Flume, which implements decentralized information flow control (DIFC), allows a high security level process to "pre-create" secret files in a low security level directory. However, the pre-create mechanism makes s...Flume, which implements decentralized information flow control (DIFC), allows a high security level process to "pre-create" secret files in a low security level directory. However, the pre-create mechanism makes some normal system calls unavailable, and moreover, it needs priori knowledge to create a large quantity of objects, which is difficult to estimate in practical operating systems. In this paper, we present an extended Flume file access control mechanism, named Effect, to substitute the mechanism of pre-create, which permits write operations (create, delete, and rename a file) on directories and creates a file access virtual layer that allocates operational views for each process with noninterference properties. In the end, we further present an analysis on the security of Effect. Our work makes it easier for multi-user to share confidential information in decentralized information flow control systems.展开更多
The Paper emphasizes relativity between Web usage mining and the application of Web site structure and content. It has shown that the amount of effort revolved in processing and quantifying the structure and content o...The Paper emphasizes relativity between Web usage mining and the application of Web site structure and content. It has shown that the amount of effort revolved in processing and quantifying the structure and content of a Web site is well worth in performing Web usage mining. The necessity of combining Web site structure and content with Web usage mining process is further proved.展开更多
基金Supported by the National Natural Science Foundation of China(61003268,61103220,91118003,61173138,61170022)Hubei Provincial Natural Science Foundation(2010CDB08601)The Fundamental ResearchFunds for the Central Universities (3101038,274629)
文摘Flume, which implements decentralized information flow control (DIFC), allows a high security level process to "pre-create" secret files in a low security level directory. However, the pre-create mechanism makes some normal system calls unavailable, and moreover, it needs priori knowledge to create a large quantity of objects, which is difficult to estimate in practical operating systems. In this paper, we present an extended Flume file access control mechanism, named Effect, to substitute the mechanism of pre-create, which permits write operations (create, delete, and rename a file) on directories and creates a file access virtual layer that allocates operational views for each process with noninterference properties. In the end, we further present an analysis on the security of Effect. Our work makes it easier for multi-user to share confidential information in decentralized information flow control systems.
文摘The Paper emphasizes relativity between Web usage mining and the application of Web site structure and content. It has shown that the amount of effort revolved in processing and quantifying the structure and content of a Web site is well worth in performing Web usage mining. The necessity of combining Web site structure and content with Web usage mining process is further proved.