首页 | 本学科首页   官方微博 | 高级检索  
   检索      

基于用户意愿的文件访问控制策略
引用本文:何鸿君,罗莉,曹四化,宁京宣,李朋,董黎明.基于用户意愿的文件访问控制策略[J].国防科技大学学报,2007,29(6):54-58,80.
作者姓名:何鸿君  罗莉  曹四化  宁京宣  李朋  董黎明
作者单位:国防科技大学,计算机学院,湖南,长沙,410073
摘    要:访问控制是保护计算机上文件安全的重要技术手段。针对文件攻击,提出一种量化的评估方法,对主流访问控制策略进行了量化评估,指出主流访问控制策略的脆弱性在于赋予了程序访问用户能够访问的文件集合的权利。提出一种基于用户意愿的访问控制策略,其风险远远小于主流访问控制策略,能够防御未知文件攻击,证明了策略的安全性质,并讨论了其实现方案。

关 键 词:访问控制  用户意愿  文件攻击  恶意程序
文章编号:1001-2486(2007)06-0054-05
收稿时间:2007/6/13 0:00:00
修稿时间:2007年6月13日

A File Access Control Policy Based on User's Intention
HE Hongjun,LUO Li,CAO Sihu,NING Jingxuan,LI Peng and DONG Liming.A File Access Control Policy Based on User's Intention[J].Journal of National University of Defense Technology,2007,29(6):54-58,80.
Authors:HE Hongjun  LUO Li  CAO Sihu  NING Jingxuan  LI Peng and DONG Liming
Institution:College of Computer, National Univ. of Defense Technology, Changsha 410073, China;College of Computer, National Univ. of Defense Technology, Changsha 410073, China;College of Computer, National Univ. of Defense Technology, Changsha 410073, China;College of Computer, National Univ. of Defense Technology, Changsha 410073, China;College of Computer, National Univ. of Defense Technology, Changsha 410073, China;College of Computer, National Univ. of Defense Technology, Changsha 410073, China
Abstract:Access control is an important technique to protect computer files.Aiming at malwares that attack files,the paper proposes a quantified estimation method,and points out that the fragibility of prevalent access control policies lies in authorizing programs to access files what the user can access.The paper novelly proposes an access control policy based-on user's intention,which is able to defend unknown file attacks,and has extraordinarily less risk than prevalent access control policies.Furthermore,the paper proves security properties of the policy presented,and its application is discussed.
Keywords:access control  user's intention  file attack  malware
本文献已被 CNKI 万方数据 等数据库收录!
点击此处可从《国防科技大学学报》浏览原始摘要信息
点击此处可从《国防科技大学学报》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号