More Enforceable Security Policies

More Enforceable Security Policies
复制标题

更可执行的安全策略

DOI:
--
复制
发表时间:
2002
期刊:
影响因子:
--
通讯作者:
D. Walker
D. Walker
中科院分区:
--
文献类型:
--
作者:
Lujo Bauer;Jarred Adam Ligatti;D. Walker

文献摘要

被引文献

相似文献

我们分析了可以通过在运行时监控程序来执行的安全策略的空间。我们的程序监视器是自动机,它检查程序操作的序列,并在序列偏离指定的艾德策略时对其进行转换。最简单的这种自动机通过终止程序来截断动作序列。这种自动机通常被称为安全自动机,它们执行Schneider的EM类安全策略。我们设计了一种具有更强大的转换能力的自动机,包括在事件流中插入一系列动作和在不终止程序的情况下抑制事件流中的动作的能力。我们给出了这些新的自动机能够执行的政策的集合论特征,并表明它们是EM政策的超集。
We analyze the space of security policies that can be enforced by monitoring programs at runtime. Our program monitors are automata that examine the sequence of program actions and transform the sequence when it deviates from the speci(cid:12)ed policy. The simplest such automaton truncates the action sequence by terminating a program. Such automata are commonly known as security automata, and they enforce Schneider’s EM class of security policies. We de(cid:12)ne automata with more powerful transformational abilities, including the ability to insert a sequence of actions into the event stream and to suppress actions in the event stream without terminating the program. We give a set-theoretic characterization of the policies these new automata are able to enforce and show that they are a superset of the EM policies.