Showing posts with label Locus & biba. Show all posts
Showing posts with label Locus & biba. Show all posts
Saturday, January 11, 2014
Biba’s Model
• Similar
to Bell-LaPadula model
–
s Î S
can read o Î O iff i(s) ¡Â i(o)
–
s Î S
can write to o Î O iff i(o) ¡Â i(s)
–
s1 Î
S can execute s2 Î S
iff i(s2) ¡Â i(s1)
• Add
compartments and discretionary controls to get full dual of Bell-LaPadula model
• Information
flow result holds
–
Different proof, though
• Actually
the “strict integrity model” of Biba’s set of models
LOCUS and Biba
•
Goal: prevent untrusted software
from altering data or other software
•
Approach: make levels of trust
explicit
– credibility
rating based on estimate of software’s
trustworthiness (0 untrusted, n highly trusted)
– trusted
file systems contain software with a single
credibility level
– Process
has risk level or highest credibility level at which process can execute
– Must
use run-untrusted command to run software at lower credibility level
Biba Integrity
Model
• Set of subjects S, objects O, integrity levels I, relation ¡Â Í I ´ I holding when second dominates first
• min: I ´ I ® I returns lesser of integrity levels
• i: S È O ® I gives integrity level of entity
• r:
S ´ O means s Î
S can read o Î O
• w,
x defined similarly
Intuition for
Integrity Levels
• The
higher the level, the more confidence
– That
a program will execute correctly
– That
data is accurate and/or reliable
• Note
relationship between integrity and trustworthiness
• Important
point: integrity levels are not security levels
Subscribe to:
Posts (Atom)