Outline for May 20, 2013
Reading: §17.3, 18, [SMB06] (This is available in the Resources area of SmartSite; look in the folder “Handouts”)
Due: Homework #4, due May 24, 201
- Capacity and noninterference
- When is bandwidth of covert channel 0?
- Noninterference sufficient but not necessary
- Analysis
- Measuring capacity
- Mitigating covert channels
- Preallocation and hold until process terminates
- Impose uniformity
- Randomize resource allocation
- Efficiency/performance vs. security
- Assurance
- Trustworthy entities
- Security assurance
- Trusted system
- Why assurance is needed
- Requirements
- Assurance and software life cycle