DocumentCode :
2350960
Title :
PRISM: Program Replication and Integration for Seamless MILS
Author :
Owen, Chris ; Grove, Duncan ; Newby, Tristan ; Murray, Alex ; North, Chris ; Pope, Michael
Author_Institution :
C3I Div., Defence Sci. & Technol. Organ., Edinburgh, SA, Australia
fYear :
2011
fDate :
22-25 May 2011
Firstpage :
281
Lastpage :
296
Abstract :
We describe how to combine a minimal Trusted Computing Base (TCB) with polyinstantiated and slightly augmented Commercial Off The Shelf (COTS) software programs in separate Single Level Secure (SLS) partitions to create MultiLevel Secure (MLS) applications. These MLS applications can coordinate fine grained (intra-document) Bell LaPadula (BLP) [6] separation between information at multiple security levels. The untrusted COTS programs in the SLS partitions send at-level file edits as diff transactions to the TCB. The TCB verifies that BLP semantics will be observed and then patches these transactions into its canonical representation of the file. Finally, it releases appropriately filtered versions back to each SLS partition for re-assembly into the COTS program´s standard file format. Furthermore, by judiciously restricting how the user can interact with the system the multiple SLS instantiations of the COTS program can be made to appear as if they are a single MLS instantiation. We demonstrate the utility of this approach using Microsoft Word and DokuWiki.
Keywords :
security of data; BLP; Bell LaPadula; COTS; Commercial Off The Shelf; DokuWiki; MLS; Microsoft Word; MultiLevel Secure; PRISM; SLS; TCB; filtered versions; program replication and integration for seamless MILS; single level secure; software programs; trusted computing base; Computer architecture; Internet; Monitoring; Operating systems; Security; Three dimensional displays; Application virtualization; Computer security; Data security; Data storage systems; File systems; Information entropy; Information security; Military computing; Multilevel systems; Software architecture;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Security and Privacy (SP), 2011 IEEE Symposium on
Conference_Location :
Berkeley, CA
ISSN :
1081-6011
Print_ISBN :
978-1-4577-0147-4
Electronic_ISBN :
1081-6011
Type :
conf
DOI :
10.1109/SP.2011.15
Filename :
5958035
Link To Document :
بازگشت