Scinovex
article Open Access

Suspicious-taint-based access control for protecting OS from network attacks

Zhiyong Shan

Abstract

Today, security threats to operating systems largely come from network. Traditional discretionary access control mechanism alone can hardly defeat them. Although traditional mandatory access control models can effectively protect the security of OS, they have problems of being incompatible with application software and complex in administration. In this paper, we propose a new model, Suspicious-Taint-Based Access Control (STBAC) model, for defeating network attacks while being compatible, simple and maintaining good system performance. STBAC regards the processes using Non-Trustable-Communications as the starting points of suspicious taint, traces the activities of the suspiciously tainted processes by taint rules, and forbids the suspiciously tainted processes to illegally access vital resources by protection rules. Even in the cases when some privileged processes are subverted, STBAC can still protect vital resources from being compromised by the intruder. We implemented the model in the Linux kernel and evaluated it through experiments. The evaluation showed that STBAC could protect vital resources effectively without significant impact on compatibility and performance.

Security and Verification in ComputingAccess Control and TrustAdvanced Malware Detection TechniquesMandatory access controlComputer securityComputer scienceAccess controlDiscretionary access controlControl (management)Internet privacyRole-based access control
Citations
8
FWCI
0.14
field-weighted impact
References
60
Percentile
51%
vs. same field & year
Citations per year
Cited by
Suspicious-taint-based access control for protecting OS from network attacks
International Journal of Engineering in Computer Science · 2021 · 8 citations
References
A lattice model of secure information flow
Communications of the ACM · 1976 · 1,890 citations
Suspicious-taint-based access control for protecting OS from network attacks
International Journal of Engineering in Computer Science · 2021 · 8 citations
Citation Network

How this paper connects to the literature. Drag to explore, click any node to open that paper.