0% found this document useful (0 votes)
14 views5 pages

Security in SCL Systems Overview

The document outlines a series of report topics for students in a Principles of Operating Systems course, emphasizing the importance of original writing and proper citation of research from reputable journals. Topics include security in various operating systems (Windows, Linux, FreeBSD, macOS, Android), memory management, virtualization, and cloud computing security. Each report must be comprehensive, at least 4-6 pages long, and include diagrams and references to the latest research findings.

Uploaded by

engmohamedsw
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
14 views5 pages

Security in SCL Systems Overview

The document outlines a series of report topics for students in a Principles of Operating Systems course, emphasizing the importance of original writing and proper citation of research from reputable journals. Topics include security in various operating systems (Windows, Linux, FreeBSD, macOS, Android), memory management, virtualization, and cloud computing security. Each report must be comprehensive, at least 4-6 pages long, and include diagrams and references to the latest research findings.

Uploaded by

engmohamedsw
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

College of Computing & Information Sciences, Shinas

CSOP1207: Principles of Operating Systems


Semester 2 -AY2024-2025
Student Centered Learning
-------------------------------------------------------------------------------------------

NOTE:

• Students may be allowed to select any topic of their choice in consultation with
the teacher.
• Given below are some topics which may also be chosen by the students.
• Reports should be at least 4‐6 pages long but should cover all topics as
mentioned below. Your report must include diagrams and cite references.
• The report also includes the latest research findings from journals such as
IEEE, Web of Science, and Scopus Failing to cite references will lead to loss
of marks.
• DO NOT COPY DIRECTLY FROM SOURCE BUT WRITE IN YOUR OWN
WORDS. Plagiarism is an offence.
____________________________________________________________
-----------------------------------------------------------------------------------------------
1.
Write a detailed report on Security in Windows Server 2012. Your report
should include the following: user authentication, user authorization,
passwords and encryption, how Windows Server can be affected by worms,
viruses and spyware and the solutions to prevent them and network security
in Server such as Firewalls, IDS and how they prevent attacks from network
and the internet. The report should include the latest research findings from
journals such as IEEE, Web of Science, and Scopus, ensuring a
comprehensive overview of security mechanisms.
2.
Write a report on Security in Linux. Your report should include the following:
user authentication, user authorization, passwords and encryption, how is
Linux more secure than operating systems such as Windows XP, security for
Files and File system in Linux and network security in Linux such as Firewalls
and intrusion detection and how they prevent attacks from network and the
internet. The report should include the latest research findings from journals
such as IEEE, Web of Science, and Scopus, ensuring a comprehensive
overview of security mechanisms.

3.
Write a report on Security in the FreeBSD UNIX operating system. Your
report should include the following: user accounts and user authentication,
user authorization, passwords and encryption, how is FreeBSD is more secure
than operating systems such as Windows XP, security for Files and File
system in FreeBSD and network security in FreeBSD such as Firewalls and
intrusion detection and how they prevent attacks from network and the
internet. The report should include the latest research findings from journals
such as IEEE, Web of Science, and Scopus, ensuring a comprehensive
security mechanisms.

4.
Write a detailed report on memory management in FreeBSD and Linux.
Your report MUST cover the following topics in both FreeBSD and Linux:
management of physical memory, paging and algorithms for it, allocation of
memory to processes and kernel, caching, virtual memory, swapping and
paging mechanisms, working set and performance issues. Compare and
contrast the above topics between Linux and FreeBSD. The report should
include the latest research findings from journals such as IEEE, Web of
Science, and Scopus, ensuring a comprehensive overview of memory
management mechanisms.

5.
Write a report on journaling File systems. Your report should include an
introduction to journaling file systems in general, how they are more reliable
than other file systems, description of journaling file systems implemented in
common operating system such as Linux, Windows, FreeBSD. Also discuss
any problem and performance issues with each journaling file system. The
report should include the latest research findings from journals such as IEEE,
Web of Science, and Scopus, ensuring a comprehensive overview of
journaling File systems.

6.
Write a report on QNX Real time operating system. Your report must have an
Introduction to real‐time operating systems in general and explain how and
why they are different from general purpose operating systems such as
Windows. The areas where they are used. Discuss how QNX is one such OS.
Describe how QNX does kernel organization, memory management and
process management. The report should include the latest research findings
from journals such as IEEE, Web of Science, and Scopus, ensuring a
comprehensive overview of QNX Real time operating system.

7.
Write a report on Linux on mobile phones. Report must cover the following:
Introduction to embedded Linux, How Linux is being used on mobile phones,
what phones are using Linux, what modifications have been projects for
mobile phones. The report should include the latest research findings from
journals such as IEEE, Web of Science, and Scopus, ensuring a
comprehensive overview of Linux on mobile phones

8.
Write a detailed report on memory management in Linux and Windows
Client OS [ Windows 11]. Your report MUST cover the following topics in
both Linux and Windows: management of physical memory, paging and
algorithms for it, allocation of memory to processes and kernel, caching,
virtual memory, swapping and paging mechanisms, working set and
performance issues. Compare and contrast the above topics between Linux
and Windows. The report should include the latest research findings from
journals such as IEEE, Web of Science, and Scopus, ensuring a
comprehensive overview of memory management in Linux and Windows
Client OS.

9.
Write a report on Virtualization on servers and its many benefits. Your
report should include an introduction to virtualization and VMs, how
virtualization is used in servers and server operating systems to reduce cost,
which virtual machines are being used and how do they function interacting
with hardware and the operating system. The report should include the latest
research findings from journals such as IEEE, Web of Science, and Scopus,
ensuring a comprehensive overview of Virtualization on servers.

10.
Write a report on real-time operating systems. Your report must have an
Introduction to real‐time operating systems and explain how and why they are
different from general purpose operating systems such as Windows. The areas
where they are used. Their implementation such as kernel organization,
memory management and process management. The report should include the
latest research findings from journals such as IEEE, Web of Science, and
Scopus, ensuring a comprehensive overview of real-time operating systems.

11.
Write a report on the MINIX micro kernel operating system. Report must
cover the following: Introduction to micro kernel operating system and how
they are different from monolithic kernels such as Linux. The design of the
kernel in a microkernel OS such as MINIX. Discuss the basic implementation
of the micro kernel and how process management, memory management and
file systems are implemented in a micro kernel. For all the topics use MINIX
as an example. The report should include the latest research findings from
journals such as IEEE, Web of Science, and Scopus, ensuring a
comprehensive overview of the MINIX micro kernel operating system

12.
Write a detailed report on Process management and memory management
in the Solaris operating System. The report must cover the scheduling
algorithms in detail, different types of processes, process creation and
termination, thread support, process states, priorities. For memory
management: management of physical memory, paging and algorithms for it,
allocation of memory to processes and kernel, caching, virtual memory,
swapping and paging mechanisms, working set and performance issues. The
report should include the latest research findings from journals such as IEEE,
Web of Science, and Scopus, ensuring a comprehensive overview of Process
management and memory management in the Solaris operating System.

13.
Write a Report on macOS. Your report should cover the following aspects of
macOS security: user authentication, user authorization, passwords, and
encryption. Discuss how macOS deals with worms, viruses, and spyware, and
the preventive solutions that Apple implements. In addition, explore network
security measures on macOS, including firewalls, Intrusion Detection
Systems (IDS), and their role in defending against attacks from networks and
the internet. The report should also integrate the latest research findings from
journals such as IEEE, Web of Science, and Scopus, ensuring a
comprehensive overview of macOS security.

14.
Write a Report on Security in Android OS .This report must explore Android
OS security mechanisms, including user authentication, user authorization,
encryption, and security of apps. Examine how Android OS deals with
vulnerabilities such as malware, spyware, and security breaches, and provide
solutions that developers and users can implement to mitigate risks. Discuss
Android-specific security measures like secure boot, app permissions, and
how Android integrates security features with hardware. Include research
from journals such as IEEE, Web of Science, and Scopus.

15.
Write a detailed report on cloud computing security, covering the essential
aspects of data protection in public, private, and hybrid cloud environments.
Discuss encryption, data storage, virtualized environments, identity
management, and authentication in cloud computing. Examine the security
challenges such as data breaches, insider threats, and compliance issues.
Provide solutions and best practices for securing cloud infrastructures and
explore research findings on cloud security from journals such as IEEE, Web
of Science, and Scopus.

Common questions

Powered by AI

Journaling file systems in Linux, such as ext4, offer several advantages over those in Windows (like NTFS) or FreeBSD (UFS with soft updates). A key advantage is the rapid recovery capability after system crashes, as the journal can be replayed to restore a consistent state. This dramatically reduces downtime and data loss risk. However, despite these benefits, journaling can introduce overhead, potentially impacting performance, especially with high I/O operations. In contrast, Windows' NTFS and FreeBSD’s UFS/FFS have optimizations like transaction tracking and metadata journaling which reduce such overhead. Each system reflects a trade-off between speed, reliability, and complexity, with Linux favoring a balanced approach.

Real-time operating systems, such as QNX, differ significantly from general-purpose systems like Windows in their approach to process management. QNX implements a microkernel architecture, which simplifies the core functions of the kernel, relegating many tasks to user-space processes. This architecture, combined with a prioritization scheduling system, allows for deterministic scheduling, which is essential in real-time applications where timing is critical. Unlike general-purpose systems that may prioritize average throughput, QNX ensures that high-priority tasks are executed within strict time constraints, reducing the chances of latency. These features enable real-time systems to deliver predictable and reliable performance, which is crucial in applications like robotics and embedded systems.

Android OS employs several security mechanisms that effectively mitigate malware risks compared to traditional desktop operating systems. Secure boot ensures that only verified software components load during the boot process, preventing unauthorized code from running. Additionally, app permissions in Android provide users with the control to grant or deny applications access to specific system resources, minimizing the likelihood of malicious access. These permissions, coupled with Android's sandboxing of applications, isolate app processes, reducing the potential impact of harmful behavior. This layered security model contrasts with traditional desktop OS, where applications typically have more access, increasing vulnerability to malware.

In microkernel systems like MINIX, the kernel is minimal, delegating most services such as file systems, device drivers, and network protocols to isolated user-space processes. This decentralization enhances system stability, as failures in one component don't necessarily crash the whole system. However, the inter-process communication (IPC) overhead can degrade performance. Conversely, a monolithic kernel like Linux integrates these services into a single large kernel. While this can enhance performance due to reduced communication overhead, it also increases the risk of cascading failures affecting the entire system if a bug occurs. This trade-off highlights the balance between performance efficiency and stability.

macOS incorporates several security features that bolster its defense against worms, viruses, and spyware. Notably, Gatekeeper enforces stringent controls on software installation by requiring apps to be digitally signed by verified developers or obtained from the Apple App Store. Additionally, the built-in XProtect keeps a continuously updated blacklist of known malware signatures, providing proactive defense. macOS also uses system integrity protection to restrict root-level access to critical system files, mitigating the threat posed by malicious software that attempts to modify these files. This layered security approach is more restrictive and controlled compared to many non-Apple operating systems.

Paging and memory allocation algorithms are crucial in determining the performance and efficiency of physical memory management in Linux and Windows. In Linux, the paging system utilizes LRU (Least Recently Used) replacement algorithms, optimizing memory usage by prioritizing frequently accessed pages. Its memory management also involves overcommit strategies that allow more memory to be allocated than physically available, using swap space effectively. In contrast, Windows employs a simplified zone system, managing memory through the Global/Local Descriptors Table, which directly interacts with the page tables. These different strategies influence system performance, especially under high load conditions where Linux's approach may handle resource allocation more granularly compared to Windows' hierarchical method.

Virtualization provides significant benefits to server environments by enabling multiple virtual machines (VMs) to run on a single physical server. This capability maximizes hardware utilization, reduces the need for physical servers, and subsequently decreases operational costs related to power, cooling, and space. Virtualization software creates an abstraction layer over the physical hardware, allowing each VM to operate independently as if it were a standalone server with its own resources and operating system. This flexibility simplifies resource management and allows for rapid deployment and cloning of servers, further contributing to cost efficiency.

Linux is generally considered more secure than Windows XP due to its robust user authentication and file system protection mechanisms. In Linux, user authentication is typically more stringent, supporting multiple methods such as PAM (Pluggable Authentication Modules), which enhances flexibility and security. The file system in Linux supports complex permissions and access control while being inherently more secure due to its design. Additionally, Linux integrates security models like SELinux and AppArmor for enhanced protection, which are absent in Windows XP. Moreover, Linux's open-source nature encourages rapid patching and updates, unlike Windows XP, which no longer receives official support, leaving it vulnerable to exploits.

The main distinctions between Linux and FreeBSD regarding memory management lie in their approaches to paging, allocation, and caching. FreeBSD utilizes the ULE scheduler and incorporates advanced memory management features such as ASLR (Address Space Layout Randomization), which improves security by randomizing memory addresses. In contrast, Linux uses different schedulers (like CFS – Completely Fair Scheduler) and extensively implements techniques such as overcommitment and kmalloc caching. FreeBSD's memory management is typically more conservative in resource allocation, which can improve stability and performance under certain conditions, whereas Linux tends to optimize for throughput using more aggressive strategies. These differences often lead to variations in performance, particularly under heavy loads where FreeBSD might demonstrate more predictable behavior due to its conservative memory policies.

Cloud computing environments introduce unique security challenges such as data breaches, insider threats, and compliance issues due to their multi-tenant architecture and extensive data accessibility. Addressing these challenges requires robust encryption for data-at-rest and data-in-transit, ensuring only authorized access through identity management solutions. Implementing strict access controls and continuous monitoring can mitigate insider threats. For compliance, adhering to standards like ISO/IEC 27001 provides a framework for managing security risks. Layered security architectures and using cloud security posture management tools enhance visibility and further secure cloud infrastructures against potential attacks.

You might also like