Administration of User Account in Secure OS
Online published: 2004-01-10
张相锋 , 孙玉芳 . 安全操作系统中用户账号的管理(英文)[J]. 中国科学院大学学报, 2004 , 21(1) : 95 -100 . DOI: 10.7523/j.issn.2095-6134.2004.1.015
Many secure operating systems are developed based upon UNIX-like systems and many access control mechanisms and audit mechanism are introduced,but the system account file does not assure unique UID and might lead to confusion in audit trails.Users access rights in some security mechanisms are generally managed quite independently of account management and should also be deleted when one user is removed from the account file to avoid unintended reuse by another user.All those things require that the account file should be administrated in a way different from the traditional one in UNIX.Puts forw ard a mechanism to keep unique UID and to capture user account alteration in system call level.Puts the mechanism into practice in SLINUX,a variant ofLINUX,and provide the performance analysis.
Key words: secure OS; security mechanism; audit
[1] P Loscocco, S Smalley, P Muckelbauer, R Taylor, J Turner, J Farrell.The inevitability of failure:The flawed assumption of security in modern comput ing environments.In :Proceedings of the 21st N ational Inf ormation S ystems Secu rit y Conference.1998.303-314
[2] National Computer Security Center.Department of defense trusted computer system evaluation criteria.DoD 5200.28-STD.1985
[3] The International Organization for Standardization.Common criteria for information technology security evaluation———Part 1, 2, 3。1999
[4] Paul Whelan.Linux security auditing.Available at http://ww.sans.org.2001
[5] Deborah Downs, Jerzy Rub, Kenneth Kung, Carole Joran。Issues in discretionary access control。In:Proceedings of the 1985 IEEE Sympo-sium on S ecurity and Privacy.IEEE C omput er S ociety Press, 1985.208
[6] Fort George G Meade.A guide to understanding audit in trusted systems.NCSC-TG-001.Version-2, Library No.S-228, 470.1987
[7] Terry Escamilla.Intrusion detection:Network security beyond the firewall.Wiley Computer Publishing, 1998.ISBN 0-471-29000-9.30
/
| 〈 |
|
〉 |