U4. Bell-LaPladula

Description

Masters Comp Sec Mind Map on U4. Bell-LaPladula, created by Craig Parker on 30/11/2013.
Craig Parker
Mind Map by Craig Parker, updated more than 1 year ago
Craig Parker
Created by Craig Parker over 10 years ago
39
0

Resource summary

U4. Bell-LaPladula
  1. a confidentiality policy that forbids information flows from ‘high’ security levels down to ‘low’ security levels
    1. only considers information flows that occur when a subject observes or alters an object
    2. BLP is a state machine model
      1. To define the BLP State Set consider 3 separate aspects
        1. Current access operations
          1. Current assignment of security levels.
            1. Current permissions.
          2. Access permissions are defined through an access control matrix & through security levels that form a partial ordering
            1. 2 Mandatory BLP policies.
              1. Simple security property (no read-up)
                1. ss-property simply means that a subject is not allowed to observe (read) an object of higher security level than itself
                  1. First BLP policy forbids information flows from ‘high’ to ‘low’ security levels
                    1. when a subject reads an object, the information flow is from object to subject
                      1. natural to prevent low-level subjects reading high-level objects
                        1. for example, a user who has been cleared to 'secret' level is not allowed to read 'top secret' document
                2. Star Property (no write down)
                  1. ss-property is fine for 'observe' activities, but it does not prevent improper declassification of information
                    1. does not prevent a high-level subject reading a high-level object and copying the information to a lower level object and so possibly allowing a low-level subject to read this object.
                      1. Star property is in place to prevent this
                    2. Problems with no write down
                      1. Using the Maximum Security level no write down would mean that Higher level users could not communicate with lower level
                        1. using this in the *-property we allow the temporary downgrade of a subject
                          1. Therefore current security level is used
                    3. Trusted Subjects
                      1. trusted subjects as subjects that are permitted to violate the *-property
                        1. Star property can be redefined and demanded for only subjects that are not trusted
                          1. Trusted subjects may violate security policies!
                            1. a trusted subject may be in a position to inflict damage
                              1. Trusted subjects may not be trustworthy
                                1. A trustworthy subject could be defined as one that will not inflict damage!
                      2. Discretionary security (ds) property:
                        1. ds-property only permits operations that are expressly stated in the access control matrix
                        Show full summary Hide full summary

                        Similar

                        U2.1 Comp Sec: deals with prevention & detection of unauthorised actions by users of a comp system
                        Craig Parker
                        U3.2 Access Control Structures
                        Craig Parker
                        U3. Labels & Access Control
                        Craig Parker
                        U2.2 Fundamentals
                        Craig Parker
                        U3.1 Access Control
                        Craig Parker
                        U3.3 Administration
                        Craig Parker
                        U4. Security Models & Policy
                        Craig Parker
                        U4. Biba
                        Craig Parker
                        U4. Further Aspects of BLP
                        Craig Parker
                        U4. Harrison–Ruzzo–Ullman
                        Craig Parker
                        U4. Chinese Wall
                        Craig Parker