OS Security Flashcards
Define
Access Control
Selective restriction of access to resource according to policy
Define
Subject/Principal
OS Security
Entity accessing the resource
Define
Object
OS Security
Resource being accessed
Define
Policy
OS Security
Rules on how a subject can/can’t access an object
Define
Authorization
OS Security
Who/what should perform
Define
Authentication
OS Security
Identifying who is requesting to access a resource
Define
Audit
OS Security
Log of all actions from a principal
List the 5 A’s of OS Security
Authorization, Authentication, Audit, Accountability, Access
Describe
Access Control Matrix
OS Security
Manages policies where the rows are the subject(s) and the columns are the object(s), making the cells the permission granted (T/F)
Describe
Permissions
OS Security
Finer-grained access enforced by Access Control List (ACL) and Capability-Based Security (CBS)
Describe
Access Control List (ACL)
OS Security
Each object’s ACL is defined per subject (object-centric mechanism)
Provide an analogy for an Access Control List (ACL)
OS Security
Guest/VIP list
Describe
Capability-Based Security
OS Security
Each subject has a token to access an object (subject-centric mechanism)
Provide an analogy for Capability-Based Security (CBS)
OS Security
Key
What is a Trusted Computer Base?
OS Security
A reference monitor