Outline for October 6, 2023
Reading: text, §5.2.2, 5.3, 6.1–6.2, 6.4}
Due: Homework 1, due October 9; Project teams, question, due October 11
- Example: Trusted Solaris
- Tranquility
- Declassification problem
- Strong tranquility
- Weak tranquility
- Requirements of integrity models
- Biba Model (strict integrity policy)
- Clark-Wilson Model
- Theme: military model does not provide enough controls for commercial fraud, etc. because it does not cover the right aspects of integrity
- Components
- Constrained Data Items (CDI) to which the model applies
- Unconstrained Data Items (UDIs) to which no integrity checks are applied
- Integrity Verification Procedures (IVP) that verify conformance to the integrity spec when IVP is run
- Transaction Procedures (TP) takes system from one well-formed state to another