Composing a High-assurance Infrastructure out of Tcb Components

نویسندگان

  • Mark R. Heckman
  • Roger R. Schell
چکیده

U.S. Government agencies and major vendors are actively attempting to secure critical infrastructure networks, but those efforts depend on patching unsecure, commodity systems, installing add-on security appliances, and applying other industry “best practices” that are ineffective against new attacks and software subversion. This has unfortunately led to the conclusion that it is impossible to secure critical infrastructure networks and even that a completely new, “alternative” Internet is needed. These conclusions disregard known and proven techniques for building secure, high-assurance, trusted systems – techniques developed as a result of years of research and engineering experience and systematically codified in the Trusted Computer System Evaluation Criteria (TCSEC) and related documents. Those techniques have not since been improved upon or adequately replaced, not even by the more recent Common Criteria for Information Technology Security Evaluation. In this paper, we sketch how the trusted systems technology codified in the TCSEC can be applied today to create a secure infrastructure network.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Towards Formal Evaluation of a High-Assurance Guard

A transfer guard built on a high-assurance multilevel secure (MLS) trusted computing base (TCB) must be a trusted subject with the capability to perform downgrades not otherwise permitted by the MLS security policy. Formal evaluations of MLS systems containing trusted subjects are complicated when the trusted subjects are evaluated as part of a monolithic TCB. While welldeveloped techniques of ...

متن کامل

A multilevel file system for high assurance

The designs of applications for multilevel systems cannot merely duplicate those of the untrusted world When applications are built on a high assurance base they will be constrained by the underlying policy en forcement mechanism Consideration must be given to the creation and management of multilevel data struc tures by untrusted subjects Applications should be de signed to rely upon the TCB s...

متن کامل

A Multilevel File System for High Assurancey

The designs of applications for multilevel systems cannot merely duplicate those of the untrusted world. When applications are built on a high assurance base, they will be constrained by the underlying policy enforcement mechanism. Consideration must be given to the creation and management of multilevel data structures by untrusted subjects. Applications should be designed to rely upon the TCB'...

متن کامل

A Comparison between Transcutaneous Bilirubin (TcB) and Total Serum Bilirubin (TSB) Measurements in Term Neonates

Background: Transcutaneous bilirubinometry (TCB) is a simple method for estimating bilirubin levels in neonates. This method is noninvasive, quick, and painless. We aimed to compare serum and cutaneous bilirubin measurements in term neonates.Method: In this descriptive cross-sectional study, 200 neonates with icter with birth weights of at least 2500 grams were studied. TCB was measured using a...

متن کامل

On High-Assurance Information-Flow-Secure

Early work on information flow security sought to develop theories for proving the absence of unwanted information leakage in high-assurance systems, like those that process classified data. Decades later, modern security-critical systems are more prevalent, face greater security threats, but are rarely formally proved to be information-flow secure, not least because doing so remains fairly exp...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2011