Zusammenfassung der Ressource
Computer Security
U3 - Access Control
- What is access control?
- controls
interaction
- users
- system
resources
- security policy
- requirements
- organisational
- statutory
- Confidentiality
- Integrity
- Access Request
- Reference
Monitor
- System
Decision
- Subjects
- Objects
- passive
- active
- principal
- Access
Operations
- flow of
information
- read
- write
- execute
- append
- Unix
- read
- write
- execute
- Bell-LaPadula
- info flow policy
- access modes
- observe
- alter
- Structures
- AC Matrix
- s,o,a
- rows indexed
- AC List
- columns in AC
Matrix
- Capability
List
- rows in AC
Matrix
- subject-oriented
system
- Administration
- Groups
- layer between
subjects &
objects
- Roles
- collection of
access ops
assigned to
users
- Groups vs Roles
- Role Based
Access Control
(RBAC)
- Security Labels
- Protection
Rings
- QNX/Neutrino
microkernel
- VSTa
microkernel
- BLP
- confidentiality
policy
- all
conditions
satisfied
- 'need-to-know'
security latice
- label subjects & objects
- ordered pair of properties
- security lavel
- 'need-to-know'
categories