Designing & Operating a Multilevel Security Network Using Standard Commercial Products
نویسنده
چکیده
In March 1996, the 2nd Bomb Wing, Barksdale AFB, LA declared initial operational capability on the first multilevel security system (a.k.a. multilevel network or MLN) using only low-cost commercially available products. The MLN integrates the many sources and sensitivities of information (secret and unclassified) necessary for a commander to effectively command and control global bombing operations. We developed and implemented the MLN for two reasons: • First, to reduce the number of terminals each command and control center (C) operator must use. Multiple non-integrated systems and the technical necessity of separating classified and unclassified systems have created enormous system overhead and operator training inefficiencies base and Air Force wide. In many operational areas, real estate is at a premium and reducing required floor or table space would also improve the work environment. Reducing the number of garrison terminals needed could eventually affect deployed operations, where less combat support weight means more combat weight could be transported. • Second, to reduce operational costs. Costs are reduced by buying commercial products. Savings are enhanced by the commonality of parts among various operational systems as they connect to the network. Training costs will decrease as new operational systems are added to the network because a common human-computer interface would exist between systems. The MLN is working and the single most expensive item is the operating system at roughly $3,000 each ($1900 each with a site license). The MLN is already a model for other C centers and continuous refinement will only improve its desirability.
منابع مشابه
MLS DBMS Interoperability Study
Interoperability among heterogeneous databases is a fundamental requirement of many emerging Department of Defense (DoD) systems. Often these systems also have requirements for Multilevel-Secure (MLS) operation, where data is labeled to reflect its sensitivity level (e.g., UNCLASSIFIED, SECRET, etc.). The Air Force Rome Laboratory MLS Database Management System (DBMS) Interoperability Study has...
متن کاملData Integrity Limitations in in Hybrid Security Architectures
We discuss a class of computer/network architectures that supports multilevel security and commercial applications, while utilizing primarily commercial-off-the-shelf (COTS) workstations, operating systems and hardware components. We show that a property of these architectures is that, while they are capable of supporting multilevel confidentiality policies, they do not generally support partia...
متن کاملAn introduction to multilevel secure relational database management systems
Multilevel Security (MLS) is a capability that allows information with different classifications to be available in an information system, with users having different security clearances and authorizations, while preventing users from accessing information for which they are not cleared or authorized. It is a security policy that has grown out of research and development efforts funded mostly b...
متن کاملThe Speci cation and Implementation of ` Commercial ' Security RequirementsIncluding
A framework for the speciication of security policies is proposed. It can used to formally specify conndentiality and integrity policies, the latter can be given in terms of Clark-Wilson style access triples. The framework extends the Clark-Wilson model in that it can be used to specify dynamic segregation of duty. For application systems where security is critical, a mul-tilevel security based...
متن کاملMultilevel security in tightly coupled military systems: Virtualization as a path to MLS
Security is a major cost driver in military systems and is of particular concern when using commercial network protocols in the military environment. MLS systems may be employed to reduce the amount of application software that must be secured and certified at the highest level, avoiding the expense and complexity associated with maintaining the entire system at the highest level of security. T...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 1996