Welcome to Journal of University of Chinese Academy of Sciences,Today is

Administration of User Account in Secure OS

  • Zhang Xiang-feng ,
  • Sun Yu-fang
Expand
  • Institute of Software, Chinese Academy of Sciences, Beijing 100080, China

Online published: 2004-01-10

Abstract

Many secure operating systems are developed based upon UNIX-like systems and many access control mechanisms and audit mechanism are introduced,but the system account file does not assure unique UID and might lead to confusion in audit trails.Users access rights in some security mechanisms are generally managed quite independently of account management and should also be deleted when one user is removed from the account file to avoid unintended reuse by another user.All those things require that the account file should be administrated in a way different from the traditional one in UNIX.Puts forw ard a mechanism to keep unique UID and to capture user account alteration in system call level.Puts the mechanism into practice in SLINUX,a variant ofLINUX,and provide the performance analysis.

Cite this article

Zhang Xiang-feng , Sun Yu-fang . Administration of User Account in Secure OS[J]. Journal of University of Chinese Academy of Sciences, 2004 , 21(1) : 95 -100 . DOI: 10.7523/j.issn.2095-6134.2004.1.015

References

[1] P Loscocco, S Smalley, P Muckelbauer, R Taylor, J Turner, J Farrell.The inevitability of failure:The flawed assumption of security in modern comput ing environments.In :Proceedings of the 21st N ational Inf ormation S ystems Secu rit y Conference.1998.303-314

[2] National Computer Security Center.Department of defense trusted computer system evaluation criteria.DoD 5200.28-STD.1985

[3] The International Organization for Standardization.Common criteria for information technology security evaluation———Part 1, 2, 3。1999

[4] Paul Whelan.Linux security auditing.Available at http://ww.sans.org.2001

[5] Deborah Downs, Jerzy Rub, Kenneth Kung, Carole Joran。Issues in discretionary access control。In:Proceedings of the 1985 IEEE Sympo-sium on S ecurity and Privacy.IEEE C omput er S ociety Press, 1985.208

[6] Fort George G Meade.A guide to understanding audit in trusted systems.NCSC-TG-001.Version-2, Library No.S-228, 470.1987

[7] Terry Escamilla.Intrusion detection:Network security beyond the firewall.Wiley Computer Publishing, 1998.ISBN 0-471-29000-9.30

Outlines

/