{"id":347,"date":"2018-07-23T12:51:56","date_gmt":"2018-07-23T12:51:56","guid":{"rendered":"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/?post_type=chapter&#038;p=347"},"modified":"2018-12-27T12:24:38","modified_gmt":"2018-12-27T12:24:38","slug":"security-models","status":"publish","type":"chapter","link":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/chapter\/security-models\/","title":{"rendered":"Security Models"},"content":{"raw":"<div><span style=\"float: right\"><a href=\"https:\/\/youtu.be\/HqXq9Hgg8Qo\" target=\"_blank\" rel=\"noopener\"><img src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"epgp books\" width=\"75px\" height=\"75px;\" \/><\/a>\r\n<\/span><\/div>\r\n&nbsp;\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong>Learning Objectives<\/strong><\/p>\r\n\r\n<ul style=\"text-align: justify\">\r\n \t<li>\u00a0To review the concept of Security Models<\/li>\r\n \t<li>\u00a0To discuss about the Models<\/li>\r\n<\/ul>\r\n<p style=\"text-align: justify\">\u00a0 \u00a0 \u2013\u00a0 Bell-LaPadula (BLP)<\/p>\r\n<p style=\"text-align: justify\">\u2013\u00a0 Biba<\/p>\r\n\r\n<ul style=\"text-align: justify\">\r\n \t<li>To understand these concepts of system evaluation<\/li>\r\n<\/ul>\r\n<p style=\"text-align: justify\"><strong>Terminology<\/strong><\/p>\r\n<p style=\"text-align: justify\"><strong>Trusted Computing Base (TCB) <\/strong>\u2013 combination of protection mechanisms<\/p>\r\n<p style=\"text-align: justify\">within a computer system<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong>Subjects \/ Objects<\/strong><\/p>\r\n<p style=\"text-align: justify\">Subjects are active (e.g., users \/ programs)<\/p>\r\n<p style=\"text-align: justify\">Objects are passive (e.g., files)<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\"><strong>Reference Monitor <\/strong>\u2013 abstract machine that mediates subject access to objects <strong>Security Kernel <\/strong>\u2013 core element of TCB that enforces the reference monitor\u2019s<\/p>\r\n<p style=\"text-align: justify\">security policy<\/p>\r\n\r\n<div style=\"text-align: justify\">\r\n\r\n<strong>Types of Access Control<\/strong>\r\n\r\n&nbsp;\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 <strong>Discretionary Access Control (DAC) <\/strong>\u2013 data owners can create and modify matrix of subject \/ object relationships (e.g., ACLs)\r\n\r\n<\/div>\r\n<ul style=\"text-align: justify\">\r\n \t<li><strong>Mandatory Access Control (MAC) <\/strong>\u2013 \u201cinsecure\u201d transactions prohibited regardless of DAC<\/li>\r\n<\/ul>\r\n<ul style=\"text-align: justify\">\r\n \t<li>Cannot enforce MAC rules with DAC security kernel<\/li>\r\n<\/ul>\r\n<p style=\"text-align: justify\">\u2013\u00a0 Someone\u00a0 with read access to a file can copy it and build a new<\/p>\r\n<p style=\"text-align: justify\">\u201cinsecure\u201d DAC matrix because he will be an owner of the new file.<\/p>\r\n<p style=\"text-align: justify\"><strong>Trust Models<\/strong><\/p>\r\n\r\n<ul style=\"text-align: justify\">\r\n \t<li>Bell-LaPadula<\/li>\r\n \t<li>Biba<\/li>\r\n \t<li>Clark-Wilson<\/li>\r\n \t<li>Chinese Wall<\/li>\r\n<\/ul>\r\n<div style=\"text-align: justify\">\r\n\r\n<strong>Bell-LaPadula (BLP) Model<\/strong>\r\n\r\n&nbsp;\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 BLP is formal (mathematical) description of mandatory access control\r\n\r\n&nbsp;\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Three properties:\r\n\r\n&nbsp;\r\n\r\n\u2013\u00a0 ds-property (discretionary security)\r\n\r\n&nbsp;\r\n\r\n\u2013\u00a0 ss-property (simple security \u2013 no \u201cread down\u201d)\r\n\r\n&nbsp;\r\n\r\n\u2013\u00a0 *-property (star property \u2013 no \u201cwrite down\u201d)\r\n\r\n&nbsp;\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 A secure system satisfies all of these properties\r\n\r\n&nbsp;\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 BLP includes mathematical proof that if a system is secure and a transition satisfies all of the properties, then the system will remain secure.\r\n\r\n&nbsp;\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Honeywell Multics kernel was only true implementation of BLP, but it never took hold\r\n\r\n&nbsp;\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 DoD information security requirements currently achieved via discretionary access control and segregation of systems rather than BLP-compliant computers.\r\n<ul>\r\n \t<li>Secure information flows because they describe acceptable connections between subjects and objects of different levels of sensitivity.<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>Security-level analysis is to enable us to construct systems that can perform concurrent computation on data at two different sensitivity levels. For example, we may want to use one machine for top-secret and confidential data at the same time.<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>The programs processing top-secret data would be prevented from leaking top-secret data to the confidential data, and the confidential users would be prevented from accessing the top-secret data.<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>Thus, the BellLa Padula model is useful as the basis for the design of systems that handle data of multiple sensitivities.<\/li>\r\n<\/ul>\r\n<strong>Biba Model<\/strong>\r\n<ul>\r\n \t<li>Similar to BLP but focus is on integrity, not confidentiality<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>Result is to turn the BLP model upside down<\/li>\r\n<\/ul>\r\n\u2013 High integrity subjects c<em>annot<\/em> read lower integrity objects (no \u201cread down\u201d)\r\n\r\n&nbsp;\r\n\r\n\u2013\u00a0 Subjects c<em>annot<\/em> move low integrity data to high-integrity environment\r\n\r\n&nbsp;\r\n\r\n(no \u201cwrite up\u201d)\r\n<ul>\r\n \t<li>McLean notes that ability to flip models essentially renders their assurance properties useless<\/li>\r\n<\/ul>\r\n<\/div>\r\n<div>\r\n\r\n<strong>Clark-Wilson Model<\/strong>\r\n\r\n&nbsp;\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Reviews distinction between military and commercial policy\r\n\r\n&nbsp;\r\n\r\n\u2013\u00a0 Military policy focus on confidentiality\r\n\r\n&nbsp;\r\n\r\n\u2013\u00a0 Commercial policy focus on integrity\r\n<ul>\r\n \t<li>Mandatory commercial controls typically involve who gets to do what type of transaction rather than who sees what (Example: cut a check above a certain dollar amount)<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>Two types of objects:<\/li>\r\n<\/ul>\r\n\u2013\u00a0 Constrained Data Items (CDIs)\r\n\r\n&nbsp;\r\n\r\n\u2013\u00a0 Unconstrained Data Items (UDIs)\r\n<ul>\r\n \t<li>Two types of transactions on CDIs in model<\/li>\r\n<\/ul>\r\n\u2013\u00a0 Integrity Verification Procedures (IVPs)\r\n\r\n&nbsp;\r\n\r\n\u2013\u00a0 Transformation Procedures (TPs)\r\n<ul>\r\n \t<li>IVPs certify that TPs on CDIs result in valid state<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>All TPs must be certified to result in valid transformation<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>System maintains\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 list\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 of\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 valid\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 relations\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 of\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 the\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 form:<\/li>\r\n<\/ul>\r\n{UserID, TP, CDI\/UDI}\r\n<ul>\r\n \t<li>Only permitted manipulation of CDI is via an authorized TP<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>If a TP takes a UDI as an input, then it must result in a proper CDI or the TP will be rejected<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>Additional requirements<\/li>\r\n<\/ul>\r\n\u2013\u00a0 Auditing: TPs must write to an append-only CDI (log)\r\n\r\n&nbsp;\r\n\r\n\u2013\u00a0 Separation of duties\r\n\r\n<\/div>\r\n<div>\r\n\r\n<strong>Clark-Wilson versus Biba<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 In Biba\u2019s model, UDI to CDI conversion is performed by trusted subject only (e.g., a security officer), but this is problematic for data entry function.<\/p>\r\n<p style=\"text-align: justify\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 In Clark-Wilson, TPs are specified for particular users and functions. Biba\u2019s model does not offer this level of granularity.<\/p>\r\n\r\n<\/div>\r\n<strong>Chinese Wall<\/strong>\r\n\r\n&nbsp;\r\n\r\nFocus is on conflicts of interest.\r\n<ul>\r\n \t<li>Principle: Users should not access the confidential information of both a client organization and one or more of its competitors.<\/li>\r\n \t<li>How it works<\/li>\r\n<\/ul>\r\n\u2013\u00a0 Users have no \u201cwall\u201d initially.\r\n\r\n&nbsp;\r\n\r\n\u2013 Once any given file is accessed, files with competitor information become inaccessible.\r\n\r\n&nbsp;\r\n\r\n\u2013\u00a0 Unlike other models, access control rules change with user behavior\r\n<ul>\r\n \t<li>This model provides access controls that can change dynamically depending upon a user\u2019s previous actions.<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>The main goal of this model is to protect against conflicts of interests by user\u2019s access attempts.<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>It is based on the information flow model, where no information can flow between subjects and objects in a way that would result in a conflict of interest.<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>The model states that a subject can write to an object if, and only if, the subject cannot read another object that is in a different data set.<\/li>\r\n<\/ul>\r\n<div>\r\n\r\n<strong>Finite State Machine Models<\/strong>\r\n\r\n&nbsp;\r\n\r\nAutomata (=Finite State Machines) are a popular way\r\n\r\n&nbsp;\r\n\r\nOf modeling many aspects of computing systems.\r\n\r\n&nbsp;\r\n\r\nThe essential features of these are then concepts of:\r\n\r\n&nbsp;\r\n\r\n\u2022\u00a0 State\r\n<ul>\r\n \t<li>State transition<\/li>\r\n<\/ul>\r\n<strong>Bell-LaPadula (BLP) Model<\/strong>\r\n\r\n&nbsp;\r\n\r\nBLP Structure Combines,\r\n<ul>\r\n \t<li><em>Access permission matrices <\/em>for access control,<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>a <em>Security lattice<\/em>, for security levels,<\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>an <em>Automaton<\/em>, for access operations.<\/li>\r\n<\/ul>\r\nSecurity policies are reduced to relations in the BLP structure.\r\n\r\n<\/div>\r\n<strong>BLP Model<\/strong>\r\n<ul>\r\n \t<li>A set of subjects <em>S<\/em><\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>A set of objects <em>O<\/em><\/li>\r\n<\/ul>\r\n<ul>\r\n \t<li>A set of access operations \u2264<\/li>\r\n<\/ul>\r\n<img class=\"alignnone size-full wp-image-348\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-77.jpg\" alt=\"\" width=\"417\" height=\"97\" \/>\r\n\r\n<em>\u00a0-f<\/em><em>s<\/em> :<em> S\u2192L <\/em>gives the maximal security each subject can have,\r\n\r\n&nbsp;\r\n\r\n<em>-f<\/em><em>c<\/em> :<em> S\u2192L <\/em>gives the current security level of each subject,\r\n\r\n&nbsp;\r\n\r\n<em>-f<\/em><em>o<\/em> : O<em>\u2192L <\/em>gives the security classification objects.\r\n\r\n&nbsp;\r\n<div>\r\n\r\nWe require : <em>f<\/em><em>c<\/em> \u2264 <em>f<\/em><em>s<\/em> , that is, the maximal level dominates the current level.\r\n\r\n&nbsp;\r\n\r\nSecurity policies: a state (<em>b, M, f<\/em> ) must satisfy,\r\n\r\n<\/div>\r\n<img class=\"alignnone size-full wp-image-349\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-78.jpg\" alt=\"\" width=\"443\" height=\"556\" \/>\r\n\r\n<img class=\"alignnone size-full wp-image-353\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-79.jpg\" alt=\"\" width=\"536\" height=\"544\" \/>\r\n<div>\r\n\r\n<strong>The Biba Model<\/strong>\r\n\r\n&nbsp;\r\n\r\nThis model addresses integrity by using a state machine model in a similar way to BLP.\r\n\r\n&nbsp;\r\n\r\nIt uses a lattice (L, \u2264) of integrity levels, and functions <em>f<\/em><em>s<\/em> : <em>S\u2192L<\/em> and <em>f<\/em><em>o<\/em><em>:O\u2192L<\/em> which assign integrity levels to subjects and objects.\r\n\r\n&nbsp;\r\n\r\nUnlike BLP there is no single high-level integrity policy.\r\n\r\n&nbsp;\r\n\r\nInstead, there is a variety of approaches.\r\n\r\n&nbsp;\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 The integrity policies guarantee that information only flows downwards.\r\n\r\n&nbsp;\r\n\r\n\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 In particular, \u201cclean\u201d high level entities cannot be corrupted by \u201cdirty\u201d low level entities.\r\n\r\n&nbsp;\r\n\r\n<strong>The Biba Model \u2013 static integrity<\/strong>\r\n\r\n&nbsp;\r\n\r\n<em>Simple integrity property <\/em>:\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\nIf a subject s can modify (alter) object then <em>f<\/em><em>s<\/em> <em>(s)<\/em> \u2265 <em>f<\/em><em>o<\/em> <em>(o)<\/em> (no-write up)\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n<em>Integrity <\/em><em>*<\/em><em> - property <\/em>:\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\nIf a subject s can read (observe) object o then s can have write access to an object o\u2019 only if <em>f<\/em><em>o<\/em> <em>(o\u2019)<\/em> \u2264 <em>f<\/em><em>s<\/em> <em>(s)<\/em>\r\n\r\n&nbsp;\r\n\r\nThese properties prevent clean subjects and objects from being contaminated by dirty information.\r\n\r\n&nbsp;\r\n\r\n<\/div>\r\n<strong>The Biba Model \u2013 dynamic integrity<\/strong>\r\n\r\n&nbsp;\r\n<ol>\r\n \t<li><strong> Subject low watermark property:<\/strong><\/li>\r\n<\/ol>\r\nSubject <em>s<\/em> can read (observe) an object <em>o<\/em> at any integrity level. The new integrity level of <em>s<\/em> is inf(<em>f<\/em><em>s<\/em><em>, f<\/em><em>o<\/em>(<em>o<\/em>)), where <em>f<\/em><em>s<\/em><em>(s)<\/em> and <em>f<\/em><em>o<\/em><em>(o)<\/em> are the integrity levels before the operation.\r\n\r\n&nbsp;\r\n<ol start=\"2\">\r\n \t<li><strong> Object low watermark property:<\/strong><\/li>\r\n<\/ol>\r\nSubject <em>s<\/em> can <em>modify<\/em> an object <em>o<\/em> at any integrity level. The new integrity level of <em>o<\/em> is inf(<em>f<\/em><em>s<\/em><em>, f<\/em><em>o<\/em>(<em>o<\/em>)), where <em>f<\/em><em>s<\/em><em>(s)<\/em> and <em>f<\/em><em>o<\/em><em>(o)<\/em> are the integrity levels before the operation.\r\n\r\n&nbsp;\r\n\r\n<strong>Summary<\/strong>\r\n<ul>\r\n \t<li>Outlined the purpose of security models<\/li>\r\n \t<li>Discussed about various security models<\/li>\r\n \t<li>Discussed about the properties of security models<\/li>\r\n<\/ul>\r\n<table>\r\n<tbody>\r\n<tr>\r\n<td><strong>you can view video on Security Models<\/strong><\/td>\r\n<td><a href=\"https:\/\/youtu.be\/HqXq9Hgg8Qo\" target=\"_blank\" rel=\"noopener\"><img class=\"alignnone wp-image-120\" src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"\" width=\"36\" height=\"36\" \/><\/a><\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n\r\n<img class=\"size-full wp-image-354 aligncenter\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/one.jpg\" alt=\"\" width=\"473\" height=\"253\" \/>","rendered":"<div><span style=\"float: right\"><a href=\"https:\/\/youtu.be\/HqXq9Hgg8Qo\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"epgp books\" width=\"75px\" height=\"75px;\" \/><\/a><br \/>\n<\/span><\/div>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong>Learning Objectives<\/strong><\/p>\n<ul style=\"text-align: justify\">\n<li>\u00a0To review the concept of Security Models<\/li>\n<li>\u00a0To discuss about the Models<\/li>\n<\/ul>\n<p style=\"text-align: justify\">\u00a0 \u00a0 \u2013\u00a0 Bell-LaPadula (BLP)<\/p>\n<p style=\"text-align: justify\">\u2013\u00a0 Biba<\/p>\n<ul style=\"text-align: justify\">\n<li>To understand these concepts of system evaluation<\/li>\n<\/ul>\n<p style=\"text-align: justify\"><strong>Terminology<\/strong><\/p>\n<p style=\"text-align: justify\"><strong>Trusted Computing Base (TCB) <\/strong>\u2013 combination of protection mechanisms<\/p>\n<p style=\"text-align: justify\">within a computer system<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong>Subjects \/ Objects<\/strong><\/p>\n<p style=\"text-align: justify\">Subjects are active (e.g., users \/ programs)<\/p>\n<p style=\"text-align: justify\">Objects are passive (e.g., files)<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong>Reference Monitor <\/strong>\u2013 abstract machine that mediates subject access to objects <strong>Security Kernel <\/strong>\u2013 core element of TCB that enforces the reference monitor\u2019s<\/p>\n<p style=\"text-align: justify\">security policy<\/p>\n<div style=\"text-align: justify\">\n<p><strong>Types of Access Control<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 <strong>Discretionary Access Control (DAC) <\/strong>\u2013 data owners can create and modify matrix of subject \/ object relationships (e.g., ACLs)<\/p>\n<\/div>\n<ul style=\"text-align: justify\">\n<li><strong>Mandatory Access Control (MAC) <\/strong>\u2013 \u201cinsecure\u201d transactions prohibited regardless of DAC<\/li>\n<\/ul>\n<ul style=\"text-align: justify\">\n<li>Cannot enforce MAC rules with DAC security kernel<\/li>\n<\/ul>\n<p style=\"text-align: justify\">\u2013\u00a0 Someone\u00a0 with read access to a file can copy it and build a new<\/p>\n<p style=\"text-align: justify\">\u201cinsecure\u201d DAC matrix because he will be an owner of the new file.<\/p>\n<p style=\"text-align: justify\"><strong>Trust Models<\/strong><\/p>\n<ul style=\"text-align: justify\">\n<li>Bell-LaPadula<\/li>\n<li>Biba<\/li>\n<li>Clark-Wilson<\/li>\n<li>Chinese Wall<\/li>\n<\/ul>\n<div style=\"text-align: justify\">\n<p><strong>Bell-LaPadula (BLP) Model<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 BLP is formal (mathematical) description of mandatory access control<\/p>\n<p>&nbsp;<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Three properties:<\/p>\n<p>&nbsp;<\/p>\n<p>\u2013\u00a0 ds-property (discretionary security)<\/p>\n<p>&nbsp;<\/p>\n<p>\u2013\u00a0 ss-property (simple security \u2013 no \u201cread down\u201d)<\/p>\n<p>&nbsp;<\/p>\n<p>\u2013\u00a0 *-property (star property \u2013 no \u201cwrite down\u201d)<\/p>\n<p>&nbsp;<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 A secure system satisfies all of these properties<\/p>\n<p>&nbsp;<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 BLP includes mathematical proof that if a system is secure and a transition satisfies all of the properties, then the system will remain secure.<\/p>\n<p>&nbsp;<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Honeywell Multics kernel was only true implementation of BLP, but it never took hold<\/p>\n<p>&nbsp;<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 DoD information security requirements currently achieved via discretionary access control and segregation of systems rather than BLP-compliant computers.<\/p>\n<ul>\n<li>Secure information flows because they describe acceptable connections between subjects and objects of different levels of sensitivity.<\/li>\n<\/ul>\n<ul>\n<li>Security-level analysis is to enable us to construct systems that can perform concurrent computation on data at two different sensitivity levels. For example, we may want to use one machine for top-secret and confidential data at the same time.<\/li>\n<\/ul>\n<ul>\n<li>The programs processing top-secret data would be prevented from leaking top-secret data to the confidential data, and the confidential users would be prevented from accessing the top-secret data.<\/li>\n<\/ul>\n<ul>\n<li>Thus, the BellLa Padula model is useful as the basis for the design of systems that handle data of multiple sensitivities.<\/li>\n<\/ul>\n<p><strong>Biba Model<\/strong><\/p>\n<ul>\n<li>Similar to BLP but focus is on integrity, not confidentiality<\/li>\n<\/ul>\n<ul>\n<li>Result is to turn the BLP model upside down<\/li>\n<\/ul>\n<p>\u2013 High integrity subjects c<em>annot<\/em> read lower integrity objects (no \u201cread down\u201d)<\/p>\n<p>&nbsp;<\/p>\n<p>\u2013\u00a0 Subjects c<em>annot<\/em> move low integrity data to high-integrity environment<\/p>\n<p>&nbsp;<\/p>\n<p>(no \u201cwrite up\u201d)<\/p>\n<ul>\n<li>McLean notes that ability to flip models essentially renders their assurance properties useless<\/li>\n<\/ul>\n<\/div>\n<div>\n<p><strong>Clark-Wilson Model<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 Reviews distinction between military and commercial policy<\/p>\n<p>&nbsp;<\/p>\n<p>\u2013\u00a0 Military policy focus on confidentiality<\/p>\n<p>&nbsp;<\/p>\n<p>\u2013\u00a0 Commercial policy focus on integrity<\/p>\n<ul>\n<li>Mandatory commercial controls typically involve who gets to do what type of transaction rather than who sees what (Example: cut a check above a certain dollar amount)<\/li>\n<\/ul>\n<ul>\n<li>Two types of objects:<\/li>\n<\/ul>\n<p>\u2013\u00a0 Constrained Data Items (CDIs)<\/p>\n<p>&nbsp;<\/p>\n<p>\u2013\u00a0 Unconstrained Data Items (UDIs)<\/p>\n<ul>\n<li>Two types of transactions on CDIs in model<\/li>\n<\/ul>\n<p>\u2013\u00a0 Integrity Verification Procedures (IVPs)<\/p>\n<p>&nbsp;<\/p>\n<p>\u2013\u00a0 Transformation Procedures (TPs)<\/p>\n<ul>\n<li>IVPs certify that TPs on CDIs result in valid state<\/li>\n<\/ul>\n<ul>\n<li>All TPs must be certified to result in valid transformation<\/li>\n<\/ul>\n<ul>\n<li>System maintains\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 list\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 of\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 valid\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 relations\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 of\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 the\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 form:<\/li>\n<\/ul>\n<p>{UserID, TP, CDI\/UDI}<\/p>\n<ul>\n<li>Only permitted manipulation of CDI is via an authorized TP<\/li>\n<\/ul>\n<ul>\n<li>If a TP takes a UDI as an input, then it must result in a proper CDI or the TP will be rejected<\/li>\n<\/ul>\n<ul>\n<li>Additional requirements<\/li>\n<\/ul>\n<p>\u2013\u00a0 Auditing: TPs must write to an append-only CDI (log)<\/p>\n<p>&nbsp;<\/p>\n<p>\u2013\u00a0 Separation of duties<\/p>\n<\/div>\n<div>\n<p><strong>Clark-Wilson versus Biba<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 In Biba\u2019s model, UDI to CDI conversion is performed by trusted subject only (e.g., a security officer), but this is problematic for data entry function.<\/p>\n<p style=\"text-align: justify\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 In Clark-Wilson, TPs are specified for particular users and functions. Biba\u2019s model does not offer this level of granularity.<\/p>\n<\/div>\n<p><strong>Chinese Wall<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>Focus is on conflicts of interest.<\/p>\n<ul>\n<li>Principle: Users should not access the confidential information of both a client organization and one or more of its competitors.<\/li>\n<li>How it works<\/li>\n<\/ul>\n<p>\u2013\u00a0 Users have no \u201cwall\u201d initially.<\/p>\n<p>&nbsp;<\/p>\n<p>\u2013 Once any given file is accessed, files with competitor information become inaccessible.<\/p>\n<p>&nbsp;<\/p>\n<p>\u2013\u00a0 Unlike other models, access control rules change with user behavior<\/p>\n<ul>\n<li>This model provides access controls that can change dynamically depending upon a user\u2019s previous actions.<\/li>\n<\/ul>\n<ul>\n<li>The main goal of this model is to protect against conflicts of interests by user\u2019s access attempts.<\/li>\n<\/ul>\n<ul>\n<li>It is based on the information flow model, where no information can flow between subjects and objects in a way that would result in a conflict of interest.<\/li>\n<\/ul>\n<ul>\n<li>The model states that a subject can write to an object if, and only if, the subject cannot read another object that is in a different data set.<\/li>\n<\/ul>\n<div>\n<p><strong>Finite State Machine Models<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>Automata (=Finite State Machines) are a popular way<\/p>\n<p>&nbsp;<\/p>\n<p>Of modeling many aspects of computing systems.<\/p>\n<p>&nbsp;<\/p>\n<p>The essential features of these are then concepts of:<\/p>\n<p>&nbsp;<\/p>\n<p>\u2022\u00a0 State<\/p>\n<ul>\n<li>State transition<\/li>\n<\/ul>\n<p><strong>Bell-LaPadula (BLP) Model<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>BLP Structure Combines,<\/p>\n<ul>\n<li><em>Access permission matrices <\/em>for access control,<\/li>\n<\/ul>\n<ul>\n<li>a <em>Security lattice<\/em>, for security levels,<\/li>\n<\/ul>\n<ul>\n<li>an <em>Automaton<\/em>, for access operations.<\/li>\n<\/ul>\n<p>Security policies are reduced to relations in the BLP structure.<\/p>\n<\/div>\n<p><strong>BLP Model<\/strong><\/p>\n<ul>\n<li>A set of subjects <em>S<\/em><\/li>\n<\/ul>\n<ul>\n<li>A set of objects <em>O<\/em><\/li>\n<\/ul>\n<ul>\n<li>A set of access operations \u2264<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-348\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-77.jpg\" alt=\"\" width=\"417\" height=\"97\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-77.jpg 417w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-77-300x70.jpg 300w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-77-65x15.jpg 65w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-77-225x52.jpg 225w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-77-350x81.jpg 350w\" sizes=\"auto, (max-width: 417px) 100vw, 417px\" \/><\/p>\n<p><em>\u00a0-f<\/em><em>s<\/em> :<em> S\u2192L <\/em>gives the maximal security each subject can have,<\/p>\n<p>&nbsp;<\/p>\n<p><em>-f<\/em><em>c<\/em> :<em> S\u2192L <\/em>gives the current security level of each subject,<\/p>\n<p>&nbsp;<\/p>\n<p><em>-f<\/em><em>o<\/em> : O<em>\u2192L <\/em>gives the security classification objects.<\/p>\n<p>&nbsp;<\/p>\n<div>\n<p>We require : <em>f<\/em><em>c<\/em> \u2264 <em>f<\/em><em>s<\/em> , that is, the maximal level dominates the current level.<\/p>\n<p>&nbsp;<\/p>\n<p>Security policies: a state (<em>b, M, f<\/em> ) must satisfy,<\/p>\n<\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-349\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-78.jpg\" alt=\"\" width=\"443\" height=\"556\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-78.jpg 443w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-78-239x300.jpg 239w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-78-65x82.jpg 65w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-78-225x282.jpg 225w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-78-350x439.jpg 350w\" sizes=\"auto, (max-width: 443px) 100vw, 443px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-353\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-79.jpg\" alt=\"\" width=\"536\" height=\"544\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-79.jpg 536w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-79-296x300.jpg 296w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-79-65x66.jpg 65w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-79-225x228.jpg 225w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-79-350x355.jpg 350w\" sizes=\"auto, (max-width: 536px) 100vw, 536px\" \/><\/p>\n<div>\n<p><strong>The Biba Model<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>This model addresses integrity by using a state machine model in a similar way to BLP.<\/p>\n<p>&nbsp;<\/p>\n<p>It uses a lattice (L, \u2264) of integrity levels, and functions <em>f<\/em><em>s<\/em> : <em>S\u2192L<\/em> and <em>f<\/em><em>o<\/em><em>:O\u2192L<\/em> which assign integrity levels to subjects and objects.<\/p>\n<p>&nbsp;<\/p>\n<p>Unlike BLP there is no single high-level integrity policy.<\/p>\n<p>&nbsp;<\/p>\n<p>Instead, there is a variety of approaches.<\/p>\n<p>&nbsp;<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 The integrity policies guarantee that information only flows downwards.<\/p>\n<p>&nbsp;<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0 In particular, \u201cclean\u201d high level entities cannot be corrupted by \u201cdirty\u201d low level entities.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>The Biba Model \u2013 static integrity<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p><em>Simple integrity property <\/em>:<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>If a subject s can modify (alter) object then <em>f<\/em><em>s<\/em> <em>(s)<\/em> \u2265 <em>f<\/em><em>o<\/em> <em>(o)<\/em> (no-write up)<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><em>Integrity <\/em><em>*<\/em><em> &#8211; property <\/em>:<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>If a subject s can read (observe) object o then s can have write access to an object o\u2019 only if <em>f<\/em><em>o<\/em> <em>(o\u2019)<\/em> \u2264 <em>f<\/em><em>s<\/em> <em>(s)<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>These properties prevent clean subjects and objects from being contaminated by dirty information.<\/p>\n<p>&nbsp;<\/p>\n<\/div>\n<p><strong>The Biba Model \u2013 dynamic integrity<\/strong><\/p>\n<p>&nbsp;<\/p>\n<ol>\n<li><strong> Subject low watermark property:<\/strong><\/li>\n<\/ol>\n<p>Subject <em>s<\/em> can read (observe) an object <em>o<\/em> at any integrity level. The new integrity level of <em>s<\/em> is inf(<em>f<\/em><em>s<\/em><em>, f<\/em><em>o<\/em>(<em>o<\/em>)), where <em>f<\/em><em>s<\/em><em>(s)<\/em> and <em>f<\/em><em>o<\/em><em>(o)<\/em> are the integrity levels before the operation.<\/p>\n<p>&nbsp;<\/p>\n<ol start=\"2\">\n<li><strong> Object low watermark property:<\/strong><\/li>\n<\/ol>\n<p>Subject <em>s<\/em> can <em>modify<\/em> an object <em>o<\/em> at any integrity level. The new integrity level of <em>o<\/em> is inf(<em>f<\/em><em>s<\/em><em>, f<\/em><em>o<\/em>(<em>o<\/em>)), where <em>f<\/em><em>s<\/em><em>(s)<\/em> and <em>f<\/em><em>o<\/em><em>(o)<\/em> are the integrity levels before the operation.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Summary<\/strong><\/p>\n<ul>\n<li>Outlined the purpose of security models<\/li>\n<li>Discussed about various security models<\/li>\n<li>Discussed about the properties of security models<\/li>\n<\/ul>\n<table>\n<tbody>\n<tr>\n<td><strong>you can view video on Security Models<\/strong><\/td>\n<td><a href=\"https:\/\/youtu.be\/HqXq9Hgg8Qo\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-120\" src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"\" width=\"36\" height=\"36\" \/><\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-354 aligncenter\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/one.jpg\" alt=\"\" width=\"473\" height=\"253\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/one.jpg 473w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/one-300x160.jpg 300w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/one-65x35.jpg 65w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/one-225x120.jpg 225w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/one-350x187.jpg 350w\" sizes=\"auto, (max-width: 473px) 100vw, 473px\" \/><\/p>\n","protected":false},"author":3,"menu_order":26,"template":"","meta":{"_acf_changed":false,"pb_show_title":"on","pb_short_title":"","pb_subtitle":"","pb_authors":[],"pb_section_license":""},"chapter-type":[],"contributor":[],"license":[],"class_list":["post-347","chapter","type-chapter","status-publish","hentry"],"part":3,"_links":{"self":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/pressbooks\/v2\/chapters\/347","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/pressbooks\/v2\/chapters"}],"about":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/wp\/v2\/types\/chapter"}],"author":[{"embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/wp\/v2\/users\/3"}],"version-history":[{"count":7,"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/pressbooks\/v2\/chapters\/347\/revisions"}],"predecessor-version":[{"id":596,"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/pressbooks\/v2\/chapters\/347\/revisions\/596"}],"part":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/pressbooks\/v2\/parts\/3"}],"metadata":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/pressbooks\/v2\/chapters\/347\/metadata\/"}],"wp:attachment":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/wp\/v2\/media?parent=347"}],"wp:term":[{"taxonomy":"chapter-type","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/pressbooks\/v2\/chapter-type?post=347"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/wp\/v2\/contributor?post=347"},{"taxonomy":"license","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/wp\/v2\/license?post=347"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}