• Complex
  • Title
  • Keyword
  • Abstract
  • Scholars
  • Journal
  • ISSN
  • Conference
搜索

Author:

Liao, Jianhua (Liao, Jianhua.) | Zhao, Yong (Zhao, Yong.) | Shen, Changxiang (Shen, Changxiang.)

Indexed by:

CPCI-S

Abstract:

In this paper, we introduce a new application isolation model which bases on Least-Privilege principle and Need-to-Know principle. Since this model is easy to implement, we call it the Feather-weight Application Isolation (FAI) model. This model is used to achieve the Process Permission Constraint (PPC) and classified Object Access Control (OAC). The model allows us to make application isolation depending on PPC policies and OAC policies. Compared with the existing complex isolation models such as sandboxes and virtual machines, the FAI model is simpler, and therefore it does not only meet the necessary security requirements but also increases the usability. To isolate applications and prevent classified objects of the applications from being illegally tampered, the FM model extends the traditional two-dimensional access control matrix to a three-dimensional access control matrix, which includes subjects, objects and processes. In order to support multi-level security and Mandatory Access Control (MAC), the concept of processes sensitivity level ranges is considered in the model. In this article, we first give an informal description of the model, and then introduce the formalized description and safety analysis. Finally we explain the feasibility of the model by showing the result of the engineering implementation.

Keyword:

Access control Process constraint Application isolation Security model

Author Community:

  • [ 1 ] [Liao, Jianhua]Peking Univ, Sch Elect Engn & Comp Sci, Beijing 100871, Peoples R China
  • [ 2 ] [Zhao, Yong]Beijing Univ Technol, Dept Comp Sci & Technol, Beijing, Peoples R China
  • [ 3 ] [Shen, Changxiang]Beijing Univ Technol, Dept Comp Sci & Technol, Beijing, Peoples R China

Reprint Author's Address:

  • [Liao, Jianhua]Peking Univ, Sch Elect Engn & Comp Sci, Beijing 100871, Peoples R China

Show more details

Related Keywords:

Related Article:

Source :

TRUSTED SYSTEMS

ISSN: 0302-9743

Year: 2010

Volume: 6163

Page: 197-,

Language: English

Cited Count:

WoS CC Cited Count: 0

SCOPUS Cited Count:

ESI Highly Cited Papers on the List: 0 Unfold All

WanFang Cited Count:

Chinese Cited Count:

30 Days PV: 2

Affiliated Colleges:

Online/Total:623/5335472
Address:BJUT Library(100 Pingleyuan,Chaoyang District,Beijing 100124, China Post Code:100124) Contact Us:010-67392185
Copyright:BJUT Library Technical Support:Beijing Aegean Software Co., Ltd.