Public reporting burden for this collection of information is estimated to average 1 hour per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing this burden, to Washington Headquarters Services, Directorate for information Operations and Reports, 1215 Jefferson Davis Highway, Suite 1204, Arlington, VA 22202-4302, and to the Office of Management and Budget, Paperwork Reduction Project (0704-0188), Washington, DC 20503.
AGENCY USE ONLY (Leave blank) 2. REPORT DATE 15 October 2004
REPORT TYPE AND DATES COVEREDFindings; 10/1/03 -9/31/04
TITLE AND SUBTITLE
A Least Privilege Model for Static Separation Kernels
FUNDING
AUTHOR(S)Timothy E. Levin and Cynthia E. Irvine and Thuy D. Nguyen NSA Contract H98230-V0-04-0023
PERFORMING ORGANIZATION NAME(S) AND ADDRESS(ES)Center for
SUPPLEMENTARY NOTESAny opinions, findings, and conclusions or recommendations expressed in this material are those of the author(s) and do not necessarily reflect the views of the National Security Agency.
12a. DISTRIBUTION/AVAILABILITY STATEMENTApproved for public release; distribution is unlimited 12b. DISTRIBUTION CODE
ABSTRACT (Maximum 200 words.)We extend the separation kernel abstraction to represent the enforcement of the principle of least privilege. In addition to the inter-block flow control policy prescribed by the traditional separation kernel paradigm, we describe an orthogonal finer-grained flow control policy by extending the protection of elements to subjects and resources, as well as blocks, within a partitioned system. We show how least privilege applied to the actions of subjects and resources provides enhanced protection for secure systems, and how only "trusted subjects" may cause certain information flows between partitions. A high assurance separation kernel based on least privilege can provide all of the functionality and protection of the traditional separation kernel, combined with a high level of confidence that the effects of subjects' activities can be minimized to their intended scope.