lecture_3_part_2

File system calls open execute directory traversal a

Info iconThis preview shows page 1. Sign up to view the full content.

View Full Document Right Arrow Icon
This is the end of the preview. Sign up to access the rest of the document.

Unformatted text preview: Efficiency Simplicity Flexibility CS 236 Online Lecture 3 Page 31 An Example Reference Monitor • The Linux code that mediates file access • Applied on relatively few of the file system calls – Open, execute, directory traversal, a few others – Not on read and write CS 236 Online Lecture 3 Page 32 Another Example Reference Monitor • A firewall • It examines every packet for certain characteristics • Typically, either any subject can do something or no subject can • But sometimes packets from particular source addresses can do more – Essentially, the source address identifies a privileged subject CS 236 Online Lecture 3 Page 33 Thinking More Broadly About Access Control • From one perspective, access control is the core of all computer security • All security is about who can access what • So where do security problems come from? – Not applying access control – Not applying access control properly CS 236 Online Lecture 3 Page 34 What Is the Most Common Access Control Mechanism? • T...
View Full Document

This document was uploaded on 11/01/2013.

Ask a homework question - tutors are online