Towards Formal Evaluation of a High-Assurance Guard
نویسندگان
چکیده
A transfer guard built on a high-assurance multilevel secure (MLS) trusted computing base (TCB) must be a trusted subject with the capability to perform downgrades not otherwise permitted by the MLS security policy. Formal evaluations of MLS systems containing trusted subjects are complicated when the trusted subjects are evaluated as part of a monolithic TCB. While welldeveloped techniques of “TCB subsets” and “TCB partitions” for composing MLS systems exist, approaches for applying these techniques for reasoning about a guard downgrade policy are not as well-developed. If the trusted downgrade process must be evaluated as part of the TCB, an inability to adequately reason about the downgrade policy would make it difficult to reason about the policy implemented by the system as a whole. And if trusted subjects cannot be evaluated separately and composed with the underlying TCB, that could lead to to expensive and repetitive certification and recertification of the system when downgrade policies change. A necessary pre-requisite for feasible evaluation of high-assurance transfer guard systems is to be able to separately evaluate the assurance of the underlying system and the implementation of the downgrade policy. This paper suggests an approach to extending the well-developed technique of “balanced assurance” to the formal evaluation of high-assurance transfer guards that could permit the downgrade function to be evaluated separately from the underlying TCB and then composed with it into an overall system.
منابع مشابه
Introduction to the Guardol Programming Language and Verification System
Guardol is a high-level programming language intended to facilitate the construction of correct network guards. The Guardol system generates Ada code from Guardol programs. It also provides specification and automated verification support: guard specifications are formally translated to SMT format and passed to a new decision procedure dealing with functions over tree-structured data. The resul...
متن کاملTeachers' Attitudes towards Teaching in Formal vs. Informal ELT Contexts
Up to now, many studies have been done to show the origin of attitudes and their relationships with behaviors or actions. Some of those works have focused on students' attitudes and some have introduced the various contexts of language teaching and learning. These studies were enough to give a new impetus for conducting the present investigation. This paper investigated the teachers' attitudes ...
متن کاملA High-assurance, Virtual Guard Architecture1
Although one senior security professional has emphasized that “it is unconscionable to use overly weak components” in a multilevel security (MLS) context, the majority of current transfer guards do exactly that. Basic guard technology is well-developed and has a long history, but most guards are built on low-assurance systems vulnerable to software subversion, and the lack of assurance limits t...
متن کاملEvaluation the effects of feeding Poecilia reticulata by Nauplii Guard and Artemia Guard (technology of domestic production for Artemia preservative based on plant extracts) on the breeder's mortality, production of breeding larvae and larval surviva
In this study, the effect of Nauplius Artemia (Nauplii Guard) and adult Artemia (Artemia Guard) in the preservative based on hydro alcoholic extract of Melissa Officinalis and Allium sativum, in order to introduce new Artemia products as aquatic food with domestic production capacity for use in ornamental fish breeding centers. Its effect on the rates of reproductive mortality, reproduction and...
متن کاملHigh Assurance Software Development
The purpose of this paper is describe how to make software assurance a part of a science of security. Software assurance as practiced is a grab-bag of techniques, heuristics, and lessons learned from earlier failures. Given the importance of software to critical infrastructures (electricity, banking, medicine), this is an untenable situation; the smooth functioning of our society depends on thi...
متن کامل