I can see clearly how discretionary access control (DAC) works by checking the p
ID: 660158 • Letter: I
Question
I can see clearly how discretionary access control (DAC) works by checking the properties of a file on my MSWindows machine, the file has attributes and the owner of the file can do almost anything with it like making it available for everyone to read, transfer the ownership to an other user or even delete it
However I cant find any visible example that I can actually see in a GUI that might help me to understand how mandatory access control (MAC) works? can I create a file under MAC? How does the file get its attributes? and how is it possible that I don't own it?
Explanation / Answer
There are a couple of places that you can see Mandatory Access Control (MAC) systems in operation in consumer OSs, that spring to mind.
SELinux is installed on a number of linux distributions and can be set in enforcing mode which would show an example.
Also windows Mandatory Integrity Levels are another example.
Seeing an example of this could be done by getting a Windows 8 machine and trying to modify files within a windows 8 store programs installation directory (under the hidden directory c:program fileswindowsapps). Even as an administrative user you will be prevented from changing these files via standard OS tools even after you have "taken ownership" of the file, which in a DAC system would usually allow you to modify it..
Related Questions
drjack9650@gmail.com
Navigate
Integrity-first tutoring: explanations and feedback only — we do not complete graded work. Learn more.