• DocumentCode
    3043089
  • Title

    Guidelines for Reference Monitors in Embedded INFOSEC Applications

  • Author

    Vallese, David C.

  • Author_Institution
    Harris Corporation, Rochester, NY 14610
  • fYear
    2007
  • fDate
    29-31 Oct. 2007
  • Firstpage
    1
  • Lastpage
    7
  • Abstract
    This paper addresses the enforcement of the principle of least privilege in embedded INFOSEC applications through the development of a security component, the Reference Monitor (RM). The concept of the principle of least privilege has been around since the mid 1970´s. The enforcement of this principle grants the most restrictive set of privileges for an authorized task. The RM component is useful for an embedment that is developed with a separation kernel that does not have built in security policies. The RM component resides outside the separation kernel and enforces a system-wide security policy through a combination of Discretionary Access Control (DAC) mechanisms and Mandatory Access Control (MAC) mechanisms. This paper discusses the architectural guidelines and the implementation of a RM component in an embedded INFOSEC application.
  • Keywords
    Access control; Application software; Communication system traffic control; Data security; Guidelines; Information security; Kernel; Protection; Protocols; Switches;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Military Communications Conference, 2007. MILCOM 2007. IEEE
  • Conference_Location
    Orlando, FL, USA
  • Print_ISBN
    978-1-4244-1513-7
  • Electronic_ISBN
    978-1-4244-1513-7
  • Type

    conf

  • DOI
    10.1109/MILCOM.2007.4455232
  • Filename
    4455232