An analysis of three kernel-based multilevel security architectures
Loading...
Authors
Irvine, Cynthia E.
Nguyen, Thuy D.
Advisors
Second Readers
Subjects
Computer architecture.
Information science.
Information science.
Date of Issue
2006-08
Date
Publisher
Monterey, California. Naval Postgraduate School
Language
Abstract
Various system architectures have been proposed for highly robust enforcement of multilevel security (MLS). This paper provides an analysis of the relative merits of three architectural types -- one based on a traditional separation kernel, another based on a security kernel, and a third based on a high-robustness separation kernel. We show that by taking advantage of commonly available hardware features, and incorporating security features required by the nascent Separation Kernel Protection Profile (SKPP), the latter architecture may provide several aspects of security and assurance that are not achievable with the other two.
Type
Technical Report
Description
Series/Report No
Department
Computer Science
Organization
Naval Postgraduate School (U.S.)
National Science Foundation (U.S.)
Defense Advanced Research Projects Agency (DARPA)
Identifiers
NPS Report Number
NPS-CS-06-001
Sponsors
Funding
Format
22 p.: ill.;28 cm.
Citation
Distribution Statement
Approved for public release; distribution is unlimited.
