The invention relates to
a domain-based
access control method and
system. The domain-based
access control method comprises the following steps of: setting
a domain label of each application and establishing
a domain-based
access control policy
library on subject and object of each application in a
system through aiming at different application domains according to requirements of a user on protection of the
system; capturing an access request of the subject on the object in the system; submitting the access request to the domain-based access control policy
library to perform domain
label detection; and judging whether a current operation is allowed or not, accepting the current access request if the current operation is allowed, and refusing the current access request if the current operation is not allowed. The domain-based access
control system comprises a capturing filtering module, an access control judging module, a domain
database module, a domain information managing module and a safety journal querying module, wherein the capturing filtering module is used for capturing and filtering
data access requests of application programs in the system, the access control judging module is used for judging whether a subject domain
label and an
object domain label are same or not and determining whether an access action is allowed or not, the domain
database module is used for saving information of the access control policy
library, the domain information managing module is used for modifying the information of the access control policy library and querying safety journals, and the safety journal querying module is used for storing dangerous operation information disobeying an access control policy. According to the domain-based access control method and system, disclosed by the invention, the application program can be effectively protected, and the safety of the application program and an
operating system can be improved.