Back to Search Start Over

Enforcing the Principle of Least Privilege with a State-Based Privilege Control Model.

Authors :
Deng, Robert H.
Feng Bao
HweeHwa Pang
Jianying Zhou
Bin Liang
Heng Liu
Wenchang Shi
Yanjun Wu
Source :
Information Security Practice & Experience; 2005, p109-120, 12p
Publication Year :
2005

Abstract

In order to provide effective support to the principle of least privilege, considering the limitation of traditional privilege mechanisms, this paper proposes a new privilege control model called State-Based Privilege Control (SBPC) and presents the design and implementation of a prototype system for SBPC called Controlled Privilege Framework (CPF) on the Linux operating system platform. SBPC decomposes the time space of a process' lifetime into a series of privilege states according to activities of the process and its need for special permissions. The privilege state is closely related to the application logic of a process. It is the privilege state transfer event that stimulates a process to transfer from one privilege state into another one. For a specified process, there is a specific set of privileges corresponding to every privilege state of the process. With the implementation of CPF, experiment results show that fine-grain and automatic privilege control can be exercised transparently to traditional applications, threats of intrusion to a system can be reduced greatly, and support to the principle of least privilege can therefore be achieved effectively. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISBNs :
9783540255840
Database :
Supplemental Index
Journal :
Information Security Practice & Experience
Publication Type :
Book
Accession number :
32976785