Lecture 9 Outline
Reading: text, §4.1*–4.5*
Assignments: Homework 2, due Oct. 17; Lab 2, due Oct. 19
- Greetings and felicitations!
- Puzzle of the Day
- Policy
- Sets of authorized, unauthorized states
- Secure systems in terms of states
- Mechanism vs. policy
- Types of Policies
- Military/government vs. confidentiality
- Commercial vs. integrity
- Types of Access Control
- Mandatory access control
- Discretionary access control
- Originator-controlled access control
- High-level policy languages
- Characterization
- Example: DTEL
- Low-level policy languages
- Characterization
- Example: tripwire configuration file