New security paradigms

John F. Dobson · 1993

Conventionalapproaches to computer securit,y lia.ve concentrated on defining securit.y in t,erms of a.ccess t,o resources implemented by locally imposed and ma,naged constraints on simple access modes (e.g., read and write) to system resources (e.g., files a.nd direct,ories).It is now becoming accept,ed t,hat.tellis view of security is inadequa.tefor ma.na.giug securit,y in a federation of administrative domains where local policies may conflict with global object,ives and some negot,iation is required to adjust multiple loca.1 policies in order to prevent loca.1 policy conflicts from hindering the achievement of a globa.policy.This new securit.yrequirement demands not so much new implementation technology as new concepts t,o be elabora.ted.We shall argue that issues of security policy need to be derived from understanding the wa.y that responsihility and a.uthority work in an ent,erprise, a.nd that t,he conventiona.appr0a.A of giving priorit.yt.0 modelling resource protection in terms of subjects, objects aud rules, formalising these in a. 'securit.ypolicy' and espetting the result automa.ticallyt.0 achieve orga.nisationalsecurity objectives, is to misrllltlerst,antl any legitimate local agency the seci1rit.ysyst.em may ha.ve as a global agency.

Read the paper · More papers on PaperTik