Compatible and Usable Mandatory Access Control for Good-enough OS Security

Autor: Shan, Zhiyong
Rok vydání: 2016
Předmět:
Druh dokumentu: Working Paper
DOI: 10.1109/ISECS.2009.29
Popis: OS compromise is one of the most serious computer security problems today, but still not being resolved. Although people proposed different kinds of methods, they could not be accepted by most users who are non-expert due to the lack of compatibility and usability. In this paper, we introduce a kind of new mandatory access control model, named CUMAC, that aims to achieve good-enough security, high compatibility and usability. It has two novel features. One is access control based on tracing potential intrusion that can reduce false negatives and facilitate security configuration, in order to improve both compatibility and usability; the other is automatically figuring out all of the compatibility exceptions that usually incurs incompatible problems. The experiments performed on the prototype show that CUMAC can defense attacks from network, mobile disk and local untrustable users while keeping good compatibility and usability.
Comment: Electronic Commerce and Security, 2009. ISECS '09. Second International Symposium on
Databáze: arXiv