总结了安全操作系统实现恶意代码防御的典型理论模型,分析了它们的基本思想、实现方法和不足之处,指出提高访问控制类模型的恶意代码全面防御能力和安全保证级别、从操作系统安全体系结构的高度构建宏病毒防御机制以及应用可信计算技术建立操作系统的恶意代码免疫机制将是该领域的研究方向。
The state of the art research on malicious code defending in the area of secure operating system is summarized. The designs, implementations, and shortcomings of major security policies against malicious code are presented. Emerging trends of research in this area are outlined to be improving defending qualities and assurance level of access control type models, defending against macro viruses by enhancing the security architecture of secure operating system, and applying trusted computing technologies to build malicious code immune environment in secure operating system.