论文部分内容阅读
针对基于状态控制的系统安全相关研究欠缺的问题,首先从访问控制的缺陷、状态控制的优势等方面讨论了研究的必要性和可行性;其次,通过引入粗粒度文件、程序及具动态特征的函数等状态,扩展了安全状态的定义;最后从信息流控制和状态对象控制的角度,提出状态取值空间、开放空间和操作空间的概念,并以此为出发点提出了状态的转换、操作、控制及检测等特征的分析方法.在此基础上,从以状态控制为目标和手段两个角度给出了其在系统安全增强及安全检测方面的应用思路.
In order to solve the problem of system security related research based on state control, the necessity and feasibility of the research are discussed from the defects of access control and the advantages of state control. Secondly, by introducing coarse-grained files, programs and dynamic features Function and other states to extend the definition of the security state. Finally, from the perspective of information flow control and state object control, the concepts of state value space, open space and operating space are proposed. Based on this, the state transition, operation, Control and detection, etc. Based on this, the application of this method in system security enhancement and safety detection is given from the perspective of state control.