首页> 外文会议>Computer Security Applications Conference >A Security Model for Military Message Systems: Retrospective
【24h】

A Security Model for Military Message Systems: Retrospective

机译:军事留言系统的安全模型:回顾性

获取原文

摘要

Military systems that process classified information must operate in a secure manner; that is, they must adequately protect information against unauthorized disclosure, modification, and withholding. A goal of current research in computer security is to facilitate the construction of multilevel secure systems, systems that protect information of different classifications from users with different clearances. Security models are used to define the concept of security embodied by a computer system. A single model, called the Bell and LaPadula model, has dominated recent efforts to build secure systems but has deficiencies. We are developing a new approach to defining security models based on the idea that a security model should be derived from a specific application. To evaluate our approach, we have formulated a security model for a family of military message systems. This paper introduces the message system application, describes the problems of using the Bell-LaPadula model in real applications, and presents our security model both informally and formally. Significant aspects of the security model are its definition of multilevel objects and its inclusion of application-dependent security assertions. Prototypes based on this model are being developed. Categories and Subject Descriptors: C.2.0 [Computer-Communication Networks]: General--Security and protection; D.4.6 [Operating Systems]: Security and Protection--access controls; information flow controls; verification; F.3.1 [Logics and Meaning of Programs]: Specifying and Verifying and Reasoning about Programs-- assertions; invariants; specification techniques; H.4.3 [Information Systems Applications]: Communications Applications--electronic mail
机译:处理分类信息的军事系统必须以安全的方式运行;也就是说,他们必须充分保护信息免受未经授权的披露,修改和扣缴。目前计算机安全性研究的目标是促进多级安全系统的构建,保护不同分类信息的系统,从用户提供不同的间隙。安全模型用于定义计算机系统体现的安全概念。单一的模型,称为Bell和Lapadula模型,最近努力建立安全系统,但具有缺陷。我们正在开发一种新方法来定义安全模型,基于安全模型应该从特定应用程序派生。为了评估我们的方法,我们为一家军事留言系统制定了安全模型。本文介绍了消息系统应用程序,描述了使用真实应用中的贝尔-1apadula模型的问题,并正式和正式介绍我们的安全模型。安全模型的重要方面是它对多级对象的定义及其包括应用程序相关的安全断言。正在开发基于该模型的原型。类别和主题描述符:C.2.0 [计算机通信网络]:一般 - 安全和保护; D.4.6 [操作系统]:安全性和保护 - 访问控制;信息流量控制;确认; F.3.1 [计划的逻辑和含义]:指定和验证和推理方案 - 断言;不变;规格技术; H.4.3 [信息系统应用]:通信应用 - 电子邮件

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号