The Center for Education and Research in Information Assurance and Security (CERIAS)

The Center for Education and Research in
Information Assurance and Security (CERIAS)

Reports and Papers Archive


Browse All Papers »       Submit A Paper »

Spoolers and Links, Version 4.1

Matt Bishop
Added 2002-07-26

Sendmail Wizardry

Matt Bishop
Added 2002-07-26



The Seaview Formal Security Policy Model

Teresa F. Lunt, Dorothy E. Denning, Roger R. Schell, Mark Heckman, William R. Shockley

This report describes a formal security policy model for a secure relational database system.  This model is intended to meet the formal model requirement specified in the DoD Trusted COmputer System Evaluation Criteria.  The model is formulated in two layers, one corresponding to a reference monitor thta enforces mandatory security, and the second defining multilevel relations and formulazing policies for labeling new and derived data, data consistency, discretionary security, and transaction consistency.  The development of a formal security policy model is the second task of the SeaView Project to design a multilevel secure database system meeting the Criteria for Class A1.

Added 2002-07-26


The Bulgarian and Soviet Virus Factories

Vesselin Bontchev
Added 2002-07-26


Condor Technical Summary

Allan Bricker, Michael Litzkow, Miron Livny
Added 2002-07-26



A Taxonomy of Computer Program Security Flaws

Alan R. Bull, Carl E. Landwehr, John P. McDermott, William S. Choi
Added 2002-07-26

The Need for Tripwire

Brian Bullen
Added 2002-07-26

The Scope of a Logic of Authentication

Michael Burrows, Martin Abadi, Roger Needham
Added 2002-07-26

Protecting NATO Information Systems in the 21st Century

NATO

Common NATO interest in information defense.  To forge a common understanding of problems, research issues, and practical ways ahead for the protection of NATO and NATO allied information systems and infrastructure on the eve of the new millennium.

Added 2002-07-26