History-based access control for mobile code

History-based access control for mobile code
复制标题

基于历史记录的移动代码访问控制

DOI:
--
复制
发表时间:
1998
期刊:
Conference on Computer and Communications Security
影响因子:
--
通讯作者:
V. Chaudhary
V. Chaudhary
中科院分区:
--
文献类型:
--
作者:
G. Edjlali;A. Acharya;V. Chaudhary

文献摘要

被引文献

相似文献

在本文中,我们提出了一种基于历史的访问控制机制,它适用于调解来自移动代码的访问。基于历史的访问控制背后的关键思想是维护各个程序所发出的访问请求的选择性历史记录,并利用该历史记录来更好地区分安全请求和潜在危险请求。一个程序被允许做什么取决于它自身的行为和身份,而不是它被加载的位置或其作者/提供者的身份。基于历史的访问控制有可能显著扩大可执行程序的集合,同时不损害安全性或易用性。我们描述了Deeds的设计和实现,Deeds是一种用于Java的基于历史的访问控制机制。Deeds的访问控制策略是用Java编写的,并且在其访问正被调解的程序仍在执行时可以进行更新。
In this paper, we present a history-based access-control mechanism that is suitable for mediating accesses from mobile code. The key idea behind history-based access-control is to maintain a selective history of the access requests made by individual programs and to use this history to improve the differentiation between safe and potentially dangerous requests. What a program is allowed to do depends on its own behavior and identity and not the location it was loaded from or the identity of its author/provider. History-based access-control has the potential to significantly expand the set of programs that can be executed without compromising security or ease of use. We describe the design and implementation of Deeds, a history-based access-control mechanism for Java. Access-control policies for Deeds are written in Java, and can be updated while the programs whose accesses are being mediated are still executing.