According to trusted compeer seeffiity evaluation standard ( tgskt ) , tfae security level of ^ armostall dbms is c2 , and it is not eueuglrto safeguarded ^ it is necessary and pressing to afford a credible system to protect infomation resource 按照可信計(jì)算機(jī)評估標(biāo)準(zhǔn)tcsec看,當(dāng)前多數(shù)dbms系統(tǒng)只具備c2級安全性,這種安全性對數(shù)據(jù)的保護(hù)是不夠的。提供一個(gè)可靠的mlsdbms系統(tǒng)來保護(hù)系統(tǒng)信息資源是必要的,迫切的。
This thesis researchs the correlative security evaluation criteria and analyses in detail linux kernel at first . linux kernel is improved at four aspects : access control list , capability , system audit , mandatory access control , based on linux kernel 2 . 4 . 4 on tcsec and the security level of linux is enhanced from cl to bl 本論文首先研究了相關(guān)的安全評估標(biāo)準(zhǔn),并對linux內(nèi)核進(jìn)行了詳細(xì)地分析,然后以tcsec為標(biāo)準(zhǔn),基于linux內(nèi)核2 . 4 . 4 ,分別從訪問控制表、權(quán)能、系統(tǒng)審計(jì)以及強(qiáng)制訪問控制四個(gè)方面時(shí)linux內(nèi)核進(jìn)行了改進(jìn),使linux的安個(gè)級別從c1級提高到了b1級。
So the evaluation and certification on information security is a fundmental research area . since us dod developed tcsec in 1985 , the security community in the world has made great progress and at last developed cc ( common criteria ) which latter was publicized as international standard 國際社會中,自從1985年美國國防部發(fā)布了tcsec (可信計(jì)算機(jī)系統(tǒng)評估準(zhǔn)則)以來,歷經(jīng)十余年的發(fā)展,已經(jīng)制定了得到廣泛認(rèn)可的cc ( it安全通用評估準(zhǔn)則) ,并將其作為國際標(biāo)準(zhǔn)發(fā)布。
The conc9pts and approaches relating to information security among the course of development of the ia are introduced . for example , reference monitor ( are ) , reference validation mechanism ( rvm ) , trusted computing base ( tcb ) , security model , tcsec , cc , iatf fritsa , etc . chapter 2 analyzes the time and space property " of information security 第一章對信息保障的歷史進(jìn)行回顧,介紹在信息保障的發(fā)展歷程中有關(guān)信息安全的概念和方法,如:引用監(jiān)視器( rm ) 、引用確認(rèn)機(jī)制( rvn ) 、可信計(jì)算基( tcb ) 、安全模型、 tcsec 、 cc 、 iatf 、 fritsa等。
After intruducing the security demand from the computer area , this paper present the designing aim of the real time audit analysis system ( raas ) , considering the trusted computer system evaluation criteria ( tcsec ) of us dod and common criteria for it security evaluation ( cc ) 本文首先介紹了計(jì)算機(jī)領(lǐng)域的安全需求,根據(jù)美國國防部的可信計(jì)算機(jī)評測標(biāo)準(zhǔn)( tcsec )和計(jì)算機(jī)信息系統(tǒng)的通用安全評價(jià)準(zhǔn)則( commoncriteriaforitsecurityevaluation , cc )中提出的安全操作系統(tǒng)的審計(jì)標(biāo)準(zhǔn),提出本系統(tǒng)的設(shè)計(jì)目的。