Security on-demand architecture with multiple modules support

2Citations
Citations of this article
3Readers
Mendeley users who have this article in their library.
Get full text

Abstract

It's very important for a general-purpose operating system to have a security-tunable feature to meet different security requirements. This can be achieved by supporting diverse security modules, invoking them on demand. However, the security architectures of existing projects on Linux kernels do not support this feature or have some drawbacks in their supporting. Thus we introduce a layered architecture which consists of original kernel layer, module coordination layer and module decision layer. The architecture supports multiple modules register, resolves policy-conflicts of modules by changing their invoking order, and allow user to customize the security by enabling or disabling modules during runtime. The detailed structure and implementation in Linux based system, SECIMOS is described. The caching issue and performance are also discussed. Our practice showed the architecture helps us achieve flexible adaptation in different environments. © Springer-Verlag Berlin Heidelberg 2005.

Cite

CITATION STYLE

APA

Wu, Y., Shi, W., Liang, H., Shang, Q., Yuan, C., & Liang, B. (2005). Security on-demand architecture with multiple modules support. In Lecture Notes in Computer Science (Vol. 3439, pp. 121–131). Springer Verlag. https://doi.org/10.1007/978-3-540-31979-5_11

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free