Αρχιτεκτονική και μηχανισμοί ασφάλειας του macOS
Architecture and Security Mechanisms of macOs

View/ Open
Keywords
MacOS ; Ασφάλεια λειτουργικών συστημάτων ; Εμπιστευτικότητα ; Ακεραιότητα ; Defense-in-depth ; Sandboxing ; FileVault ; Secure enclave ; Operating system security ; Confidentiality ; IntegrityAbstract
This thesis presents a rigorous and theoretically grounded analysis of the security
architecture of macOS, treating it as a coherent, multi-layered protection system. The study is
founded on core principles of information system security, including the confidentiality–
integrity–availability (CIA) triad, the Authentication–Authorization–Accountability (AAA) model,
modern access control paradigms, and the Defense-in-Depth strategy.
From an architectural perspective, the analysis focuses on the Darwin foundation and the
hybrid XNU kernel, emphasizing virtual memory management, process isolation, and privilege
separation as fundamental enforcement mechanisms. Data confidentiality is examined through
the interaction of APFS, FileVault encryption, Data Protection classes, and the Secure Enclave,
highlighting the critical role of hierarchical key management and hardware-assisted security. In
parallel, the application security model is evaluated through the trust chain established by code
signing, Gatekeeper, notarization, sandboxing, and the Hardened Runtime.
Furthermore, system integrity mechanisms are analyzed, including System Integrity
Protection (SIP), the signed system volume, and the secure boot chain, along with the
Transparency, Consent and Control (TCC) framework governing access to sensitive user
resources. A comparative assessment with other contemporary operating systems demonstrates
that the vertically integrated design of macOS enables a high degree of security cohesion and
enforcement consistency.
In conclusion, macOS emerges as a representative case of modern operating system security
architecture, where tight hardware–software integration and layered policy enforcement
significantly enhance system resilience, while still being subject to inherent limitations
associated with evolving threat models and system complexity.
Keywords: macOS, operating system security, confidentiality, integrity, Defense-in-Depth,
sandboxing, FileVault, Secure Enclave


