Outline for January 22, 2016
Reading: text, §4, [1]
Due: Presentation paper selection, Jan. 22; Project selection, Jan. 22; Homework 1, due January 25
- Policy
- Sets of authorized, unauthorized states
- Secure systems in terms of states
- Mechanism vs. policy
- Types of Policies
- Military/government vs. confidentiality
- Commercial vs. integrity
- Types of Access Control
- Mandatory access control
- Discretionary access control
- Originator-controlled access control
- High-level policy languages
- Characterization
- Example: Ponder
- Low-level policy languages
- Characterization
- Example: tripwire configuration file