Design and assurance strategy for the NRL Pump

被引:11
作者
Kang, MH [1 ]
Moore, AP [1 ]
Moskowitz, IS [1 ]
机构
[1] USN, Res Lab, Ctr High Assurance Comp Syst, Washington, DC 20375 USA
关键词
Fault tolerant computer systems - Security of data;
D O I
10.1109/2.666843
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Such systems suffer a host of disadvantages: They cost too much, lack user-friendly features and development environments, take too much time to evaluate and certify, and do not scale well for secure distributed computing. This lack of satisfactory security solutions is disturbing in light of the trend toward open and distributed computing, which increases a system's vulnerability to attack. The authors propose basing security solutions instead on a multiple single-level security architecture, which uses commercial (nonsecure) products for general-purpose computing and special-purpose high-assurance devices to separate data at different security levels. A multiple single-level architecture is a viable and practical solution to distributed multilevel secure computing. The keystone of this architecture is a trusted device that "pumps" data from a low security level to a higher one. The authors describe the software design and assurance argument strategy for this device, the Network NRL Pump, which can be used in any multilevel secure distributed architecture.
引用
收藏
页码:56 / +
页数:11
相关论文
共 10 条
[1]   STATEMATE - A WORKING ENVIRONMENT FOR THE DEVELOPMENT OF COMPLEX REACTIVE SYSTEMS [J].
HAREL, D ;
LACHOVER, H ;
NAAMAD, A ;
PNUELI, A ;
POLITI, M ;
SHERMAN, R ;
SHTULLTRAURING, A ;
TRAKHTENBROT, M .
IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 1990, 16 (04) :403-414
[2]  
KANG M, 1996, IEEE T SOFTWARE MAY, P329
[3]  
KANG M, 1997, 5540977991 NRL
[4]  
KANG M, 1996, P HASE 96, P198
[5]   An architecture for multilevel secure interoperability [J].
Kang, MH ;
Froscher, JN ;
Moskowitz, IS .
13TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 1997, :194-204
[6]  
KANG MH, 1993, P 1 ACM C COMP COMM, P119, DOI DOI 10.1145/168588.168604
[7]  
KROMODIMOELJO S, 1993, CP91540243 ORA
[8]  
Moore A.P., 1996, P 11 ANN C COMP ASS, P187
[9]  
Moskowitz I., 1994, P COMPASS 94, P235
[10]  
*REL SOFTW TECHN, 1996, WHIT DEEP COV US REF