并缓存新权限时,我们才会产生0.288 ts的性能开销。
In this paper, we present a mandatory access control system that uses input from multiple stakeholders to compose policies based on runtime information. In the emerging open cell phone system environment, many devices run software whose access permissions depends on multiple stakeholders, such as the device owner, the service provider, the application owner, etc., rather than a single system administrator. However, current access control administration remains as either discretionary, allowing the running and perhaps compromised process to administer permissions, or mandatory, requiring a system administrator to know all permissions for all possible legal runs. A key problem is that users may download arbitrary programs to their devices, requiring that the system contain such programs while allowing some reasonable functionality. However, such programs may need access to permissions that in combination with other conflicting permissions may lead to an attack, such as allowing voice-over-IP calls. In our approach, we use a "soft" sand-boxing mechanism to first contain such processes, request the stakeholder to authorize operations outside the sandbox that are not prohibited by policy, and maintain a runtime execution role for the process to identify its access state to the stakeholders. We define a proxy policy server that caches and combines stakeholder policies to make such access decisions. Our framework was implemented by modifying the SELinux module and using a remote proxy policy server, although a local proxy policy server is also possible. We incur a 0.288 ts performance overhead only when stakeholders need to be consulted, and new permissions are cached.