Title :
Compartmented mode workstation: prototype highlights
Author :
Berger, Jeffrey L. ; Picciotto, Jeffrey ; Woodward, John P L ; Cummings, Paul T.
Author_Institution :
MITRE Corp., Bedford, MA, USA
fDate :
6/1/1990 12:00:00 AM
Abstract :
The primary goal of the MITRE compartmented mode workstation (CMW) project was to articulate the security requirements that workstations must meet to process highly classified intelligence data. As a basis for the validity of the requirements developed, a prototype was implemented which demonstrated that workstations could meet the requirements in an operationally useful manner while still remaining binary compatible with off-the-shelf software. The security requirements not only addressed traditional security concerns but also introduced concepts in areas such as labeling and the use of a trusted window management system. The CMW labeling paradigm is based on associating two types of security labels with objects: sensitivity levels and information labels. Sensitivity levels describe the levels at which objects must be protected. Information labels are used to prevent data overclassification and also provide a mechanism for associating with data those markings that are required for accurate data labeling, but which play no role in access control decisions. The use of a trusted window manager allows users to easily operate at multiple sensitivity levels and provides a convenient mechanism for communicating security information to users in a relatively unobtrusive manner
Keywords :
security of data; software engineering; workstations; MITRE compartmented mode workstation; accurate data labeling; binary compatible; data overclassification prevention; highly classified intelligence data; information labels; markings; multiple sensitivity levels; objects; security labels; security requirements; sensitivity levels; trusted window management system; Access control; Computer security; Data security; Environmental economics; Information security; Labeling; Power generation economics; Protection; Prototypes; Workstations;
Journal_Title :
Software Engineering, IEEE Transactions on