论文部分内容阅读
UNIX 访问控制机制是为具有两种类型用户(有管理特权和没有管理特权)的环境所设计的。在这一框架下面,所有的努力都是要提供一个开放的操作系统,允许使用者轻易地共享文件,在通信过程中关闭进程。在 UNIX 的安全机制下,从安全模式与低开销两者之中选取其一是困难的甚至是不可能的。一种考虑是希望代表一些(不是所有的)独立的管理性能或减少对其他部分的依赖,同时利用系统进程交互过程实施强制策略。在当前 FreeBSD 安全环境中
UNIX access control mechanisms are designed for environments that have two types of users, with and without administrative privileges. Under this framework, all efforts are intended to provide an open operating system that allows users to easily share files and shut down processes during communications. Under the UNIX security mechanism, it is difficult or even impossible to choose one of the two security modes and low overhead. One consideration is to represent some (not all) of the independent management capabilities or to reduce reliance on other components while enforcing coercive tactics using the process of system processes interaction. In the current FreeBSD security environment