Practical Domain and Type Enforcement for UNIX
- 19 November 2002
- proceedings article
- Published by Institute of Electrical and Electronics Engineers (IEEE)
Abstract
Type enforcement is a table-oriented mandatory access control mechanism well-suited for confining applications and restricting information flows. Although both flexible and strong, type enforcement alone imposes significant administrative costs and has not been widely adopted. Domain and Type Enforcement (DTE) is an enhanced version of type enforcement designed to provide needed simplicity and compatibility. Two primary techniques distinguish DTE from simple type enforcement: DTE policies are expressed in a high-level language that includes file security attribute associations as well as other access control information; and during system execution, DTE file security attributes are maintained using a concise human-readable format in a runtime DTE policy database, thus removing the need for security-specific low-level data formats. Such formats are a major source of incompatibility for security-enhanced systems. A DTE UNIX prototype system has been implemented to evaluate these primary DTE concepts. This paper presents experiences gained and preliminary results indicating that DTE can provide cost effective security increases to UNIX systems while maintaining a high degree of compatibility with existing programs and media.Keywords
This publication has 14 references indexed in Scilit:
- LOCK trek: navigating uncharted spacePublished by Institute of Electrical and Electronics Engineers (IEEE) ,2003
- Access meditation in a message passing kernelPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2003
- A resource allocation model for denial of servicePublished by Institute of Electrical and Electronics Engineers (IEEE) ,2003
- A specification and verification method for preventing denial of serviceIEEE Transactions on Software Engineering, 1990
- Specifications for Multi-Level Security and a Hook-UpPublished by Institute of Electrical and Electronics Engineers (IEEE) ,1987
- A Secure Capability Computer SystemPublished by Institute of Electrical and Electronics Engineers (IEEE) ,1986
- A security model for military message systemsACM Transactions on Computer Systems, 1984
- Unwinding and Inference ControlPublished by Institute of Electrical and Electronics Engineers (IEEE) ,1984
- Non-Discretionery Controls for Commercial ApplicationsPublished by Institute of Electrical and Electronics Engineers (IEEE) ,1982
- Secure Computer System: Unified Exposition and Multics InterpretationPublished by Defense Technical Information Center (DTIC) ,1976