Current Approaches to Policy based Security

A. L. Gottlieb · 2003

The effort to combat the effects of malicious software on unwary users is ongoing. Of the many approaches being studied today, the work being done in application oriented Security Policies is gaining wide recognition and is the focus of this report. Specifically, we shall look at two models. First, “Naccio”, conceived by Evans at MIT. Here, we have a system that will change programs to force them into compliance with established security policies. Second, we will examine “Enforceable Security Policies”, introduced by Schneider at Cornell University. In this model, applications are literally escorted thru their executions. Along the way, actions to be taken by the application are compared to established policy and if a violation is anticipated, the execution is brought to a halt. “Naccio” Naccio detects anomalies in source code then produces a new copy of the source code that is free of any anomalies and presumed safe for execution. Here, an anomaly is detected when the source code is in violation of a safety policy. Safety policies are constraints on system resources (e.g. number of open files per process). Upon detection of such an anomaly, Naccio will replace any offending system calls within the source code with calls to a Policy-Enforcing Library, I.E. a substitute library of system calls for

Read the paper · More papers on PaperTik