Security policy enforcement at the file system level in the Windows NT operating system family

作者: S.D. Wolthusen

DOI: 10.1109/ACSAC.2001.991521

关键词:

摘要: This paper describes the implementation of an enforcement module for file system security implemented as part a architecture distributed systems which enforces centrally administered policy under Windows NT operating platform. The mechanism provides mandatory access control, encryption, and auditing on individual basis across while being fully transparent to both users application programs functioning regardless type or its attachment mechanism.

参考文章(11)
Spencer E. Minear, Providing policy control over object operations in a mach based system usenix security symposium. pp. 13- 13 ,(1995)
John F. Farrell, S. Jeff Turner, Peter A. Loscocco, Ruth C. Taylor, Stephen D. Smalley, Patrick A. Muckelbauer, The Inevitability of Failure: The Flawed Assumption of Security in Modern Computing Environments ,(2000)
Rajeev Nagar, Windows NT file system internals: a developer's guide O'Reilly & Associates, Inc.. ,(1997)
Erez Zadok, Alex Shender, Ion Badulescu, Extending file systems using stackable templates usenix annual technical conference. pp. 5- 5 ,(1999)
Helen Custer, David A. Solomon, Inside Windows NT ,(1992)
O.S. Saydjari, J.M. Beckman, J.R. Leaman, LOCK trek: navigating uncharted space ieee symposium on security and privacy. pp. 167- 175 ,(1989) , 10.1109/SECPRI.1989.36291
Bruce J. Walker, Richard A. Kemmerer, Gerald J. Popek, Specification and verification of the UCLA Unix security kernel Communications of The ACM. ,vol. 23, pp. 118- 131 ,(1980) , 10.1145/358818.358825
Matt Blaze, A cryptographic file system for UNIX computer and communications security. pp. 9- 16 ,(1993) , 10.1145/168588.168590
Ray Spencer, Stephen Smalley, Peter Loscocco, Mike Hibler, David Andersen, Jay Lepreau, The flask security architecture: system support for diverse security policies usenix security symposium. pp. 11- 11 ,(1999) , 10.21236/ADA443108