|
SECURITY LABORATORY SEMINAR
In attendance: Matt Bishop presents the Bell-LaPadula Model David E. Bell and Leonard La Padula, Secure Computer System: Unified Exposition and Multics Interpretation, ESD-TR-75-306, ESD/AFSC, Hanscom AFB, Bedford, MA (1975) [DTIC AD-A023588] Security clearance fsc ² subject
Simple Security PropertyReading is acceptable if L ³
Lþ and Cþ Í C
Star PropertyWriting is acceptable if L £
Lþ and C Í Cþ
Discretionary Access Control Rules ² applies to reading and writing
Security level foc (o) Security compartment fsk (s) Security compartment fok (o) P = rights = {read, write, edit, own} Code for the Simple Security Condition, the Star Property and the Discretionary Access Control Property (see paper) 16 Rules from MULTICS (see
paper) Questions?Mutual Exclusion? ² Canþt prevent subject from having
one or another categories
How closely does the model match reality? It is possible to break MULTICS |
|||||||||||||||||||||||||||||||||||||