{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,1]],"date-time":"2025-03-01T05:34:12Z","timestamp":1740807252403,"version":"3.38.0"},"publisher-location":"Berlin, Heidelberg","reference-count":34,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642176968"},{"type":"electronic","value":"9783642176975"}],"license":[{"start":{"date-parts":[[2010,1,1]],"date-time":"2010-01-01T00:00:00Z","timestamp":1262304000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2010]]},"DOI":"10.1007\/978-3-642-17697-5_7","type":"book-chapter","created":{"date-parts":[[2010,12,7]],"date-time":"2010-12-07T07:22:58Z","timestamp":1291706578000},"page":"131-161","source":"Crossref","is-referenced-by-count":3,"title":["From a Generic Framework for Expressing Integrity Properties to a Dynamic mac Enforcement for Operating Systems"],"prefix":"10.1007","author":[{"given":"Patrice","family":"Clemente","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jonathan","family":"Rouzaud-Cornabas","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christian","family":"Toinard","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"7_CR1","unstructured":"Committee on National Security Systems. National Information Assurance Glossary, CNSS Instruction No. 4009, 23 (April 2010)"},{"key":"7_CR2","unstructured":"Biba, K.J.: Integrity considerations for secure computer systems, tech. rep., MITRE Corp., 04 (1977)"},{"key":"7_CR3","unstructured":"Bell, D., LaPadula, L.: Secure computer systems: Mathematical foundations, tech. rep., Technical Report MTR-2547 (1973)"},{"key":"7_CR4","doi-asserted-by":"crossref","unstructured":"Lee, T.: Using mandatory integrity to enforce \u2018commercial\u2019 security. In: Proceedings of IEEE Symposium on Security and Privacy, pp. 140\u2013146 (April 1988)","DOI":"10.1109\/SECPRI.1988.8106"},{"key":"7_CR5","doi-asserted-by":"crossref","unstructured":"Ko, C., Redmond, T.: Noninterference and intrusion detection. In: Proceedings of IEEE Symposium on Security and Privacy, pp. 177\u2013187 (2002)","DOI":"10.1109\/SECPRI.2002.1004370"},{"key":"7_CR6","doi-asserted-by":"crossref","first-page":"11","DOI":"10.1109\/SP.1982.10014","volume-title":"Proc. 1982 IEEE Symp. Security and Privacy","author":"J. Goguen","year":"1982","unstructured":"Goguen, J., Meseguer, J.: Security policies and security models. In: Proc. 1982 IEEE Symp. Security and Privacy, Oakland, CA, pp. 11\u201320. IEEE, Los Alamitos (1982)"},{"key":"7_CR7","unstructured":"Rahimi, N.A.: Trusted path execution for the linux 2.6 kernel as a linux security module. In: ATEC 2004: Proceedings of the Annual Conference on USENIX Annual Technical Conference, Berkeley, CA, USA, pp. 34\u201334. USENIX Association (2004)"},{"key":"7_CR8","first-page":"184","volume-title":"IEEE Symposium on Security and Privacy","author":"D.D. Clark","year":"1987","unstructured":"Clark, D.D., Wilson, D.R.: A Comparison of Commercial and Military Computer Security Policies. In: IEEE Symposium on Security and Privacy, pp. 184\u2013194. IEEE Computer Society Press, Los Alamitos (1987)"},{"issue":"1","key":"7_CR9","doi-asserted-by":"publisher","first-page":"30","DOI":"10.1145\/353323.353382","volume":"3","author":"F.B. Schneider","year":"2000","unstructured":"Schneider, F.B.: Enforceable security policies. ACM Trans. Inf. Syst. Secur.\u00a03(1), 30\u201350 (2000)","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"7_CR10","volume-title":"The Theory and Practice of Concurrency","author":"A.W. Roscoe","year":"1997","unstructured":"Roscoe, A.W., Hoare, C.A.R., Bird, R.: The Theory and Practice of Concurrency. Prentice Hall PTR, Upper Saddle River (1997)"},{"key":"7_CR11","doi-asserted-by":"crossref","unstructured":"Clarkson, M.R., Schneider, F.B.: Hyperproperties. In: IEEE 21st Computer Security Foundations Symposium, CSF 2008, pp. 51\u201365 (June 2008)","DOI":"10.1109\/CSF.2008.7"},{"key":"7_CR12","unstructured":"Bauer, L., Ligatti, J., Walker, D.: More Enforceable Security Policies. Foundations of Computer Security, 95 (2002)"},{"key":"7_CR13","doi-asserted-by":"crossref","unstructured":"Terry, P., Wiseman, S.: A \u2018new\u2019 security policy model. In: Proceedings of IEEE Symposium on Security and Privacy, pp. 215\u2013228 (May 1989)","DOI":"10.1109\/SECPRI.1989.36296"},{"key":"7_CR14","first-page":"325","volume":"2","author":"J. Briffaut","year":"2009","unstructured":"Briffaut, J., Lalande, J.-F., Toinard, C.: Formalization of security properties: enforcement for mac operating systems and verification of dynamic mac policies. International Journal on Advances in Security\u00a02, 325\u2013343 (2009)","journal-title":"International Journal on Advances in Security"},{"key":"7_CR15","unstructured":"Zeldovich, N., Boyd-Wickizer, S., Kohler, E., Mazi\u00e8res, D.: Making information flow explicit in histar. In: OSDI 2006: Proceedings of the 7th USENIX Symposium on Operating Systems Design and Implementation, Berkeley, CA, USA, pp. 19\u201319. USENIX Association (2006)"},{"issue":"6","key":"7_CR16","doi-asserted-by":"publisher","first-page":"321","DOI":"10.1145\/1323293.1294293","volume":"41","author":"M. Krohn","year":"2007","unstructured":"Krohn, M., Yip, A., Brodsky, M., Cliffer, N., Kaashoek, M.F., Kohler, E., Morris, R.: Information flow control for standard os abstractions. SIGOPS Oper. Syst. Rev.\u00a041(6), 321\u2013334 (2007)","journal-title":"SIGOPS Oper. Syst. Rev."},{"issue":"4","key":"7_CR17","doi-asserted-by":"publisher","first-page":"301","DOI":"10.1145\/1357010.1352624","volume":"42","author":"P. Efstathopoulos","year":"2008","unstructured":"Efstathopoulos, P., Kohler, E.: Manageable fine-grained information flow. SIGOPS Oper. Syst. Rev.\u00a042(4), 301\u2013313 (2008)","journal-title":"SIGOPS Oper. Syst. Rev."},{"key":"7_CR18","unstructured":"TRESYS., Setools\u2013policy analysis tools for selinux (2010)"},{"key":"7_CR19","first-page":"184","volume-title":"Workshop on Security and High Performance Computing Systems","author":"J. Briffaut","year":"2009","unstructured":"Briffaut, J., Rouzaud-Cornabas, J., Toinard, C., Zemali, Y.: A new approach to enforce the security properties of a clustered high-interaction honeypot. In: Guha, R.K., Spalazzi, L. (eds.) Workshop on Security and High Performance Computing Systems, Leipzig, Germany, June 2009, pp. 184\u2013192. IEEE Computer Society, Los Alamitos (2009)"},{"issue":"8","key":"7_CR20","doi-asserted-by":"publisher","first-page":"461","DOI":"10.1145\/360303.360333","volume":"19","author":"M.A. Harrison","year":"1976","unstructured":"Harrison, M.A., Ruzzo, W.L., Ullman, J.D.: Protection in operating systems. Commun. ACM\u00a019(8), 461\u2013471 (1976)","journal-title":"Commun. ACM"},{"key":"7_CR21","unstructured":"Spencer, R., Smalley, S., Loscocco, P., Hibler, M., Andersen, D., Lepreau, J.: The flask security architecture: system support for diverse security policies. In: SSYM 1999: Proceedings of the 8th Conference on USENIX Security Symposium, Berkeley, CA, USA, pp. 11\u201311. USENIX Association (1999)"},{"key":"7_CR22","doi-asserted-by":"publisher","first-page":"237","DOI":"10.1145\/1542207.1542244","volume-title":"SACMAT 2009: Proceedings of the 14th ACM Symposium on Access Control Models and Technologies","author":"Z. Mao","year":"2009","unstructured":"Mao, Z., Li, N., Chen, H., Jiang, X.: Trojan horse resistant discretionary access control. In: SACMAT 2009: Proceedings of the 14th ACM Symposium on Access Control Models and Technologies, New York, NY, USA, pp. 237\u2013246. ACM, New York (2009)"},{"key":"7_CR23","doi-asserted-by":"publisher","first-page":"435","DOI":"10.1109\/ICCNMC.2001.962629","volume-title":"ICCNMC 2001: Proceedings of the 2001 International Conference on Computer Networks and Mobile Computing (ICCNMC 2001)","author":"H. Liang","year":"2001","unstructured":"Liang, H., Sun, Y.: Enforcing mandatory integrity protection in operating system. In: ICCNMC 2001: Proceedings of the 2001 International Conference on Computer Networks and Mobile Computing (ICCNMC 2001), Washington, DC, USA, p. 435. IEEE Computer Society, Los Alamitos (2001)"},{"key":"7_CR24","doi-asserted-by":"crossref","unstructured":"Li, N., Mao, Z., Chen, H.: Usable mandatory integrity protection for operating systems. In: IEEE Symposium on Security and Privacy, SP 2007, pp. 164\u2013178 (May 2007)","DOI":"10.1109\/SP.2007.37"},{"key":"7_CR25","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1109\/JSAC.2002.806121","volume":"21","author":"A. Sabelfeld","year":"2003","unstructured":"Sabelfeld, A., Myers, A.: Language-based information-flow security. IEEE Journal on Selected Areas in Communications\u00a021, 5\u201319 (2003)","journal-title":"IEEE Journal on Selected Areas in Communications"},{"key":"7_CR26","doi-asserted-by":"crossref","unstructured":"Mohay, G., Zellers, J.: Kernel and shell based applications integrity assurance. In: Proceedings of 13th Annual Computer Security Applications Conference, pp. 34\u201343 (December 1997)","DOI":"10.1109\/CSAC.1997.646171"},{"key":"7_CR27","doi-asserted-by":"crossref","unstructured":"Iglio, P.: Trustedbox: a kernel-level integrity checker. In: 15th Annual Proceedings of Computer Security Applications Conference (ACSAC 1999), pp. 189\u2013198 (1999)","DOI":"10.1109\/CSAC.1999.816027"},{"key":"7_CR28","unstructured":"Sailer, R., Zhang, X., Jaeger, T., van Doorn, L.: Design and implementation of a tcg-based integrity measurement architecture. In: SSYM 2004: Proceedings of the 13th Conference on USENIX Security Symposium, Berkeley, CA, USA, pp. 16\u201316. USENIX Association (2004)"},{"key":"7_CR29","doi-asserted-by":"publisher","first-page":"90","DOI":"10.1109\/ICNS.2006.13","volume-title":"ICNS 2006: Proceedings of the International Conference on Networking and Services","author":"N.A. Quynh","year":"2006","unstructured":"Quynh, N.A., Takefuji, Y.: A real-time integrity monitor for xen virtual machine. In: ICNS 2006: Proceedings of the International Conference on Networking and Services, Washington, DC, USA, p. 90. IEEE Computer Society, Los Alamitos (2006)"},{"key":"7_CR30","unstructured":"Berger, S., C\u00e1ceres, R., Goldman, K.A., Perez, R., Sailer, R., van Doorn, L.: virtualizing the trusted platform module. In: USENIX-SS 2006: Proceedings of the 15th Conference on USENIX Security Symposium, Berkeley, CA, USA, USENIX Association (2006)"},{"key":"7_CR31","first-page":"80","volume-title":"Proceedings of the 12th ACM Symposium on Access Control Models and Technologies","author":"M. Xu","year":"2007","unstructured":"Xu, M., Jiang, X., Sandhu, R., Zhang, X.: Towards a VMM-based usage control framework for OS kernel integrity protection. In: Proceedings of the 12th ACM Symposium on Access Control Models and Technologies, p. 80. ACM, New York (2007)"},{"key":"7_CR32","doi-asserted-by":"crossref","unstructured":"Rouzaud Cornabas, J., Clemente, P., Toinard, C.: An Information Flow Approach for Preventing Race Conditions: Dynamic Protection of the Linux OS (best paper award). In: Fourth International Conference on Emerging Security Information, Systems and Technologies SECURWARE 2010, Venise Italy (July 2010)","DOI":"10.1109\/SECURWARE.2010.10"},{"key":"7_CR33","doi-asserted-by":"crossref","unstructured":"Uppuluri, P., Joshi, U., Ray, A.: Preventing race condition attacks on file-systems. In: SAC 2005: Proceedings of the 2005 ACM Symposium on Applied Computing, pp.\u00a0346\u2013353. ACM, New York (2005)","DOI":"10.1145\/1066677.1066758"},{"key":"7_CR34","unstructured":"McVoy, L., Staelin, C.: lmbench: portable tools for performance analysis. In: ATEC 1996: Proceedings of the 1996 Annual Conference on USENIX Annual Technical Conference, Berkeley, CA, USA, pp. 23\u201323. USENIX Association (1996)"}],"container-title":["Lecture Notes in Computer Science","Transactions on Computational Science XI"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-17697-5_7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,2,28]],"date-time":"2025-02-28T14:07:49Z","timestamp":1740751669000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-17697-5_7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2010]]},"ISBN":["9783642176968","9783642176975"],"references-count":34,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-17697-5_7","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2010]]}}}