Access Control



tải về 2.19 Mb.
trang12/15
Chuyển đổi dữ liệu01.03.2024
Kích2.19 Mb.
#56689
1   ...   7   8   9   10   11   12   13   14   15
Lecture 04 Access control new (1)

EAL

  • Note: product with high EAL may not be more secure than one with lower EAL
    • Why?
  • Similarly, product with an EAL may not be any more secure than one without
    • Why?

EAL 1 thru 7

  • EAL1  functionally tested
  • EAL2  structurally tested
  • EAL3  methodically tested, checked
  • EAL4  designed, tested, reviewed
  • EAL5  semiformally designed, tested
  • EAL6  verified, designed, tested
  • EAL7  formally … (blah blah blah)

Common Criteria

  • EAL4 is most commonly sought
    • Minimum needed to sell to government
  • EAL7 requires formal proofs
    • Author could only find 2 EAL7 products…
  • Who performs evaluations?
    • Government accredited labs, of course (for a hefty fee, like 6 figures)

Authentication vs Authorization

  • Authentication  Are you who you say you are?
    • Restrictions on who (or what) can access system
  • Authorization  Are you allowed to do that?
    • Restrictions on actions of authenticated users
  • Authorization is a form of access control
  • Classic view of authorization…
    • Access Control Lists (ACLs)
    • Capabilities (C-lists)

Lampson’s Access Control Matrix


rx

rx

r





rx

rx

r

rw

rw

rwx

rwx

r

rw

rw

rx

rx

rw

rw

rw

OS
Accounting
program
Accounting
data
Insurance
data
Payroll
data
Bob
Alice
Sam
Accounting
program

tải về 2.19 Mb.

Chia sẻ với bạn bè của bạn:
1   ...   7   8   9   10   11   12   13   14   15




Cơ sở dữ liệu được bảo vệ bởi bản quyền ©hocday.com 2024
được sử dụng cho việc quản lý

    Quê hương