arrow
Return

Efficiently Supporting Attribute-Based Access Control in Linux

delete2024-07-01
delete0
PRE
AI
H
H.O. Sai Varshith
S
Shamik Sural *
J
Jaideep Vaidya
V
Vijayalakshmi Atluri
DOI:10.1109/TDSC.2023.3299429delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Linux is a widely used multi-user operating system with applications ranging from personal desktop to commercial heavy duty web servers. It has built-in security features based on discretionary access control enforced in the form of access control lists, which can be enhanced using the Linux Security Module (LSM) Framework. LSM allows inserting security verification hooks for supporting custom security policies. However, there is no support yet for Attribute-Based Access Control (ABAC) - an access control model gaining popularity due to its dynamic nature and flexibility. In ABAC, access is granted or denied based on attributes of the subject, object and environment. In this work, we propose a method for enhancing Linux's security features by integrating ABAC for file system objects using the LSM framework. We look at various kernel and user space components and how they can be made to work together to enforce ABAC policies. Different algorithms and data structures for efficient access request resolution are also investigated. Finally, we carry out extensive performance evaluation of the ABAC-enabled Linux system and discuss its results.
Keywords:
Linux
Access control
Kernel
File systems
Data structures
Authentication
Sockets
ABAC
linux security module
file system security
access resolution

Journal

IEEE Transactions on Dependable and Secure Computing cover
IEEE Transactions on Dependable and Secure Computing
IF:
7.5
Papers:
2.4K
Citations:
9.6K

Organization

I
indian institute of technology system (iit system)
Scholars:
9.5W
Papers: 9.9W
Citations: 93
I
indian institute of technology (iit) - kharagpur
Scholars:
6.2K
Papers: 6.5K
Citations: 6