欢迎访问中国科学院大学学报,今天是
论文

基于LSM框架的审计系统的设计与实现

  • 王富良 ,
  • 贺也平 ,
  • 李丽萍
展开
  • 1. 中国科学院信息安全技术工程研究中心, 北京 100080;
    2. 中国科学院软件研究所, 北京 100049;
    3. 中国科学院研究生院, 北京 100049

收稿日期: 2004-11-17

  修回日期: 2005-02-24

  网络出版日期: 2005-11-15

基金资助

国家自然科学基金项目(60083007);国家重点基础研究发展规划(973)项目(G1999035802)资助

Design and Implementation of LSM Based Secure Auditing System

  • WANG Fu-Liang ,
  • HE Ye-Ping ,
  • LI Li-Ping
Expand
  • 1. Engineering Research Center for Information Security Technology, Chinese Academy of Sciences, Beijing 100080, China;
    2. Institute of Software, Chinese Academy of Sciences, Beijing 100080, China;
    3. Graduate School, Chinese Academy of Sciences, Beijing 100049, China

Received date: 2004-11-17

  Revised date: 2005-02-24

  Online published: 2005-11-15

摘要

LSM是Linux系统的通用访问控制框架,在安胜安全操作系统V4.0中,我们在这一访问控制框架的基础上做了适当的扩展并设计实现了安全审计系统。该安全审计系统与安胜安全操作系统V2.0的审计系统相比,性能得到了很大的提高。另外,隐蔽通道会绕过系统的安全策略来进行非法的数据流传输,我们在审计系统中进行了实时检测和报警。

本文引用格式

王富良 , 贺也平 , 李丽萍 . 基于LSM框架的审计系统的设计与实现[J]. 中国科学院大学学报, 2005 , 22(6) : 707 -711 . DOI: 10.7523/j.issn.2095-6134.2005.6.008

Abstract

LSM is the access control framework for Linux system.In the ANSHENG secure operating system V4.0,a secure auditing system based on the extended Linux Security Modules was introduced.Compared with the secure auditing system of ANSHENG secure operating system V2.0,the LSM based auditing system has a better performance.Last,the auditing system developed a method to detect covered channels in our ANSHENG secure operating system V4.0.

参考文献

[1] DoD 5200.28-STD,Department of Defense Standard.Department of Defense Trusted Computer System Evaluation Criteri a.National Computer Security Center,Ft.Meade,MD,USA,1985.

[2] China State Bureau of Quality and Techni cal Supervision.National Criteria of People's Republi c of China:Classified criteria for security protection of Computer information system.GB 17859-1999,1999(in Chinese).

[3] The International Organization for Standardization.Common Criteria for Information Technology Security Evaluation.ISO IEC 15408:1999(E),1999.

[4] Liu HF,Qing SH,LiuWQ.Design and realization of auditing in secure OS.Journal of Computer Research &Development,2001,38(10):1262~1268 (in Chinese with Engli sh abstract).

[5] Zhao ZK,Qing SH,Li LP.Research on the security architecture supporting dynamic and multiple security polici es.Computer Engineering,2004,30(3):63~66(in Chinese with English abstract).

[6] Qing SH,Liu WQ,Wen HZ.Operating System Security.Beijing:Tsinghua University Press,2004(in Chinese).

[7] Qing SH,Zhu JF.Covet channel analysis on ANSHENG secure operating system.Journal of Software,2004,15(9):1385~1392(in Chinese with Engli sh abstract).

文章导航

/