Skip to main content
Back to USENIX
  • Conferences
  • Students
Sign in

USENIX Conference Policies

  • Event Code of Conduct
  • Conference Network Policy
  • Statement on Environmental Responsibility Policy

Confining Root Programs with Domain and Type Enforcement

Kenneth M. Walker, Daniel F. Sterne, M. Lee Badger, Michael J. Petkac, David L. Sherman, Karen A. Oostendorp, Trusted Information Systems, Inc.

The pervasive use of the root privilege is a central problem for UNIX security because an attacker who subverts a singel root program gains complete control over a computing system. Domain and type enforcement (DTE) is a strong, configurable operating system access control technology that can minimize the damage root programs can cause if subverted. DTE does this by preventing groups of root programs from accessing critical files in inappropriate access modes. This paper illustrates how a DTE-enhanced UNIX prototype, driven by simple, machine-interpretable DTE policies, can provide strong protection against specific classes of attacks by malicious programs that gain root privilege. We present a sequence of policy componenets that protest system binaries against Rootkit, a widely-used hacker toolkit, and protect password, system log, user, and device special files against other root-based attacks. Tradeoffs among DTE policy complexity, scope of protection, and other factors are discussed.

Kenneth M. Walker, Trusted Information Systems, Inc.

Daniel F. Sterne, Trusted Information Systems, Inc.

M. Lee Badger, Trusted Information Systems, Inc.

Michael J. Petkac, Trusted Information Systems, Inc.

David L. Sherman, Trusted Information Systems, Inc.

Karen A. Oostendorp, Trusted Information Systems, Inc.

BibTeX
@inproceedings {260630,
author = {Kenneth M. Walker and Daniel F. Sterne and M. Lee Badger and Michael J. Petkac and David L. Sherman and Karen A. Oostendorp},
title = {Confining Root Programs with Domain and Type Enforcement},
booktitle = {6th USENIX Security Symposium (USENIX Security 96)},
year = {1996},
address = {San Jose, CA},
url = {https://www.usenix.org/conference/6th-usenix-security-symposium/confining-root-programs-domain-and-type-enforcement},
publisher = {USENIX Association},
month = jul
}
Download

Links

Paper: 
http://usenix.org/publications/library/proceedings/sec96/full_papers/walker/walker.ps
  • Log in or register to post comments

© USENIX
EIN 13-3055038

  • Privacy Policy
  • Contact Us