Sciweavers

SP
1996
IEEE

A Security Model of Dynamic Labeling Providing a Tiered Approach to Verification

14 years 4 months ago
A Security Model of Dynamic Labeling Providing a Tiered Approach to Verification
In the proposed mandatory access control model, arbitrary label changing policies can be expressed. The relatively simple model can capture a wide variety of security policies, including high-water marks, downgrading, separation of duties, and Chinese Walls. The model forms the basis for a tiered approach to the formal development of secure systems, whereby security verification can be spread across what makes up the reference monitor and the security requirement specification. The advantage of this approach is that once a trusted computing base (TCB) is in place, reconfiguring it for different security requirements requires verification of just the new requirements. We illustrate the approach with a number of examples, including one policy that permits high-level subjects to make relabeling requests on low-level objects; the policy is multilevel secure.
Simon N. Foley, Li Gong, Xiaolei Qian
Added 07 Aug 2010
Updated 07 Aug 2010
Type Conference
Year 1996
Where SP
Authors Simon N. Foley, Li Gong, Xiaolei Qian
Comments (0)