DESIGN AND IMPLEMENTATION OF SECURE LINUX KERNEL SECURITY FUNCTIONS
-
-
Abstract
The Common Criteria (CC) was adopted as the international standard for information security evaluation in July 1999. The newness of the CC and the lack of experiences in its application throw great challenge to the development of secure operating systems with conformance to the CC philosophy. Based on a research experiment, the design and implementation of kernel security functions for a secure Linux system named RS Linux are discussed with intention to capture some fundamental CC concepts. The clauses for a third level system of the China Classified Criteria for Security (CCCS) are taken into consideration in determining the security functions. The definition of the security functions is presented in the form of the CC security functional requirement components. The instantiation of the security functions is stated from the aspects of the security support architecture and the security models interpretation in a Linux system. An empirical means is given to estimate the negative impact of RS Linux security mechanisms on the system performance. Research shows that demands of the CCCS can be described completely with constructs provided in the CC. A direction of further research on secure operating systems is pointed out at the end of the paper.
-
-