Is "Deny Access" a Valid "Fail-Safe Default" Principle for Building Security in Cyberphysical Systems?
Fabio Massacci · IEEE Security & Privacy · 2019
In 1975, Saltzer and Schroeder (S&S) elucidated eight design principles that shaped decades of security research and development.1Some of them are listed as key tenets of security protocols2in software design methodologies, such as Microsoft's Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege threat model,3,4and in McGraw's 2004 article "Software Security" in IEEE Security & Privacy.5