• DocumentCode
    2795566
  • Title

    An enhanced scheme of enforcing DTE security policy based on trusted computing technology

  • Author

    Liu, Wei-peng ; Zuo, Xiao-dong ; Huang, Qiang

  • Author_Institution
    State Key Lab. of Inf. Security, Grad. Sch. of Chinese Acad. of Sci., Beijing
  • Volume
    7
  • fYear
    2008
  • fDate
    12-15 July 2008
  • Firstpage
    3657
  • Lastpage
    3662
  • Abstract
    As a classical security policy, DTE (domain and type enforcement) is usually used to protect the integrity of information and implemented in many famous security operating systems. But there are three main questions for most systems that have implemented DTE security policy as follows: 1) security policy enforcing module is easy to be tampered and bypass before loaded; 2) The content of security policy file is easily to be disclosed and modified; 3) The system is prone to suffer from "changed-name" attack. Trusted computing provides novel ideas and methods to solve the question of information security. The paper presents an enhanced scheme of enforcing DTE security policy based on trusted computing technology, it is scalable and can deal with the questions mentioned above well. It analyses the whole design of scheme in details and implements a prototype system to demonstrate the feasibility. Experiment results show that it has accepted performance overhead.
  • Keywords
    data integrity; operating systems (computers); security of data; DTE security policy; changed-name attack; domain and type enforcement; information integrity; security operating systems; trusted computing technology; Authorization; Computer security; Cybernetics; Data security; File systems; Information security; Machine learning; Operating systems; Protection; Prototypes; DTE; Security module; Security operating system; Trusted computing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Machine Learning and Cybernetics, 2008 International Conference on
  • Conference_Location
    Kunming
  • Print_ISBN
    978-1-4244-2095-7
  • Electronic_ISBN
    978-1-4244-2096-4
  • Type

    conf

  • DOI
    10.1109/ICMLC.2008.4621040
  • Filename
    4621040