Outline for September 26, 2021
Reading: text, §4.3–4.4, 2.1–2.2, 5.1
Due: Homework 1, due October 5; Project selection, due Oct 7
- Types of Policies
- Military/government vs. confidentiality
- Commercial vs. integrity
- Access Control Matrix
- Commands, nesting, and conditions
- create subject
- create object
- destroy subject
- destroy object
- enter r into A[s, o]
- delete r from A[s, o]
- Copy flag, own rights
- Principle of attenuation of privilege
- Undecidability result
- Goals of confidentiality policies
- Bell-LaPadula Model with levels only
- Security levels
- Simple security property
- *-property
- Discretionary security property
- Simplified version of the Basic Security Theorem