Design of secure operating systems with high security levels

被引:0
|
作者
QING SiHan1
2 School of Software and Microelectronics
3 Institute of Computing Technology
机构
基金
中国国家自然科学基金;
关键词
secure operating systems with high security levels; architecture; security model; covert channel analysis;
D O I
暂无
中图分类号
TP316 [操作系统]; TP309 [安全保密];
学科分类号
081201 ; 081202 ; 0835 ; 0839 ; 1402 ;
摘要
Numerous Internet security incidents have shown that support from secure operating systems is paramount to fighting threats posed by modern computing environments. Based on the requirements of the relevant national and international standards and criteria, in combination with our experience in the design and development of the ANSHENG v4.0 secure operating system with high security level (hereafter simply referred to as ANSHENG OS), this paper addresses the following key issues in the design of secure operating systems with high security levels: se- curity architecture, security policy models, and covert channel analysis. The design principles of security architecture and three basic security models: confidentiality, integrity, and privilege control models are discussed, respectively. Three novel security models and new security architecture are proposed. The prominent features of these proposals, as well as their applications to the ANSHENG OS, are elaborated. Cover channel analysis (CCA) is a well-known hard problem in the design of secure operating systems with high security levels since to date it lacks a sound theoretical basis and systematic analysis approach. In order to resolve the fundamental difficulties of CCA, we have set up a sound theoretical basis for completeness of covert channel identification and have proposed a unified framework for covert channel identification and an efficient backward tracking search method. The successful application of our new proposals to the ANSHENG OS has shown that it can help ease and speedup the entire CCA process.
引用
收藏
页码:399 / 418
页数:20
相关论文
共 50 条
  • [1] Design of secure operating systems with high security levels
    Qing Sihan
    Shen ChangXiang
    [J]. SCIENCE IN CHINA SERIES F-INFORMATION SCIENCES, 2007, 50 (03): : 399 - 418
  • [2] Design of secure operating systems with high security levels
    SiHan Qing
    ChangXiang Shen
    [J]. Science in China Series F: Information Sciences, 2007, 50 : 399 - 418
  • [3] Security patterns and secure systems design
    Fernandez, Eduardo B.
    [J]. Dependable Computing, Proceedings, 2007, 4746 : 233 - 234
  • [4] Abstract security patterns and the design of secure systems
    Fernandez, Eduardo B.
    Yoshioka, Nobukazu
    Washizaki, Hironori
    Yoder, Joseph
    [J]. CYBERSECURITY, 2022, 5 (01)
  • [5] Abstract security patterns and the design of secure systems
    Eduardo B. Fernandez
    Nobukazu Yoshioka
    Hironori Washizaki
    Joseph Yoder
    [J]. Cybersecurity, 5
  • [6] Reducing Security Policy Size for Internet Servers in Secure Operating Systems
    Yokoyama, Toshihiro
    Hanaoka, Miyuki
    Shimamura, Makoto
    Kono, Kenji
    Shinagawa, Takahiro
    [J]. IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2009, E92D (11): : 2196 - 2206
  • [7] Secure Design Patterns for Security in Smart Metering Systems
    Ur-Rehman, Obaid
    Zivic, Natasa
    [J]. UKSIM-AMSS NINTH IEEE EUROPEAN MODELLING SYMPOSIUM ON COMPUTER MODELLING AND SIMULATION (EMS 2015), 2015, : 278 - 283
  • [8] Analysis of Systems Security Engineering Design Principles for the Development of Secure and Resilient Systems
    Beach, Paul M.
    Mailloux, Logan O.
    Langhals, Brent T.
    Mills, Robert F.
    [J]. IEEE ACCESS, 2019, 7 : 101741 - 101757
  • [9] SoSPa: A System of Security Design Patterns for Systematically Engineering Secure Systems
    Nguyen, Phu H.
    Yskout, Koen
    Heyman, Thomas
    Klein, Jacques
    Scandariato, Riccardo
    Le Traon, Yves
    [J]. 2015 ACM/IEEE 18TH INTERNATIONAL CONFERENCE ON MODEL DRIVEN ENGINEERING LANGUAGES AND SYSTEMS (MODELS), 2015, : 246 - 255
  • [10] Novel operating band design schemes for high-contrast passive terahertz security screening systems
    Zhang Yongfeng
    Zhang Shufang
    Sun Xiaoling
    [J]. JOURNAL OF MODERN OPTICS, 2021, 68 (11) : 579 - 586