Separation and Integration in MILS (The MILS Constitution)
نویسنده
چکیده
We describe the MILS approach to design, construction, integration, and evaluation of secure systems. The crucial feature of the MILS approach is that it separates the problems of enforcing security policy from those of securely sharing resources. MILS design proceeds in two steps: first, we develop a logical security policy architecture in which the system is deconstructed into interacting components in such a way that the trusted components are as simple as possible; second, we allocate components of the policy architecture to resources that are securely shared through mechanisms for logical separation. MILS identifies certain standard resources such as processors, networks, consoles, and file systems and publishes protection profiles for their logical separation; a COTS marketplace is developing that provides components evaluated to these profiles. Standard protection profiles and a marketplace for evaluated policy components (such as guards and filters) are also anticipated. Top-down design of a MILS system pays attention to existing protection profiles and strives to target these where appropriate. MILS construction can then incorporate COTS products evaluated to these protection profiles. MILS integration takes COTS and bespoke policy components and allocates them to physical resources that may be shared using COTS and bespoke components for separation in a way that is faithful to the original policy architecture. Security assurance and evaluation in MILS are assembled in the same way. That is so say, MILS security assurance is compositional : assurance for an overall system is derived from that of its components, integrated according to the specific policy architecture and resource allocation of the system concerned. Compositional design and assurance for a system property such as security is a radical innovation; we outline the justification for the MILS approach to accomplishing this.
منابع مشابه
A Formal Model for MILS Integration
The central artifact in a MILS system is its policy architecture. This identifies the logical components of the system and their channels for communications, and specifies which components are trusted. The components of the policy architecture are logically separate but may share physical resources under the control of trusted resource-sharing components, such as separation kernels or partition...
متن کاملManual in-line stabilization increases pressures applied by the laryngoscope blade during direct laryngoscopy and orotracheal intubation.
BACKGROUND Manual in-line stabilization (MILS) is recommended during direct laryngoscopy and intubation in patients with known or suspected cervical spine instability. Because MILS impairs glottic visualization, the authors hypothesized that anesthesiologists would apply greater pressure during intubations with MILS than without. METHODS Nine anesthetized and pharmacologically paralyzed patie...
متن کاملAn Evaluation and Certification Scheme for MILS
Over the past decade there has been steady activity and progress associated with MILS, a modular or “compositional” approach to the design and assurance of dependable systems [BDRS08, AFHOT06, VBC+05]. The idea is that the assured properties of MILS components have a form that allows the assurance of a MILS system to be based largely on that of its components [Rus08]. A coalition of vendors, go...
متن کاملThe MILS architecture for high-assurance embedded systems
High-assurance systems require a level of rigor, in both design and analysis, not typical of conventional systems. This paper provides an overview of the Multiple Independent Levels of Security and Safety (MILS) approach to high-assurance system design for security and safety critical embedded systems. MILS enables the development of a system using manageable units, each of which can be analyze...
متن کاملLaryngoscopy force, visualization, and intubation failure in acute trauma: should we modify the practice of manual in-line stabilization?
CERVICAL spine stabilization during transport and general care reduced secondary neurologic injury from 10– 25% to 1–3%. This experience led airway managers to adopt manual in-line stabilization (MILS) during direct laryngoscopy (DL). Although MILS is intuitively appealing, there is, as Santoni et al. state in this issue of ANESTHESIOLOGY, “no objective evidence of benefit.” Substantial ethical...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2008