-
CSE543 - Introduction to Computer and Network Security Page
CSE543 - Introduction to Computer and Network Security Module: Mandatory Access Control
Professor Trent Jaeger
1
CSE543 - Introduction to Computer and Network Security Module: - - PowerPoint PPT Presentation
CSE543 - Introduction to Computer and Network Security Page
1
CSE543 - Introduction to Computer and Network Security Page
2
CSE543 - Introduction to Computer and Network Security Page
3
CSE543 - Introduction to Computer and Network Security Page
4
CSE543 - Introduction to Computer and Network Security Page
5
CSE543 - Introduction to Computer and Network Security Page
6
CSE543 - Introduction to Computer and Network Security Page
O1 O2 O3 J R RW RW S2
RW S3
RW
7
CSE543 - Introduction to Computer and Network Security Page
8
CSE543 - Introduction to Computer and Network Security Page
O1 O2 O3 J R RW RW S2
RW S3
RW
9
CSE543 - Introduction to Computer and Network Security Page
10
CSE543 - Introduction to Computer and Network Security Page
11
CSE543 - Introduction to Computer and Network Security Page
12
CSE543 - Introduction to Computer and Network Security Page
13
CSE543 - Introduction to Computer and Network Security Page
O1 O2 O3 J1 R RW
RW
14
CSE543 - Introduction to Computer and Network Security Page
15
CSE543 - Introduction to Computer and Network Security Page
16
CSE543 - Introduction to Computer and Network Security Page
than they are
17
CSE543 - Introduction to Computer and Network Security Page
18
CSE543 - Introduction to Computer and Network Security Page
19
CSE543 - Introduction to Computer and Network Security Page
20
CSE543 - Introduction to Computer and Network Security Page
21
CSE543 - Introduction to Computer and Network Security Page
22
CSE543 - Introduction to Computer and Network Security Page
23
CSE543 - Introduction to Computer and Network Security Page
24
CSE543 - Introduction to Computer and Network Security Page
25
CSE543 - Introduction to Computer and Network Security Page
26
Bob: CONF., {INTEL}) Charlie: TS, {CRYPTO, NUC, INTEL}) Alice: (SEC., {CRYTPO, NUC}) DocA: (CONFIDENTIAL, {INTEL}) DocB: (SECRET, {CRYPTO}) DocC: (UNCLASSIFIED, {NUC})
CSE543 - Introduction to Computer and Network Security Page
27
CSE543 - Introduction to Computer and Network Security Page
(a monk may write a prayer book that can be read by commoners, but not one to be read by a high priest).
monk may read a book written by the high priest, but may not read a pamphlet written by a lowly commoner).
28
CSE543 - Introduction to Computer and Network Security Page
29
Bob: (CONF., {INTEL}) Charlie: (TS, {CRYPTO, NUC, INTEL}) Alice: (SEC., {CRYTPO, NUC}) DocA: (CONFIDENTIAL, {INTEL}) DocB: (SECRET, {CRYPTO}) DocC: (UNCLASSIFIED, {NUC})
CSE543 - Introduction to Computer and Network Security Page
30
CSE543 - Introduction to Computer and Network Security Page
31
CSE543 - Introduction to Computer and Network Security Page
32
CSE543 - Introduction to Computer and Network Security Page
33
CSE543 - Introduction to Computer and Network Security Page
34
CSE543 - Introduction to Computer and Network Security Page
35
CSE543 - Introduction to Computer and Network Security Page
36
CSE543 - Introduction to Computer and Network Security Page
O1 O2 O3 J R R RW S2
RW S3
RW
37
CSE543 - Introduction to Computer and Network Security Page
38
CSE543 - Introduction to Computer and Network Security Page
– RWX assigned by file owners
39
CSE543 - Introduction to Computer and Network Security Page
40
CSE543 - Introduction to Computer and Network Security Page
41
secret secret
unclassified unclassified
trusted trusted untrusted untrusted
read read read read read read read read read read write write write write write write write
File: newfile
Process: newproc
Labeling State
Process:
File: acct
write
Transition State Protection State
CSE543 - Introduction to Computer and Network Security Page
42
CSE543 - Introduction to Computer and Network Security Page
43
CSE543 - Introduction to Computer and Network Security Page
44