Operating Systems Level 12
PART 4 • SYSTEMS & CAREER

Permit the Required Action—and Nothing More

Separate authentication from authorization, model access rights, apply least privilege and trace how the kernel reference monitor protects system objects.

Level 12 of 15 Intermediate 100–125 minutes Policy decision lab
BY THE END, YOU CAN

Reason about protection

  • Apply CIA and least privilege.
  • Compare ACLs and capabilities.
  • Separate identity and permission.
  • Explain common OS attack classes.
  • Design layered controls and audits.
01 • DEFINE THE SECURITY GOAL

Protection Controls Use; Security Resists Misuse

CONFIDENTIALITY

Prevent unauthorized disclosure

Permissions, isolation and encryption limit who can observe information.

INTEGRITY

Prevent unauthorized change

Access control, signed code, audit logs and safe update paths protect correctness.

AVAILABILITY

Keep service usable

Quotas, rate limits, redundancy and recovery reduce accidental and deliberate disruption.

least privilege default deny complete mediation defense in depth separation of duty

A trusted reference monitor must mediate every access, resist tampering and remain small enough to analyze. User/kernel mode, page permissions and system calls provide the mechanism; policy decides which accesses should be granted.

02 • REPRESENT WHO MAY DO WHAT

Access Matrix Rows Are Subjects; Columns Are Objects

Model Stored with Question answered Trade-off
ACL Object Who may access this object? Easy object review; delegation/revocation details matter
Capability Subject/token What objects may this holder access? Natural delegation; protect unforgeability
RBAC Role assignments What may this job role do? Scales administration; role explosion possible
MAC Labels and central policy Does label flow permit access? Strong central control; less discretionary flexibility

Authentication establishes an identity using evidence. Authorization evaluates that identity, requested operation, target object and context. Auditing records what occurred; it does not itself prevent the action.

03 • INTERACTIVE REFERENCE-MONITOR LAB

Evaluate Role, Resource and Action

READY

Default deny

Select an access request to see the explicit policy decision.

04 • REDUCE ATTACK SURFACE

Different Threats Require Different Controls

MEMORY CORRUPTION

Overflow/use-after-free

Safer languages, bounds checks, ASLR, NX/DEP and control-flow defenses reduce exploitation.

PRIVILEGE ESCALATION

Gain forbidden authority

Patch vulnerable code, minimize privileged services, separate accounts and audit elevation.

MALWARE

Abuse legitimate execution

Signed updates, allow-listing, sandboxing, least privilege and behavioral detection provide layers.

TOCTOU

Check/use race

Use atomic APIs and object handles; a pathname may resolve differently after a separate check.

SIDE CHANNEL

Infer through shared effects

Timing, caches and speculative behavior can leak across boundaries not visible in access checks.

DENIAL OF SERVICE

Exhaust finite resources

Quotas, backpressure, rate limits and isolation protect availability.

05 • PROGRAM TRACING

Trace One Protected File Read

ACCESS PATH ·

06 • CHECK YOUR UNDERSTANDING

Ten Security Checks

Answered correctly: 0 of 10
07 • EXAM & INTERVIEW

Explain Threat, Mechanism and Residual Risk

2-MARK
  1. Protection versus security?
  2. Define least privilege.
  3. ACL versus capability?
  4. Authentication versus authorization?
  5. What is complete mediation?
5-MARK
  1. Explain access matrix.
  2. Compare security models.
  3. Explain defense in depth.
  4. Analyze TOCTOU.
  5. Describe malware controls.
INTERVIEW
  1. Why default deny?
  2. Why hash passwords?
  3. What does ASLR do?
  4. Why are logs protected?
  5. Can containers be a security boundary?
LEVEL 12 SUMMARY

You Can Explain Why an Access Is Allowed or Denied

  • Security preserves confidentiality, integrity and availability.
  • Authentication and authorization solve different problems.
  • ACLs, capabilities, roles and labels encode policy differently.
  • Least privilege limits blast radius.
  • Layered controls reduce but do not eliminate risk.
COURSE CHECKPOINT

Mark complete after you can justify one policy decision.

Saved only in this browser.