Unit 4: File management and security
Operating Systems notes · PTU syllabus (BSIT303/BSBC403)
On this page
Unit summary
Files store data permanently, and security protects the whole system. This unit covers file operations, access methods, directory structures and management, remote file systems, file protection, security environments, unauthorised use, denial of service, access control and authentication, application security, viruses and anti-virus software, and firewalls.
After this unit you can
- Explain file operations, access methods and directory structures
- Explain remote file systems and file protection
- Explain security threats including unauthorised use and denial of service
- Explain access control, authentication, application security, anti-virus and firewalls
PTU syllabus topics
- File operations
- access methods
- directory structures and management
- remote file systems
- file protection
- security environments
- unauthorized use
- denial of service
- access control and authentication
- application security
- viruses and anti-virus
- firewalls
Authentication
Passwords, biometrics, OTP
Access control
Permissions and access lists
Anti-malware
Virus and worm defence
Firewall
Filters network traffic
Updates and audit
Patches and logs
Topic 1
File concept and operations
- File: named collection of related information on secondary storage; attributes — name, type, location, size, protection, timestamps, owner.
- Operations: create, open, read, write, reposition (seek), delete, truncate, close; the OS maintains an open-file table.
Topic 2
Access methods
Sequential
Records read in order
Log files, tapes, text processing
Direct (random)
Any block accessed by number
Databases, airline reservations
Indexed
Index points to blocks; search index then access
Large files with key-based look-up
Topic 3
Directory structures and management
Single-level
All files in one directory — naming conflicts
Two-level
Separate directory per user
Tree-structured
Hierarchical folders with paths
Acyclic graph
Shared files and subdirectories (links)
General graph
Allows cycles — needs garbage collection
- Operations: search, create, delete, list, rename, traverse; absolute and relative path names.
Topic 4
Remote file systems
- Access files on other machines over a network — NFS (Unix/Linux), SMB/CIFS (Windows shares), distributed file systems (HDFS) and cloud storage; client–server model; issues — consistency, caching, failures, security.
Topic 5
File protection
- Access control lists (ACLs): list of users and their permissions for each file.
- Unix permissions: owner, group, others × read, write, execute (rwxr-xr--; chmod 754).
- Passwords and encryption for sensitive files.
Topic 6
Security environment and threats
- Security goals: confidentiality, integrity, availability.
- Unauthorised use: intruders (casual users, insiders, hackers), stolen credentials, privilege escalation, exploitation of software bugs (buffer overflow).
- Denial of service (DoS): making a system or service unavailable by overwhelming it — DDoS uses many compromised machines (botnets).
Topic 7
Access control and authentication
- Authentication: passwords (strong, hashed and salted), one-time passwords, smart cards and tokens, biometrics, multi-factor authentication.
- Access control models: discretionary (owner decides), mandatory (system labels), role-based (permissions by role); principle of least privilege.
Topic 8
Application security
- Secure coding (input validation, avoiding buffer overflows and injection), patching and updates, sandboxing, code signing, least-privilege execution, logging and monitoring.
Topic 9
Viruses and anti-virus software
- Malware: virus (attaches to programs), worm (self-replicates across networks), Trojan horse, ransomware, spyware, rootkit, logic bomb.
- Anti-virus: signature-based detection, heuristic and behaviour-based detection, sandboxing, real-time scanning, regular updates.
Topic 10
Firewalls
- Firewall: filters traffic between networks by rules — packet filters, stateful inspection, application-level gateways (proxies); host-based firewalls on computers.
Key terms
- Access method
- Way of reading and writing file records
- ACL
- List of permissions attached to a file
- Denial of service
- Attack making a service unavailable
- Authentication
- Verifying the identity of a user
- Least privilege
- Granting only the access needed
Quick revision
- File attributes and operations; open-file table.
- Sequential, direct, indexed access.
- Single-level, two-level, tree, acyclic, general graph directories; paths.
- NFS, SMB; ACLs and Unix permissions.
- CIA; unauthorised use; DoS and DDoS; authentication and access control; application security; malware and anti-virus; firewalls.
Important exam questions
Practice questions written to the PTU exam pattern for this unit's syllabus: short answers (Section A style) and long answers (Sections B and C style).
Short-answer questions
- Q1.List six file operations.
- Q2.Distinguish sequential and direct access.
- Q3.What is a tree-structured directory?
- Q4.What does chmod 755 mean?
- Q5.What is a DDoS attack?
- Q6.Distinguish a virus and a worm.
Long-answer questions
- Q1.Explain file operations and access methods.
- Q2.Explain directory structures and remote file systems.
- Q3.Explain file protection and access control and authentication.
- Q4.Discuss security threats, application security, anti-virus software and firewalls.
Stuck on this unit?
Message SBS on WhatsApp for help with Operating Systems, or to ask about studying B.Sc IT at Synetic.
