Authorization




CS166

Chris Pollett

Oct 22, 2012

Outline

Authentication vs Authorization

System Certification

Orange Book

Orange Book Outline

D and C Divisions

B Division

B and A Divisions

Orange Book: Last Word

Quiz

Which of the following is true?

  1. Dictionary attacks are not much of a threat if the password file is copied -- provided passwords are hashed and salts are used.
  2. The Equal Error Rate of a biometric is when the insult rate equals the fraud rate.
  3. A CSRF attack is an attack against password generators.

Common Criteria

EAL

EAL 1 thru 7

Common Criteria

Classic Authorization

Classic authorization enforced by

Lampson's Access Control Matrix

Lampson Access matrix

Are You Allowed to Do That?

Access Control Lists (ACLs)

Lampson Matrix, ACL example

Capabilities (or C-Lists)

Lampson Matrix, Capabilties example

ACLs vs Capabilities

ACLs versus Capabilties example

Confused Deputy

Confused Deputy Matrix

ACL's and Confused Deputy

Confused Deputy Transaction

Confused Deputy

ACLs vs Capabilities

Classifications and Clearances

We are now going to start looking at Multilevel Security (MLS) Models.

Clearances and Classification

Subjects and Objects