General Purpose Operating System for Security-critical Applications

نویسنده

  • Jaroslav Janáček
چکیده

Computers are used by the general public for an increasing number of tasks where security is an important aspect. Most of the computers are used to execute potentially malicious applications, often without the user’s knowledge, alongside applications that process sensitive data. The common security functions of the current common operating systems do not provide sufficient protection of the confidentiality and the integrity of the sensitive data processed by one application against other applications running on behalf of the same user. We show that the operating system has an important role in security – it is often impossible to effectively deal with security at the application layer without a suitable support of the operating system. We analyze several typical examples of applications used in home and office environments and generalize the security requirements and the security properties of the data used by the applications. We design a security model including a formally defined information flow policy to protect the confidentiality and the integrity of the data. We state and prove basic security properties of the model. We analyze several existing protection profiles for operating systems, and we argue that none of them is suitable for an operating system with the intended use. We present a new protection profile that supports our new security model. Finally, we show that it is feasible to modify Linux operating system to make it compliant with the presented protection profile. ∗Recommended by thesis supervisor: Assoc. Prof. Daniel Olejár Defended at Faculty of Mathematics, Physics and Informatics, Comenius University in Bratislava on November 22, 2010. c ⃝ Copyright 2010. All rights reserved. Permission to make digital or hard copies of part or all of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies show this notice on the first page or initial screen of a display along with the full citation. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, to republish, to post on servers, to redistribute to lists, or to use any component of this work in other works requires prior specific permission and/or a fee. Permissions may be requested from STU Press, Vazovova 5, 811 07 Bratislava, Slovakia. Janáček, J. General Purpose Operating System for Security-critical Applications. Information Sciences and Technologies Bulletin of the ACM Slovakia, Vol. 2, No. 2 (2010) 49-59

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

ریسک سنج: ابزاری برای سنجش دقیق میزان ریسک امنیتی برنامه‌ها در دستگاه‌های همراه

Nowadays smartphones and tablets are widely used due to their various capabilities and features for end users. In these devices, accessing a wide range of services and sensitive information including private personal data, contact list, geolocation, sending and receiving messages, accessing social networks and etc. are provided via numerous application programs. These types of accessibilities, ...

متن کامل

The VFiasco approach for a verified operating system

The quality of today’s main-stream operating systems is not sufficient for safety-critical and security-critical applications. In this paper we discuss several possible approaches to build an operating system that is safer and more secure. We especially focus on the approach taken in the VFiasco project on the verification of the Fiasco microkernel operating system. In this project, we use the ...

متن کامل

Taming Subsystems

The embedded and mobile computing market with its wide range of innovations is expected to remain growing in the foreseeable future. Recent developments in the embedded computing technology offer more performance thereby facilitating applications of unprecedented utility. Open systems, such as Linux, provide access to a huge software base. Nevertheless, these systems have to coexist with critic...

متن کامل

Estimating the Future of Electronic Health Information System in Society

Background: The health information system provides an integrated platform and an information connection between the actors of the health system regardless of temporal and spatial limitations. Objective This study aims to investigate the factors affecting the development of electronic health record (EHR) system and predict the future of this system in Iran. Methods: In this descriptive study, ...

متن کامل

On Object Orientation as a Paradigm for General PurposeDistributed Operating

In the Amadeus project we have been considering the construction of a general purpose distributed support environment for object oriented programming. In this paper we tackle a number of key areas whose interaction must be addressed in the design of such a general purpose object support system: 1) integration of support for (object oriented) database systems; 2) integration of security mechanis...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2011