本文要介绍了国家秘密全生命周期保护过程中应用到的标记标识、物理隔离、密码保护、身份鉴别、访问控制、安全审计及数据销毁等7项技术措施,并指出只有综合运用全面的技术和管理措施,才能构建出"进不来、出不去,找不到、看不懂,拿不走、逃不脱"的安全保密防护体系.
As secure infrastructural software, secure operating systems are well known for its protection against kinds of threats and attacks. In this paper, we report the work of building EARTH operating system towards to "structurized protection" level of national security standards. EARTH has a flexible architecture supporting dynamic multiple policies, effective mandatory access control mechanism. We give formal system specification and proof of the security models and provide covert channel analysis and mitigation methods. Our experiments show that EARTH has good system performance. Furthermore, the research and development experiences and lessons learned in EARTH project is discussed.
<正>2010年,"震网"成为安全圈里一个耳熟能详的名词,至今人们依然在认真地对其进行分析,我们也不例外。通过结合各方面的资料并作进一步技术分析,我们得到以下结论:"震网"病毒攻击事件具有国家行为和规模网络战的性质;物理隔离的信息系统若不注重安全,也存在被攻击的隐患。
Malwares and their resulting threats are growing urgently. A method at the file system level is provided for analysis and defense against malwares with reducing the loss as possible, and implements a file system for malware analysis and protection (MAPFS). With check-point and file versioning technology, MAPFS can record the modifications in file systems during the process. These records are important for analysis of malware behavior, and may be used to recover the files damaged by the malwares. Experiments show that this method is effective in analysis and defense of malwares, and MAPFS only brings a little loss lower than 10 percent.
本文结合BLP、Biba安全保密模型,对我国目前现有的安全隔离与信息交换技术产品,就其安全保密性问题进行了理论分析研究.