Malfeasance: a foundation for traducement, libel, heresy, and other traditional security policies
Matt Bishop, Thomas Stewart Walcott · 2004
Traditional computer security policies are specified using ad hoc methods. As a result, it is difficult to compare policies and analyze the relations between them. Implementation of security policies is yet more challenging. Three challenge problems derived from real-world security challenges are used to illustrate the issues associated with these traditional approaches. We demonstrate that Bell-LaPadula, Clark-Wilson, Biba, Originator Controls, the Clinical Information Systems Security, and Chinese Wall models (among others) do not adequately address the requirements of these problems. We present a policy specification language, Malfeasance, and use it to describe several traditional security models. Malfeasance is derived from Z formal methods, thereby permitting formal reasoning such as policy composition and comparisons. We then highlight the capabilities of Malfeasance by deriving three new policies (Traducement, Libel, and Heresy) that address our challenge problems. Finally, we also discuss the requirements for implementing Malfeasance under a variety of operating systems.