A Model-Independent Security Architecture for Distributed Heterogeneous Systems
By (author) Stephen D B Wolthusen
Paperback (Published)
(December 2003)
ISBN: 9783832504168
5.71 x 8.27 inches
Price: $61.00
Out of stock
This dissertation shows that information assurance properties can be both specified within a formal model of systems to which the properties are applied using the same formal theory for modeling, specification, and reasoning and enforced in such a way that enforcement is performed consistently across multiple, heterogeneous nodes and organizational domains while retaining the semantics of the formal model. The properties, referred to as security policies, can be specifically enforced at the operating system level and are constructed in such a way that automated reasoning mechanisms derive lower abstraction layer properties from higher semantic levels specified by administrative personnel based on the formal abstract model and interpretations thereof. Moreover, operations to be performed are permitted based on proofs obtained within the formal model while required operations are also derived within the model. To permit the consistent enforcement of an arbitrarily large set of security policies and scalability across large organizations and networks, externally controlled reference monitors and external reference monitors are introduced which control layered enforcement mechanisms that can be implemented both in systems constructed ab initio and as an add-on to existing, particularly commercially available operating systems even if no source code is available for modification to ease the transition to secure systems while permitting mission fulfillment based on legacy systems. These aspects are demonstrated using the Microsoft Windows 2000 operating system as an example. Enforcement mechanisms are described using the reference interpretation including modification and augmentation of file system and network protocol stack behavior along with the implicit benefits derived from the use of these enforcement mechanisms. Specifically, the implementation of dynamic distributed network firewalling and intrusion detection as well as multilevel security capabilities under the control of consistent policies are discussed. For this purpose the suitability of the framework for modeling multisensor data fusion as applied to intrusion detection is discussed. To demonstrate the capabilities of the layered enforcement system for application-specific domains, the use of visible and invisible labeling mechanisms for hard copy output is furthermore discussed.
- By (author) Stephen D B Wolthusen
Similar Books
Care in an Era of New Technologies and Artificial Intelligence
Relationships in a Connected World
Volume 14
Buchblogs zwischen Passion und Profession
Zur Diskursivierung digitaler literaturbezogener Anschlusskommunikation als Arbeit
Die Einführung ins richtige Handeln in der Arithmetik (Madḫal ar-rašad ilā ʿilm al-ʿadad) von al-Qalaṣādī (st. 1486)
Bearbeitung und Einordnung in die maġribinische Mathematikgeschichte
Volume 19
Digitale Medien und Religionsunterricht
Ein domänenspezifischer Beitrag zu einer kritischen Medienbildung unter Berücksichtigung medien-, bildungs- und lerntheoretischer Perspektiven
Ein Glucksritter als Wegbereiter der Motorisierung
Der Basler Kaufmann Eduard Burckhardt (1847-1897)
Partizipative Produktentwicklung in der Modeindustrie
Methoden, Vorgehensmodelle und ihre Anwendung in der Wertschöpfung smarter Outdoorbekleidung
Heterarchical Production Planning and Control Architectures in the Context of Industry 4.0
Complexity-based Selection and Guidance for Implementation
Volume 67
Proceedings of the 7th Symposium of the Hellenic Society for Archaeometry
Archaeology Archaeometry: 30 Years Later
I disegni e i discorsi di Giovanni Antonio Nigrone vol. I
fontanaro e ingegniero de acqua (1585-1609 ca.)
Volume 481
I disegni e i discorsi di Giovanni Antonio Nigrone vol. II
Fontanaro e ingegniero de acqua (1585-1609 ca.)
Volume 497
