A multilevel secure constrained intrusion detection system prototype
dc.contributor.advisor | Irvine, Cynthia E. | |
dc.contributor.advisor | Nguyen, Thuy D. | |
dc.contributor.author | Ang, Kah Kin. | |
dc.date.accessioned | 2012-03-14T17:43:57Z | |
dc.date.available | 2012-03-14T17:43:57Z | |
dc.date.issued | 2010-12 | |
dc.identifier.uri | https://hdl.handle.net/10945/5026 | |
dc.description.abstract | The Monterey Security Architecture (MYSEA) provides a distributed multilevel secure (MLS) environment consisting of a MLS local area network (LAN) and multiple single-level networks. The MYSEA server enforces a mandatory access control policy to ensure that users can only access data for which they are authorized. Intrusion detection systems (IDS) placed on a single-level network can store the alerts in the IDS databases at the same classification level as the network being monitored. As most databases do not support the enforcement of mandatory security policies, access to these databases is restricted to singlelevel access only. Thus, administrators are not presented with a coherent view of IDS alerts from all of the connected networks. The objective of this thesis is to design a database proxy to allow administrators to view and analyze IDS information at multiple classification levels while enforcing the systems overall mandatory policy. Based on the derived concept of operations and the requirements, a design for the database proxy that mediates access to databases at different levels was conceived. A prototype database proxy was implemented along with modifications to a web-based analysis tool to allow the viewing and analysis of IDS information at multiple classification levels. | en_US |
dc.description.uri | http://archive.org/details/amultilevelsecur109455026 | |
dc.format.extent | xviii, 97 p. ; | en_US |
dc.publisher | Monterey, California. Naval Postgraduate School | en_US |
dc.rights | This publication is a work of the U.S. Government as defined in Title 17, United States Code, Section 101. Copyright protection is not available for this work in the United States. | en_US |
dc.subject.lcsh | Computer science | en_US |
dc.subject.lcsh | Proxy | en_US |
dc.title | A multilevel secure constrained intrusion detection system prototype | en_US |
dc.type | Thesis | en_US |
dc.contributor.corporate | Naval Postgraduate School (U.S.) | |
dc.contributor.department | Computer Science | |
dc.description.service | Naval Postgraduate School author (civilian) | en_US |
dc.identifier.oclc | 698376301 | |
etd.thesisdegree.name | M.S. | en_US |
etd.thesisdegree.level | Masters | en_US |
etd.thesisdegree.discipline | Computer Science | en_US |
etd.thesisdegree.grantor | Naval Postgraduate School | en_US |
etd.verified | no | en_US |
dc.description.distributionstatement | Approved for public release; distribution is unlimited. |
Files in this item
This item appears in the following Collection(s)
-
1. Thesis and Dissertation Collection, all items
Publicly releasable NPS Theses, Dissertations, MBA Professional Reports, Joint Applied Projects, Systems Engineering Project Reports and other NPS degree-earning written works.