• DocumentCode
    2734538
  • Title

    Implementation of a discretionary access control model for script-based systems

  • Author

    Jaeger, Trent ; Prakash, Atul

  • Author_Institution
    Dept. of Electr. Eng. & Comput. Sci., Michigan Univ., Ann Arbor, MI, USA
  • fYear
    1995
  • fDate
    13-15 Jun 1995
  • Firstpage
    70
  • Lastpage
    84
  • Abstract
    Powerful applications can be implemented using command scripts. A command script is a program written by one user, called a writer, and made available to another user, called the reader, who executes the script. For instance, command scripts could be used by Mosaic, the popular World-wide Web browsing tool, to provide fancy interfaces to services, such as banking, shopping, etc. However, the use of command scripts presents a serious security problem. A command script is run with the reader´s access rights, so a writer can use a command script to gain unauthorized access to the reader´s data and applications. Existing solutions to the problem either severely restrict I/O capability of scripts, limiting the range of applications that can be supported, or permit all I/O to scripts, potentially compromising the security of the reader´s data. We define a discretionary access control model that permits users to flexibly limit the access rights of the processes that execute a command script. We use this model in a prototype system that safely executes command scripts available from Mosaic
  • Keywords
    authorisation; security of data; Mosaic; World-wide Web browsing tool; discretionary access control model; prototype system; script-based systems; unauthorized access; Access control; Application software; Data security; Electronic mail; File systems; Laboratories; Permission; Postal services; Power system modeling; Software systems;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Foundations Workshop, 1995. Proceedings., Eighth IEEE
  • Conference_Location
    County Kerry
  • ISSN
    1063-6900
  • Print_ISBN
    0-8186-7033-9
  • Type

    conf

  • DOI
    10.1109/CSFW.1995.518554
  • Filename
    518554