Skip to main navigation Skip to search Skip to main content

Comprehensive integrity protection for desktop Linux

  • Stony Brook University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Information flow provides principled defenses against malware. It can provide system-wide integrity protection without requiring any program-specific understanding. Information flow policies have been around for 40+ years but they have not been explored in today's context. Specifically, they are not designed for contemporary software and OSes. Applying these policies directly on today's OSes affects usability. In this paper, we focus our attention on an information-flow based integrity protection system that we implemented for Linux, with the goal of minimizing usability impact. We discuss the design decisions made in this system and provide insights on building usable information flow systems.

Original languageEnglish
Title of host publicationSACMAT 2014 - Proceedings of the 19th ACM Symposium on Access Control Models and Technologies
PublisherAssociation for Computing Machinery
Pages89-92
Number of pages4
ISBN (Print)9781450329392, 9781450329392
DOIs
StatePublished - 2014
Event19th ACM Symposium on Access Control Models and Technologies, SACMAT 2014 - London, ON, Canada
Duration: Jun 25 2014Jun 27 2014

Publication series

NameProceedings of ACM Symposium on Access Control Models and Technologies, SACMAT

Conference

Conference19th ACM Symposium on Access Control Models and Technologies, SACMAT 2014
Country/TerritoryCanada
CityLondon, ON
Period06/25/1406/27/14

Fingerprint

Dive into the research topics of 'Comprehensive integrity protection for desktop Linux'. Together they form a unique fingerprint.

Cite this