DocumentCode
1534907
Title
Compartmented mode workstation: prototype highlights
Author
Berger, Jeffrey L. ; Picciotto, Jeffrey ; Woodward, John P L ; Cummings, Paul T.
Author_Institution
MITRE Corp., Bedford, MA, USA
Volume
16
Issue
6
fYear
1990
fDate
6/1/1990 12:00:00 AM
Firstpage
608
Lastpage
618
Abstract
The primary goal of the MITRE compartmented mode workstation (CMW) project was to articulate the security requirements that workstations must meet to process highly classified intelligence data. As a basis for the validity of the requirements developed, a prototype was implemented which demonstrated that workstations could meet the requirements in an operationally useful manner while still remaining binary compatible with off-the-shelf software. The security requirements not only addressed traditional security concerns but also introduced concepts in areas such as labeling and the use of a trusted window management system. The CMW labeling paradigm is based on associating two types of security labels with objects: sensitivity levels and information labels. Sensitivity levels describe the levels at which objects must be protected. Information labels are used to prevent data overclassification and also provide a mechanism for associating with data those markings that are required for accurate data labeling, but which play no role in access control decisions. The use of a trusted window manager allows users to easily operate at multiple sensitivity levels and provides a convenient mechanism for communicating security information to users in a relatively unobtrusive manner
Keywords
security of data; software engineering; workstations; MITRE compartmented mode workstation; accurate data labeling; binary compatible; data overclassification prevention; highly classified intelligence data; information labels; markings; multiple sensitivity levels; objects; security labels; security requirements; sensitivity levels; trusted window management system; Access control; Computer security; Data security; Environmental economics; Information security; Labeling; Power generation economics; Protection; Prototypes; Workstations;
fLanguage
English
Journal_Title
Software Engineering, IEEE Transactions on
Publisher
ieee
ISSN
0098-5589
Type
jour
DOI
10.1109/32.55089
Filename
55089
Link To Document