Formal methods of IT security
Francis Barry · ITNOW · 1992
Abstract This article examines formal models of security, a concept fundamental to the design of secure computer systems. A formal security model is a mathematically precise statement of security policy. It specifies the initial state of a system, the way in which the system progresses from one state to another, and a definition of a ‘secure’ state of the system. If all the assumptions required by the model hold, then all future states of the system will be secure. Trusted systems are typically based on models such as the Monitor Model, the Information Flow Model, the Bell-LaPadula Model, and the Biba Integrity Model.