Unit 4 of 4 · B.Sc IT Sem 3

Unit 4: File management and security

Operating Systems notes · PTU syllabus (BSIT303/BSBC403)

3 min read10 topics10 exam questions
On this page
  1. Unit summary
  2. File concept and operations
  3. Access methods
  4. Directory structures and management
  5. Remote file systems
  6. File protection
  7. Security environment and threats
  8. Access control and authentication
  9. Application security
  10. Viruses and anti-virus software
  11. Firewalls
  12. Key terms
  13. Quick revision
  14. Important questions

Unit summary

Files store data permanently, and security protects the whole system. This unit covers file operations, access methods, directory structures and management, remote file systems, file protection, security environments, unauthorised use, denial of service, access control and authentication, application security, viruses and anti-virus software, and firewalls.

After this unit you can

  • Explain file operations, access methods and directory structures
  • Explain remote file systems and file protection
  • Explain security threats including unauthorised use and denial of service
  • Explain access control, authentication, application security, anti-virus and firewalls

PTU syllabus topics

  • File operations
  • access methods
  • directory structures and management
  • remote file systems
  • file protection
  • security environments
  • unauthorized use
  • denial of service
  • access control and authentication
  • application security
  • viruses and anti-virus
  • firewalls
ClassificationLayers of OS security
Protecting a system
  • Authentication

    Passwords, biometrics, OTP

  • Access control

    Permissions and access lists

  • Anti-malware

    Virus and worm defence

  • Firewall

    Filters network traffic

  • Updates and audit

    Patches and logs

1

Topic 1

File concept and operations

  • File: named collection of related information on secondary storage; attributes — name, type, location, size, protection, timestamps, owner.
  • Operations: create, open, read, write, reposition (seek), delete, truncate, close; the OS maintains an open-file table.
2

Topic 2

Access methods

ComparisonFile access methods
How it works
Example

Sequential

Records read in order

Log files, tapes, text processing

Direct (random)

Any block accessed by number

Databases, airline reservations

Indexed

Index points to blocks; search index then access

Large files with key-based look-up

3

Topic 3

Directory structures and management

ClassificationDirectory structures
Directories
  • Single-level

    All files in one directory — naming conflicts

  • Two-level

    Separate directory per user

  • Tree-structured

    Hierarchical folders with paths

  • Acyclic graph

    Shared files and subdirectories (links)

  • General graph

    Allows cycles — needs garbage collection

  • Operations: search, create, delete, list, rename, traverse; absolute and relative path names.
4

Topic 4

Remote file systems

  • Access files on other machines over a network — NFS (Unix/Linux), SMB/CIFS (Windows shares), distributed file systems (HDFS) and cloud storage; client–server model; issues — consistency, caching, failures, security.
5

Topic 5

File protection

  • Access control lists (ACLs): list of users and their permissions for each file.
  • Unix permissions: owner, group, others × read, write, execute (rwxr-xr--; chmod 754).
  • Passwords and encryption for sensitive files.
6

Topic 6

Security environment and threats

  • Security goals: confidentiality, integrity, availability.
  • Unauthorised use: intruders (casual users, insiders, hackers), stolen credentials, privilege escalation, exploitation of software bugs (buffer overflow).
  • Denial of service (DoS): making a system or service unavailable by overwhelming it — DDoS uses many compromised machines (botnets).
7

Topic 7

Access control and authentication

  • Authentication: passwords (strong, hashed and salted), one-time passwords, smart cards and tokens, biometrics, multi-factor authentication.
  • Access control models: discretionary (owner decides), mandatory (system labels), role-based (permissions by role); principle of least privilege.
8

Topic 8

Application security

  • Secure coding (input validation, avoiding buffer overflows and injection), patching and updates, sandboxing, code signing, least-privilege execution, logging and monitoring.
9

Topic 9

Viruses and anti-virus software

  • Malware: virus (attaches to programs), worm (self-replicates across networks), Trojan horse, ransomware, spyware, rootkit, logic bomb.
  • Anti-virus: signature-based detection, heuristic and behaviour-based detection, sandboxing, real-time scanning, regular updates.
10

Topic 10

Firewalls

  • Firewall: filters traffic between networks by rules — packet filters, stateful inspection, application-level gateways (proxies); host-based firewalls on computers.

Key terms

Access method
Way of reading and writing file records
ACL
List of permissions attached to a file
Denial of service
Attack making a service unavailable
Authentication
Verifying the identity of a user
Least privilege
Granting only the access needed

Quick revision

  • File attributes and operations; open-file table.
  • Sequential, direct, indexed access.
  • Single-level, two-level, tree, acyclic, general graph directories; paths.
  • NFS, SMB; ACLs and Unix permissions.
  • CIA; unauthorised use; DoS and DDoS; authentication and access control; application security; malware and anti-virus; firewalls.

Important exam questions

Practice questions written to the PTU exam pattern for this unit's syllabus: short answers (Section A style) and long answers (Sections B and C style).

Short-answer questions

  1. Q1.List six file operations.
  2. Q2.Distinguish sequential and direct access.
  3. Q3.What is a tree-structured directory?
  4. Q4.What does chmod 755 mean?
  5. Q5.What is a DDoS attack?
  6. Q6.Distinguish a virus and a worm.

Long-answer questions

  1. Q1.Explain file operations and access methods.
  2. Q2.Explain directory structures and remote file systems.
  3. Q3.Explain file protection and access control and authentication.
  4. Q4.Discuss security threats, application security, anti-virus software and firewalls.

Stuck on this unit?

Message SBS on WhatsApp for help with Operating Systems, or to ask about studying B.Sc IT at Synetic.

WhatsApp us