• DocumentCode
    3370586
  • Title

    Integrated Access Permission: Secure and Simple Policy Description by Integration of File Access Vector Permission

  • Author

    Yamaguchi, Takuto ; Tabata, Toshihiro ; Nakamura, Yuichi

  • Author_Institution
    Grad. Sch. of Natural Sci. & Technol., Okayama Univ., Okayama
  • fYear
    2008
  • fDate
    24-26 April 2008
  • Firstpage
    40
  • Lastpage
    45
  • Abstract
    In pervasive computing, embedded systems have a possibility to be attacked by crackers, including 0-day attack, as well as enterprise systems. In particular, in a case where a cracker gets a root privilege, damages are significant. To resolve this problem, Security-Enhanced Linux (SELinux) is useful. However, SELinux has a problem that is significant complexity for configuration because of too fine-grained access control. As a method for resolving this problem, SELinux Policy Editor (SEEdit) has been developed; this is a tool that simplifies the SELinux configuration. SEEdit uses the Simplified Policy Description Language (SPDL) as a policy description language. In the SPDL, we define new access permissions that integrate Access Vector Permissions (AVPs) employed in SELinux to provide access permissions in a security policy. Thus, we propose a set of access permissions named Integrated Access Permissions (IAPs), which enables the achievement of a good balance between reducing the workload of the configurations and guaranteeing security in SELinux. In addition, we evaluate our IAPs and show them almost secure.
  • Keywords
    Linux; authorisation; embedded systems; ubiquitous computing; SEEdit tool; SELinux Policy Editor; Simplified Policy Description Language; access control; embedded systems; file access vector permission; integrated access permission; pervasive computing; security-enhanced Linux; Access control; Financial advantage program; Information security; Linux; Monitoring; Operating systems; Permission; Size control; Software engineering; Tellurium; Access Control; Access Permission; SELinux; Security Policy;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Security and Assurance, 2008. ISA 2008. International Conference on
  • Conference_Location
    Busan
  • Print_ISBN
    978-0-7695-3126-7
  • Type

    conf

  • DOI
    10.1109/ISA.2008.21
  • Filename
    4511531