Concepts and Terminology for Computer Security
Donald L. Brinkley, Roger R. Schell · 2006
This essay introduces many of the concepts and terms most important in gaining an understanding of computer security. It focuses on techniques for achieving access control within computer systems and networks. The essay begins by defining what is meant by computer security and describing why it is important to constrain the definition to protection that can be meaningfully provided with a significant degree of assurance within computer systems. The theory of computer security — the reference monitor concept — is introduced next through an analogy with security concepts from the world of people and sensitive documents. Next, the essay develops the presentation of the theory by introducing concepts and terms related to the security policy. Distinctions between discretionary and nondiscretionary access control policies are provided, and supporting policies are introduced. Techniques used for building a secure system based on the principles of the theory are presented, along with methods of usefully verifying the security of a system. The security kernel is presented as a useful, high-assurance realization of the reference monitor concept, and the principles behind designing and implementing one from scratch are discussed. Feasible improvements to the security of an existing operating system, as well as fundamental limitations on those improvements, are described next. Finally, the reference monitor concept is applied to networks, and cryptography and access control are shown to be useful partners.