Download Full eXpert-BSM v.1.5 User Manual

Transcript
}
...
}
The policy involves a series of relations defined between user and file groups. For each
user group entered in the policy, three possible relations can be specified: nread,
nwrite, and nexec. nread indicates that users in the associated list are not allowed
to read files matching the file lists specified in the bracket clause. Illegal file writes and
executions are specified similarly. It is not necessary for every relation to be specified in
the user list, and file lists may be empty, indicating no defined restrictions.
The following is an example EMERALD access policy specification:
UserGroups { RegStaff
Management
Accnt
}
FileGroups { Programs (
(em_user1 em_user2)
(em_admin )
(em_acct)
/bin /usr/bin
/usr/local/bin
/usr/local/ftp/bin )
Admtools ( /etc/bin /etc/sbin
/usr/sbin /sbin )
CompanySecrets ( /secret )
Payroll ( /accounting/DBMS/payroll.db )
}
Policy {
RegStaff (
nread[CompanySecrets Payroll]
nwrite[CompanySecrets Programs Payroll
Admtools]
nexec[Admtools] )
Management(
nread[]
nwrite[Programs Admtools]
nexec[] )
Accnt (
nwrite[Programs Admtools]
nread[CompanySecrets]
nexec[Admtools] )
}
In the above example, which illustrates a valid access policy specification, there exists a
small group of regular staff defined as em_user1 and em_user2. There is a management staff, with one manager em_admin and an accounting group consisting of user
em_acct. Four file groups are defined. The first is the programs group, where programs are defined as being located in /bin, /usr/bin/, /usr/local/bin/,
EMERALD eXpert-BSM User’s Guide
Page 41