Language - Based Security Scribe :
نویسنده
چکیده
Access-control lists (ACLs) are a traditional way to enforce permissions for access control. A trusted entity (e.g., operating system) knows which principals (e.g., users, programs) have access to which resources (e.g., files). One problem with ACLs is that they do not keep track of why each principal was granted a certain set of permissions. This allows a malicious entity to misuse permissions, i.e., use permissions for purposes other than those for which they were intended. For example, consider the following scenario. The owner of a server o↵ers the server as a computation resource to many users. The system has a compiler installed, and the owner of the system wants to bill users according to how much they are using the compiler. To this end, the compiler appends an entry to a log file, /var/billing.log, every time a user compiles a file. At the end of every month, the owner of the system bills users according to the entries in /var/billing.log. To protect against malicious users, the system owner does not give users direct access to /var/billing.log. Instead, the system owner gives the compiler program, cc, permission to open and write to /var/billing.log. The idea is that users can only open the file /var/billing.log through the compiler—which is trusted to only modify the file in a correct way. To make this concrete, when the user executes the command
منابع مشابه
The role of Baghdad scribe women in developing Islamic sciences and culture in the fourth era of the Abbasid Caliphate (448-656 AH)
Scribe women in the Abbasid era were active in various political, social, and cultural fields. Analyzing Iraq scribe women, specifically Baghdad, in the fourth era of the Abbasid caliphate (448-656 AH), the present study seeks to answer the question of what was their roles in cultural changes and the development of Islamic sciences and culture. This study has used a historical research method b...
متن کاملQuantitative performance of E-Scribe warehouse in detecting quality issues with digital annotated ECG data from healthy subjects.
The US Food and Drug Administration recommends submission of digital electrocardiograms in the standard HL7 XML format into the electrocardiogram warehouse to support preapproval review of new drug applications. The Food and Drug Administration scrutinizes electrocardiogram quality by viewing the annotated waveforms and scoring electrocardiogram quality by the warehouse algorithms. Part of the ...
متن کاملSCRIBE: A large-scale and decentralized publish-subscribe infrastructure
This paper presents Scribe, a large-scale event notification infrastructure for topic-based publishsubscribe applications. Scribe supports large numbers of topics, with a potentially large number of subscribers per topic. Scribe is built on top of Pastry, a generic peer-to-peer object location and routing substrate overlayed on the Internet, and leverages Pastry’s reliability, self-organization...
متن کاملScribe: a large-scale and decentralized application-level multicast infrastructure
This paper presents Scribe, a scalable application-level multicast infrastructure. Scribe supports large numbers of groups, with a potentially large number of members per group. Scribe is built on top of Pastry, a generic peer-topeer object location and routing substrate overlayed on the Internet, and leverages Pastry’s reliability, self-organization, and locality properties. Pastry is used to ...
متن کاملPropositional Proof Complexity An Introduction
1 Preface and Acknowledgements This article is an abridged and revised version of a 1996 McGill University technical report [14]. The technical report was based on lectures delivered by the author at a workshop in Holetown, Barbados and on the authors prepared overhead transparencies. The audience at this workshop wrote scribe notes which then formed the technical report [14]. The material sele...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2017