Outline for September 26, 2024
Reading: text, §14, 20.1.2.2, 4.1–4.3
Assignments: Homework 1, due October 8; Project selection, due Oct 10
- Class overview
- Principles of secure design
- Bases: simplicity, restrictiveness
- Principle of least privilege
- Principle of least authority
- Principle of fail-safe defaults
- Principle of economy of mechanism
- Principle of complete mediation
- Principle of open design
- Principle of separation of privilege
- Principle of least common mechanism
- Principle of least astonishment
- Principle of psychological acceptability
- Reference monitor
- Entities, subjects, and objects
- What a reference monitor, reference validation mechanism are
- Relationship to policy
- Policy
- Sets of authorized, unauthorized states
- Secure systems in terms of states
- Defining confidentiality, integrity, availability
- Policy models and mechanisms
- Example
- Types of Policies
- Military/government vs. confidentiality
- Commercial vs. integrity