Show simple item record

dc.contributor.advisorIrvine, Cynthia E.
dc.contributor.advisorNguyen, Thuy D.
dc.contributor.authorAng, Kah Kin.
dc.date.accessioned2012-03-14T17:43:57Z
dc.date.available2012-03-14T17:43:57Z
dc.date.issued2010-12
dc.identifier.urihttps://hdl.handle.net/10945/5026
dc.description.abstractThe Monterey Security Architecture (MYSEA) provides a distributed multilevel secure (MLS) environment consisting of a MLS local area network (LAN) and multiple single-level networks. The MYSEA server enforces a mandatory access control policy to ensure that users can only access data for which they are authorized. Intrusion detection systems (IDS) placed on a single-level network can store the alerts in the IDS databases at the same classification level as the network being monitored. As most databases do not support the enforcement of mandatory security policies, access to these databases is restricted to singlelevel access only. Thus, administrators are not presented with a coherent view of IDS alerts from all of the connected networks. The objective of this thesis is to design a database proxy to allow administrators to view and analyze IDS information at multiple classification levels while enforcing the systems overall mandatory policy. Based on the derived concept of operations and the requirements, a design for the database proxy that mediates access to databases at different levels was conceived. A prototype database proxy was implemented along with modifications to a web-based analysis tool to allow the viewing and analysis of IDS information at multiple classification levels.en_US
dc.description.urihttp://archive.org/details/amultilevelsecur109455026
dc.format.extentxviii, 97 p. ;en_US
dc.publisherMonterey, California. Naval Postgraduate Schoolen_US
dc.rightsThis publication is a work of the U.S. Government as defined in Title 17, United States Code, Section 101. Copyright protection is not available for this work in the United States.en_US
dc.subject.lcshComputer scienceen_US
dc.subject.lcshProxyen_US
dc.titleA multilevel secure constrained intrusion detection system prototypeen_US
dc.typeThesisen_US
dc.contributor.corporateNaval Postgraduate School (U.S.)
dc.contributor.departmentComputer Science
dc.description.serviceNaval Postgraduate School author (civilian)en_US
dc.identifier.oclc698376301
etd.thesisdegree.nameM.S.en_US
etd.thesisdegree.levelMastersen_US
etd.thesisdegree.disciplineComputer Scienceen_US
etd.thesisdegree.grantorNaval Postgraduate Schoolen_US
etd.verifiednoen_US
dc.description.distributionstatementApproved for public release; distribution is unlimited.


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record