期刊文献+

Linux安全模块在安全审计系统中的应用 被引量:1

The application of Linux security modules for security audit system
原文传递
导出
摘要 安全审计是保障计算机系统本地安全和网络安全的重要技术,通过对审计信息的分析可以为计算机系统的脆弱性评估、责任认定、损失评估、系统恢复提供关键性信息.为了满足各类应用对Linux平台安全性的要求,Linus Torvalds提出了轻量级、通用的访问控制框架LSM.据此,利用LSM框架提供的安全模块可装载性和编程接口,实现了细粒度、可移植、高安全性的安全审计系统. The security audit system is effective for both the host security and network security; it should be an ongoing process but not be a one - time shot. On top, security is a delicate balance among protection, availability and User acceptance. An audit trail is a series of records of computer events, about an operating system, an application, or user activities. It is generated by an auditing system that monitors system activity. By analyzing the audit trails, we can determine vulnerabilities, establish accountability, assess damage and recover the system. Linux security modules (LSM) is a lightweight, general purpose, access control framework for the mainstream Linux kernel. Base on the general purpose framework provides by Linux security modules, a portable, loadable, finer -grained security audit system was designed and implemented.
作者 张浩
出处 《福州大学学报(自然科学版)》 CAS CSCD 北大核心 2008年第2期203-207,共5页 Journal of Fuzhou University(Natural Science Edition)
基金 福建省教育厅科研资助项目(JA07028)
关键词 LINUX安全模块 访问控制 安全审计 系统调用 细粒度 Linux security modules access control security audit system calls finer - grained
  • 相关文献

参考文献6

二级参考文献25

  • 1丁志芳,徐孟春,李晓秋,刘琰.Linux安全模块的设计与实现[J].计算机应用,2003,23(z1):289-291. 被引量:2
  • 2Daniel P Bovet,Marco Cesati.深入理解Linux内核[M].北京:中国电力出版社,2001. 被引量:4
  • 3毛德操 胡希明.Linux内核源代码情景分析[M].杭州:浙江大学出版社,2001.. 被引量:195
  • 4HOSMER H H.The multipolicy paradigm for trusted systems[A].Proceedings of the New Security Paradigms Workshop[C].little Compton,R.I,IEEE Press,1992-1993.19-32. 被引量:1
  • 5KUHNHAUSER W E,OSTROWSKI M V K.A framework to support multiple security policies[A].Proceedings of the 7th Annual Canadian Computer Security Symposium[C].Canadian System Security Centre,Ottawa,Canada,1995.1-19. 被引量:1
  • 6WRIGHT C,COWAN C,SMALLEY S,et al.Linux security modules:general security support for the linux kernel[A].USENIX Security Symposium[C].San Francisco,CA,2002.17-31. 被引量:1
  • 7SMALLEY S.Implementing SELinux as a Linux Security Module[R].NAI Labs Report#01-043,2002. 被引量:1
  • 8EDWARDS A,JAEGER T,ZHANG X L.Verifying Authorization Hook Placement for the Linux Security Modules Framework[R].IBM Research Report,RC22254(W0111-057),2001. 被引量:1
  • 9JAJODIA S,SAMARATI P,SUBRAHMANIAN V S.A logical language for expressing authorizations[A].Proceedings of the IEEE Symposium on Security and Privacy[C].1997.31-42. 被引量:1
  • 10BERTINO E,CATANIA B,et al.A system to specify and manage multipolicy access control models[A].Proceedings of the Third International Workshop on Policies for Distributed Systems and Networks (POLICY'02)[C].2002.116-127. 被引量:1

共引文献7

同被引文献2

引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部