Authorization

Mark Stamp · Information Security · 2005

Authorization deals with restrictions placed on authenticated users. In this chapter we cover the basics of traditional authorization, including access control lists (ACLs) and capabilities. We illustrate the subtle differences between ACLs and capabilities using the classic “confused deputy” problem. We then present some of the security issues related to multilevel and multilateral security, and we briefly touch on the related topics of covert channels and inference control. Multilevel security naturally leads us into the world of security modeling, where we briefly discuss two of the simplest such models, Bell-LaPadula and Biba's Model. After covering the basics of security modeling, we consider non-traditional access control topics, including CAPTCHAs and firewalls. We concluded the chapter by stretching the definition of access control to cover intrusion detection systems (IDS).

Read the paper · More papers on PaperTik