skip to main content
research-article
Free Access

A decade of OS access-control extensibility

Published:01 February 2013Publication History
Skip Abstract Section

Abstract

Open source security foundations for mobile and embedded devices.

References

  1. Abrams, M.D., Eggers, K.W., LaPadula, L.J. and Olson, I.M. A generalized framework for access control: An informal description. In Proceedings of the 13th NIST-NCSC National Computer Security Conference (1990), 135--143.Google ScholarGoogle Scholar
  2. Anderson, J.P. Computer Security Technology Planning Study. Technical report, Electronic Systems Division, Air Force Systems Command, 1972.Google ScholarGoogle Scholar
  3. Apple Inc. Kernel authorization. Technical Note TN2127, 2007; http://developer.apple.com/technotes/tn2005/tn2127.html.Google ScholarGoogle Scholar
  4. Badger, L., Sterne, D.F., Sherman, D.., Walker, K.M. and Haghighat, S.A. Practical domain and type enforcement for Unix. In Proceedings of the 1995 IEEE Symposium on Security and Privacy 66 (1995). IEEE Computer Society. Google ScholarGoogle ScholarDigital LibraryDigital Library
  5. Bell, D.E., and L.J. LaPadula. Secure computer systems: mathematical foundations and model. Technical Report M74-244. Mitre Corp., Bedford, MA, 1973.Google ScholarGoogle Scholar
  6. Biba, K. Integrity considerations for secure computer systems. Technical Report TR-3153. Mitre Corp., Bedford, MA, 1977.Google ScholarGoogle Scholar
  7. Boebert, W.E. and Kain, R.Y. A practical alternative to hierarchical integrity policies. In Proceedings of the 8th National Computer Security Conference, 1985.Google ScholarGoogle Scholar
  8. Cantrill, B.M., Shapiro, M.W. and Leventhal, A.H. Dynamic instrumentation of production systems. In Proceedings of the Usenix Annual Technical Conference (Berkeley, CA, 2004). Usenix Association. Google ScholarGoogle ScholarDigital LibraryDigital Library
  9. Fraser, T., Badger, L. and Feldman, M. Hardening COTS software with generic software wrappers. In Proceedings of the 1999 IEEE Symposium on Security and Privacy.Google ScholarGoogle Scholar
  10. Kleiman, S.R. Vnodes: An architecture for multiple file system types in Sun Unix. In Proceedings of the Summer 1986 Usenix Conference.Google ScholarGoogle Scholar
  11. Loscocco, P.A. and Smalley, S.D. Integrating flexible support for security policies into the Linux operating system. In Proceedings of the 2001 Usenix Annual Technical Conference. Usenix Association, 29--42. Google ScholarGoogle ScholarDigital LibraryDigital Library
  12. McKusick, M.K., Neville-Neil, G.V. The Design and Implementation of the FreeBSD Operating System. Pearson Education, 2004. Google ScholarGoogle ScholarDigital LibraryDigital Library
  13. Neumann, P.G., Boyer, R.S., Feiertag, R.J., Levitt, K.N. and Robinson, L. A provably secure operating system: the system, its applications, and proofs, second edition. Technical Report CSL-116. Computer Science Laboratory, SRI International, 1980.Google ScholarGoogle Scholar
  14. Ott, A. Rule-set-based access control (RSBAC) for Linux (2010); http://www.rsbac.org/.Google ScholarGoogle Scholar
  15. Saltzer, J.H. and Schroeder, M.D. The protection of information in computer systems. In Proceedings of the IEEE 63, 9 (1975), 1278--1308.Google ScholarGoogle ScholarCross RefCross Ref
  16. Sebes, E.J. Overview of the architecture of Distributed Trusted Mach. In Proceedings of the Usenix Mach Symposium (1991). Usenix Association, 20--22.Google ScholarGoogle Scholar
  17. Spencer, R., Smalley, S., Loscocco, P., Hibler, M., Andersen, D. and Lepreau, J. 1999. The Flask security architecture: system support for diverse security policies. In Proceedings of the 8th Usenix Security Symposium (1999). Usenix Association, 123--139. Google ScholarGoogle ScholarDigital LibraryDigital Library
  18. Vance, C., Miller, T. C., Dekelbaum, R., Reisse, A. 2007. Security-enhanced Darwin: Porting SELinux to Mac OS X. In Proceedings from the Third Annual Security Enhanced Linux Symposium (2007).Google ScholarGoogle Scholar
  19. Watson, R.N.M. Exploiting concurrency vulnerabilities in system call wrappers. In Proceedings of the First Usenix Workshop on Offensive Technologies. Usenix Association, 2007, 1--8. Google ScholarGoogle ScholarDigital LibraryDigital Library
  20. Watson, R.N.M. New approaches to operating system security extensibility. Technical Report UCAM-CL-TR-818. University of Cambridge, Computer Laboratory, 2012.Google ScholarGoogle Scholar
  21. Watson, R.N.M., Anderson, J., Laurie, B. and Kennaway, K. Capsicum: Practical capabilities for Unix. In Proceedings of the 19th Usenix Security Symposium (2010). Usenix Association. Google ScholarGoogle ScholarDigital LibraryDigital Library
  22. Watson, R.N.M. Feldman, B., Migus, A. and Vance, C. Design and implementation of the TrustedBSD MAC Framework. In Proceedings of the Third DARPA Information Survivability Conference and Exhibition (2003). IEEE.Google ScholarGoogle Scholar
  23. Wright, C., Cowan, C., Morris, J., Smalley, S. and Kroah-Hartman, G. 2002. Linux security modules: General security support for the Linux kernel. In Proceedings of the 11th Usenix Security Symposium (2002). Usenix Association. Google ScholarGoogle ScholarDigital LibraryDigital Library

Index Terms

  1. A decade of OS access-control extensibility

        Recommendations

        Comments

        Login options

        Check if you have access through your login credentials or your institution to get full access on this article.

        Sign in

        Full Access

        • Published in

          cover image Communications of the ACM
          Communications of the ACM  Volume 56, Issue 2
          February 2013
          95 pages
          ISSN:0001-0782
          EISSN:1557-7317
          DOI:10.1145/2408776
          Issue’s Table of Contents

          Copyright © 2013 ACM

          Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

          Publisher

          Association for Computing Machinery

          New York, NY, United States

          Publication History

          • Published: 1 February 2013

          Permissions

          Request permissions about this article.

          Request Permissions

          Check for updates

          Qualifiers

          • research-article
          • Popular
          • Refereed

        PDF Format

        View or Download as a PDF file.

        PDF

        eReader

        View online with eReader.

        eReader

        HTML Format

        View this article in HTML Format .

        View HTML Format