DocumentCode :
3370586
Title :
Integrated Access Permission: Secure and Simple Policy Description by Integration of File Access Vector Permission
Author :
Yamaguchi, Takuto ; Tabata, Toshihiro ; Nakamura, Yuichi
Author_Institution :
Grad. Sch. of Natural Sci. & Technol., Okayama Univ., Okayama
fYear :
2008
fDate :
24-26 April 2008
Firstpage :
40
Lastpage :
45
Abstract :
In pervasive computing, embedded systems have a possibility to be attacked by crackers, including 0-day attack, as well as enterprise systems. In particular, in a case where a cracker gets a root privilege, damages are significant. To resolve this problem, Security-Enhanced Linux (SELinux) is useful. However, SELinux has a problem that is significant complexity for configuration because of too fine-grained access control. As a method for resolving this problem, SELinux Policy Editor (SEEdit) has been developed; this is a tool that simplifies the SELinux configuration. SEEdit uses the Simplified Policy Description Language (SPDL) as a policy description language. In the SPDL, we define new access permissions that integrate Access Vector Permissions (AVPs) employed in SELinux to provide access permissions in a security policy. Thus, we propose a set of access permissions named Integrated Access Permissions (IAPs), which enables the achievement of a good balance between reducing the workload of the configurations and guaranteeing security in SELinux. In addition, we evaluate our IAPs and show them almost secure.
Keywords :
Linux; authorisation; embedded systems; ubiquitous computing; SEEdit tool; SELinux Policy Editor; Simplified Policy Description Language; access control; embedded systems; file access vector permission; integrated access permission; pervasive computing; security-enhanced Linux; Access control; Financial advantage program; Information security; Linux; Monitoring; Operating systems; Permission; Size control; Software engineering; Tellurium; Access Control; Access Permission; SELinux; Security Policy;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Security and Assurance, 2008. ISA 2008. International Conference on
Conference_Location :
Busan
Print_ISBN :
978-0-7695-3126-7
Type :
conf
DOI :
10.1109/ISA.2008.21
Filename :
4511531
Link To Document :
بازگشت