hidden
Image Database Export Citations

Menu:

Secure and Usable Integrity Protection Model for Operating Systems

Show full item record

Type: Working Paper
Author: Chang, Eric
Date: 2016
Agency: Yale University
Series: Working Paper
URI: https://hdl.handle.net/10535/10226
Sector: Theory
Region: North America
Subject(s): research
Abstract: "Host compromise is one of the most serious security problems for operating systems today. Existing integrity protection models for operating systems are difficult to use; on the other hand, the most available integrity protection models only provide heuristic approaches without strong guarantees. This paper presents SecGuard, a secure and high-available integrity protection model for operating systems. To ensure the security of systems, SecGuard provides formal guarantees that operating systems are security under three threats: network-based threat, IPC communication threat, and contaminative file threat. On the other hand, we introduce some novel mechanisms to ensure high-available of the model. For instance, SecGuard leverages the information of the existing discretionary access control mechanism to initialize integrity labels for subjects and objects in the systems. Moreover, we describe the implementation of SecGuard for Linux using Linux Security Modules framework, and show it has low overhead and effectively achieve security and high-availability for operating systems."

Files in this item

Files Size Format View xmlui.dri2xhtml.METS-1.0.item-files-description
llncs.pdf 285.3Kb PDF View/Open Main article

This item appears in the following document type(s)

Show full item record