Access control is an important technique to protect computer files. Aiming at malwares that attack files, the paper proposes a quantified estimation method, and points out that the fragibility of prevalent access control policies lies in authorizing programs to access files what the user can access. The paper novelly proposes an access control policy based-on user's intention, which is able to defend unknown file attacks, and has extraordinarily less risk than prevalent access control policies. Furthermore, the paper proves security properties of the policy presented, and its application is discussed.
参考文献
相似文献
引证文献
引用本文
何鸿君,罗莉,曹四化,等.基于用户意愿的文件访问控制策略[J].国防科技大学学报,2007,29(6):54-58,80. HE Hongjun, LUO Li, CAO Sihua, et al. A File Access Control Policy Based on User's Intention[J]. Journal of National University of Defense Technology,2007,29(6):54-58,80.