The flask security architecture: system support for diverse security policies

Update Item Information
Publication Type technical report
School or College College of Engineering
Department Computing, School of
Creator Hibler, Michael J.
Other Author Spencer, Ray; Smalley, Stephen; Loscocco, Peter; Andersen, David, Lepreau, Jay
Title The flask security architecture: system support for diverse security policies
Date 1998
Description Operating systems must be flexible in their support for security policies, i.e., the operating system must provide sufficient mechanisms for supporting the wide variety of real-world security policies. Systems claiming to provide this support have failed to do so in two ways: they either fail to provide sufficient control over the propagation of access rights, or they fail to provide enforcement mechanisms to support fine-grained control and dynamic security policies. In this paper we present an operating systems security architecture that solves both of these problems. The first problem is solved by ensuring that the security policy (through a consistent replica) is consulted for every security decision. The second problem is solved through mechanisms that are directly integrated into the service-providing components of the system. The architecture is described through its prototype implementation in the Flask microkernel-based OS, and the policy flexibility of the prototype is evaluated. We present initial evidence that the architecture's performance impact is modest. Moreover, our architecture is applicable to many other types of operating systems and environments.
Type Text
Publisher University of Utah
Subject Flask; Security architecture
Subject LCSH Computer security
Language eng
Bibliographic Citation Spencer, R., Smalley, S., Loscocco, P., Hibler, M. J., Andersen, D., & Lepreau, J. (1998). The flask security architecture: system support for diverse security policies. 1-15. UUCS-98-014.
Series University of Utah Computer Science Technical Report
Relation is Part of ARPANET
Rights Management ©University of Utah
Format Medium application/pdf
Format Extent 5,106,810 bytes
Identifier ir-main,15973
ARK ark:/87278/s6805m0b
Setname ir_uspace
ID 704836
Reference URL https://collections.lib.utah.edu/ark:/87278/s6805m0b
Back to Search Results