首先分析Linux系统中两种主要安全机制的局限性.然后,给出SECIMOS的构建,简介了各个安全策略模型及其实现模块,并描述结合多个安全模块的方法.最后,给出了SECIMOS的性能参数和与其他安全项目之间的比较.
In this paper, we analyze the restrictions of two main security schemes in Linux system. Then SECIMOS architecture is outlined; security policy model and security modules are introduced respectively. The way to combine these modules in LSM is described. The performance of SECIMOS and the comparison with other security projects are discussed finally.