A Framework for Implementing Dynamically Modified Least Privilege Security Policy

SHEN Qing-ni,QING Si-han,HE Ye-ping,LI Li-ping
DOI: https://doi.org/10.3321/j.issn:0372-2112.2006.10.012
2006-01-01
Abstract:Least privilege mechanism can provide a reasonable degree of security assurance for secure operating systems.This paper described a framework for implementing dynamically modified least privilege security policy,which combined role's duty separation property and domain's function separation property.Under the control of its new capability mechanism based on a process's executable image,current role and current domain,it restricted the process to the minimum amount of privileges within these contexts.This paper illustrated its implementation in ANSHENG OS v4.0,a copyrighted secure operating system satisfying all the specified requirements of Criteria class 4,"Structured-Protection",in GB17859-1999(equally,the B2 level in TCSEC) in China.Thus it demonstrates that this framework can help enforcing dynamically least privilege control on a secure operating system,while still providing a flexible efficient system.
What problem does this paper attempt to address?