DocumentCode :
1384106
Title :
Managing system and active-content integrity
Author :
Michener, John R. ; Acar, Tolga
Author_Institution :
Enterprises Solutions Inc., Monterey, CA, USA
Volume :
33
Issue :
7
fYear :
2000
fDate :
7/1/2000 12:00:00 AM
Firstpage :
108
Lastpage :
110
Abstract :
In a shared, multiuser environment, protecting data from damage or misappropriation by unauthorized users is a major concern. The widespread use of active (executable) content such as Microsoft ActiveX controls and Javascripts has given rise to a dangerous, common practice: executing unknown, untrusted code. Security-minded users typically address this problem by executing only signed content that a familiar entity has verified. However, code signing does not protect against bugs already present in the signed code. Patched or new versions of the code can be issued, but the loader (which verifies and loads the executable content, and then transfers the execution control to the module) will still accept the old version, unless the newer version is installed over it. We propose a method that addresses the executable content management problem. Our method employs an executable content loader (which we call a strong loader) and a short-lived configuration management file to address the software aging problem. The loader is tightly integrated to the operating system. It downloads the configuration file from an integrity server; then it verifies and loads executable modules by applying the policy in this configuration file
Keywords :
configuration management; data integrity; multi-access systems; network operating systems; operating systems (computers); security of data; Javascripts; Microsoft ActiveX controls; active-content integrity; code signing; data protection; executable content; executable content loader; executable content management problem; executable modules; execution control; integrity server; operating system; security-minded users; shared multiuser environment; short-lived configuration management file; signed content; software aging problem; strong loader; unauthorized users; unknown untrusted code; Content management; Control systems; Counting circuits; Information security; Internet; Operating systems; Power system protection; Software maintenance; Software systems; Watches;
fLanguage :
English
Journal_Title :
Computer
Publisher :
ieee
ISSN :
0018-9162
Type :
jour
DOI :
10.1109/2.869389
Filename :
869389
Link To Document :
بازگشت