The Center for Education and Research in Information Assurance and Security (CERIAS)

The Center for Education and Research in
Information Assurance and Security (CERIAS)

Reports and Papers Archive


Browse All Papers »       Submit A Paper »

The Spring Nucleus: A Microkernel for Objects

Graham Hamilton,Panos Kougiouris
Added 2002-07-26

Report on the Larch Shared Language: Version 2.3

John V. Guttag,James J. Horning,Andres Modet
Added 2002-07-26


Introduction to LCL, A Larch/C Interface Language

J. V. Guttag,J. J. Horning
Added 2002-07-26

Using Models of Intrusions

Thomas D. Garvey,Teresa F. Lunt
Added 2002-07-26

Model-Based Intrusion Detection

Thomas D. Garvey,Teresa F. Lunt
Added 2002-07-26

Debugging Larch Shared Language Specifications

Stephen J. Garland,John V. Guttag,James J. Horning
Added 2002-07-26


A Code Generation Interface for ANSIC

Christopher W. Fraser,David R. Hanson
Added 2002-07-26

Anatomy of a Flame: Conflict and Community Building on the Internet

V. Franco,R. Piirto,H.Y. Hu,B.V. Lewenstein
Added 2002-07-26

Issues in the Implementation of a Remote Memory Paging System

Edward W. Felten, John Zahorjan
Added 2002-07-26


The COPS Security Checker System

CERIAS TR 1999-13
Dan Farmer,Eugene H. Spafford
Download: PDF

In the past several years, there have been a large number of published works that have graphically described a wide variety of security problems particular to UNIX. Without fail, the same problems have been discussed over and over again, describing the problems with SUID (set user ID) programs, improper file permissions, and bad passwords (to name a few). There are two common characteristics to each of these problems: first, they are usually simple to correct, if found; second, they are fairly easy to detect. Since almost all systems have fairly equivalent problems, it seems appropriate to create a tool to detect potential security problems as an aid to system admin- istrators. This paper describes one such tool: COPS (Computer Oracle and Password System) is a freely-available, reconfigurable set of programs and shell scripts that enable system administrators to check for possible security holes in their systems. This paper briefly describes the system. Included are the underlying design goals, the functions provided by the tool, possible extensions, and some experiences gained from its use. We also include information on how to obtain a copy of the initial COPS release.

Added 2002-07-26

NIS Security Problems

Rik Farrow
Added 2002-07-26

The Cross-architecture Procedure Call

Raymond Brooke Essick IV
Added 2002-07-26