全部 标题 作者
关键词 摘要

OALib Journal期刊
ISSN: 2333-9721
费用:99美元

查看量下载量

相关文章

更多...
软件学报  2008 

Analysis on Implicit Authorization in Privilege Through Rule Deduction
基于规则推导的特权隐式授权分析

Keywords: privilege,constraint rule,execution rule,deduction,implicit authorization
特权
,约束规则,执行规则,推导,隐式授权

Full-Text   Cite this paper   Add to My Lib

Abstract:

A scheme on studying the safety issues for privilege in systems is introduced.Since the particular faculty of transiting security states makes analyzing and protecting privilege for a system difficult,techniques used in traditional access control should not copy to this field.For this reason the features are firstly inspected by discussing the origination of privilege using access control space theory.Then rules defined for a system could be divided into two categories:constraint rules and execution rules,describing the restrictions and effect of an authorization respectively.Furthermore,a special authorization relation between different privilege operations,as well as its properties,is investigated against rules' logical patterns by deduction.A quick algorithm for constructing authorization deduction graph is also provided.Basing on it,common safety issue of implicit authorization was reviewed with the possibility to be abused.Finally this paper formalizes the capability mechanism defined by POSIX (portable operating system interface) standard,constructing ADG (authorization deduction graph) for it.The design is revised with countermeasures against privilege abusing so as to preserve consistent with the principle of least privilege.

Full-Text

Contact Us

service@oalib.com

QQ:3279437679

WhatsApp +8615387084133