Current Operating System security DAC is enough ? (discretionary access control) Decisions are only based on user identity and ownership Each user has complete discretion over his objects Only two major categories of users : user and superuser Some services must run as superuser No protection against malicious software If superuser is compromised...