Outline for April 20, 2004
Reading: Chapter 29.1-29.4
Discussion Problem
Actually, Socrates was an organizer. The function of an organizer
is to raise questions that agitate, that break through the accepted
pattern. Socrates, with his goal of "know thyself," was
raising the internal questions within the individual that are so
essential for the revolution which is external to the individual.
So Socrates was carrying out the first stage of making revolutionaries.
If he had been permitted to continue raising questions about the
meaning of life, to examine life and refuse the conventional values,
the internal revolution would soon have moved out into the political
arena. Those who tried him and sentenced him to death knew what
they were doing.1
How might you apply this philosophy to computer security?
Outline for the Day
- Security in Programming
- Example program: goal
- Requirements and Policy
- Access to role account conditioned on user, location, time
- How to handle settings of accounts: override, merge
- Who can alter access control information
- Allow unrestricted and restricted access
- Access to objects owned by role account restricted to those authorized to use role account
- Threat Analysis
- Unauthorized users accessing role accounts
- Obtaining access to a role account as though an authorized user
- Authorized user using non-secure channel to obtain access, exposing information to unauthorized user
- Unauthorized user altering access control information
- Authorized user executing Trojan horse to give access to unauthorized user
- Authorized users access in role accounts
- Performing unauthorized commands (intentionally)
- Executing command that performs unauthorized actions (unintentionally)
- Changing restrictions on ability to obtain access to account
- Design
- User interface
- High-level design
- Access to roles and commands
- Refinement
- First level
- Second level
- Functions: location, access control record, error handling
1.
Saul Alinsky, Rules for Radicals, Random House, Inc.,
New York, NY (1972) pp. 72-73.
Here is a PDF version of this document.