Application-oriented confidentiality and integrity dynamic union security model based on MLS policy

  • Mingfu Xue*
  • , Aiqun Hu
  • , Chunlong He
  • *Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

Abstract

We propose a new security model based on MLS Policy to achieve a better security performance on confidentiality, integrity and availability. First, it realizes a combination of BLP model and Biba model through a two-dimensional independent adjustment of integrity and confidentiality. And, the subject's access range is adjusted dynamically according to the security label of related objects and the subject's access history. Second, the security level of the trusted subject is extended to writing and reading privilege range respectively, following the principle of least privilege. Third, it adjusts the objects' security levels after adding confidential information to prevent the information disclosure. Fourth, it uses application-oriented logic to protect specific applications to avoid the degradation of security levels. Thus, it can ensure certain applications operate smoothly. Lastly, examples are presented to show the effectiveness and usability of the proposed model.

Original languageEnglish
Pages (from-to)1694-1697
Number of pages4
JournalIEICE Transactions on Information and Systems
VolumeE95-D
Issue number6
DOIs
StatePublished - Jun 2012
Externally publishedYes

Keywords

  • Application-oriented logic
  • Confidentiality and integrity
  • Least privilege
  • Multi-level security policy
  • Security model

Fingerprint

Dive into the research topics of 'Application-oriented confidentiality and integrity dynamic union security model based on MLS policy'. Together they form a unique fingerprint.

Cite this