APPLICATION OF A MULTI-LEVEL ACCESS SCHEME FOR PROTECTING CONFIDENTIAL DATA
V. A., Okorokov, D. E. Laschuk · Journal of the Ural Federal district Information security · 2021
Preventing leaks of confidential information stored and processed by computer systems is one of the most important problems that one has to face when processing data with limited access, in particular personal data.By now, there are many examples when confidential data is stolen by intruders and used by them for criminal purposes or becomes available to a wide range of Internet users.This circumstance shows the need to develop reliable mechanisms that ensure the delimitation of access to data, which makes it possible to minimize the damage arising from the compromise of confidential information.The basic mechanisms that provide access control are usually built into the operating system (OS) kernel and require significant effort to implement and configure within a specific OS instance.The article discusses one of the main methods of access control, which are used in protected operating systems, namely the multilevel access method.The implementation of the method requires a fairly large effort of developers and is often associated with the need to modify the existing application software.The relevance of this topic for the study of the course "Security of operating systems" by students enrolled in areas related to ensuring information security and information protection in computing systems is noted.Within the framework of the article various approaches to the implementation of multilevel access are considered and the basic problems of its implementation are noted [1].The influence of restrictions for subjects with different levels of access is also considered, based on the use of additional security criteria for each subject and modification of methods for transforming allowed information flows in the system.