该文分析了基于自主访问控制机制的远程容灾系统存在的安全性问题。设计了一套基于SELinux的安全策略,采用强制类型访问控制,实现了最小权限和权责分离的安全原则,增强了远程容灾系统数据的安全性,并解决了容灾系统服务使用的合法性问题。
Disaster tolerate system basing on discretion access control system have some security problems.Designing a suit of SELinux-based security policy,using mandatory access control,the security rules of least-privileges and separation of powers and responsibilities come true, enhanced the security of the backup data,meantime,the legality problem of using the service of disaster tolerate system can be solved.