UCLA Secure Unix

Gerald J. Popek, Mark Kampe, Charles S. Kline, Allen Stoughton, Michael R. Urban, Evelyn Walton · 1979 International Workshop on Managing Requirements Knowledge (MARK) · 1979

There has been considerable interest for some time in developing an operating system which could be conclusively shown secure, in the sense that the information stored on behalf of a heterogeneous user population was safely protected from unauthorized access or modification, even in the face of skilled attempts to do so. Early attempts to attain this goal consisted largely of auditing an existing system through attempts at circumventing the controls, and then revising the implementation code to block any successful paths that were found. Unfortunately, this approach failed to produce a secure system, largely because third generation operating systems contain so many errors that "penetration audits" followed by patches inevitably led to a system whose controls were still easily penetrated.

Read the paper · More papers on PaperTik