Outline for April 17, 2013
Reading: § 3.4–3.5, 4, handout
Due: Homework #2, due April 26, 2013
- Expressive power
- ESPM and multi-parent create
- Simulation and expressiveness
- Comparing security properties of models
- Policy
- Sets of authorized, unauthorized states
- Secure systems in terms of states
- Mechanism vs. policy
- Types of Policies
- Military/government vs. confidentiality
- Commercial vs. integrity
- Types of Access Control
- Mandatory access control
- Discretionary access control
- Originator-controlled access control
- High-level policy languages
- Characterization
- Example: DTEL
- Low-level policy languages
- Characterization
- Example: tripwire configuration file