正在加载图片...
Principle 5:Compartmentalization Break the system up into as many isolated units as possible -Simplicity -Containing attacker in case of failure Example:submarines are built with many chambers,each separately sealed Example:prison. Counterexample:Famous violations of this principle exist standard UNIX privilege model -A program with root privilege can do everything(including erase logs) A few operating systems,such as Trusted Solaris,do compartmentalize. Tradeoff with manageability. Counterexample:OS that crashes if an application crashes. -CSE825 13CSE825 13 Principle 5: Compartmentalization  Break the system up into as many isolated units as possible ─ Simplicity ─ Containing attacker in case of failure  Example: submarines are built with many chambers, each separately sealed  Example: prison.  Counterexample: Famous violations of this principle exist standard UNIX privilege model ─ A program with root privilege can do everything (including erase logs)  A few operating systems, such as Trusted Solaris, do compartmentalize.  Tradeoff with manageability.  Counterexample: OS that crashes if an application crashes
<<向上翻页向下翻页>>
©2008-现在 cucdc.com 高等教育资讯网 版权所有