Toward a Medium-Robustness Separation Kernel Protection Profile
Author
DeLong, Rance J.
Nguyen, Thuy D.
Irvine, Cynthia E.
Levin, Timothy E.
Date
2007-12-14Metadata
Show full item recordAbstract
A protection profile for high-robustness separation kernels has recently been validated and several implementations are under development. However, medium-robustness
separation kernel development efforts have no protection profile, although the US Government has published guidance for authoring such a profile. As a step toward a protection profile, a set of security requirements for medium-robustness separation kernels is proposed. These requirements result from an informal, yet principled, approach. By bracketing the problem with appropriate reference points and elaborating a method for interpolating the requirements both a measure of uniformity
and a basis for further discussion are achieved. Our reference points include the high robustness protection profile, the existing medium robustness consistency instruction, and our familiarity with the nuances of separation kernels. This practitioner-oriented study is intended to advance the prevailing practices for commercial software development, which presently falls far short of the rigor needed for either high-robustness or medium-robustness systems. These requirements represent an incremental improvement in the pursuit of secure software � and is intended to be a step forward on the road to higher assurance.
Description
Annual Computer Security Applications Conference (ACSAC)
Rights
This publication is a work of the U.S. Government as defined in Title 17, United States Code, Section 101. Copyright protection is not available for this work in the United States.Related items
Showing items related by title, author, creator and subject.
-
High Robustness Requirements in a Common Criteria Protection Profile
Nguyen, Thuy D.; Levin, Timothy E.; Irvine, Cynthia E. (John Wiley and Sons, Hoboken, NJ, 2006,, 2006-04-00);The development of a Common Criteria protection profile for high-robustness separation kernels requires explicit modifications of several Common Criteria requirements as well as extrapolation from existing (e.g., medium ... -
A Note on High Robustness Requirements for Separation Kernels
Levin, Timothy E.; Irvine, Cynthia E.; Nguyen, Thuy D. (International Common Criteria Conference (ICCC 05), September 28-29, 2005., 2005-09-28);The development of a protection profile for high-robustness separation kernels requires explicit modifications of several Common Criteria requirements as well as extrapolation from existing (e.g., medium assurance) guidance ... -
Assurance Considerations for a Highly Robust TOE
Nguyen, Thuy D.; Irvine, Cynthia E.; Levin, Timothy E.; McEvilley, Michael (International Common Criteria Conference (ICCC), Rome, Italy, September 2007, 2007-09-01);The U.S. Government Protection Profile for Separation Kernels in Environments Requiring High Robustness (SKPP) is undergoing evaluation. During its authoring process, new extended functional and assurance requirements were ...