Lecture 10: April 19, 2021
Reading: text, §2, 3.1–3.2,4–4.6
Due: Homework 2, due April 21, 2021; Lab 1, due April 19, 2021
- Access Control Matrix
- Commands and conditions: create•file, various flavors of grant•right to show conditions and nested commands
- Copy flag, own rights
- Principle of attenuation of privilege
- Decidability of security
- Notion of leakage in terms of ACM
- Determining security of a generic system with generic rights and mono-operational commands is decidable
- Determining security of a generic system with generic rights is undecidable (HRU result)
- Meaning: can’t derive a generic algorithm; must look at (sets of) individual case
- Policy
- Sets of authorized, unauthorized states
- Secure systems in terms of states
- Mechanism vs. policy
- Types of Policies
- Military/government vs. confidentiality
- Commercial vs. integrity