loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
18th Annual Computer Security Applications Conference (ACSAC '02)
Thirty Years Later: Lessons from the Multics Security Evaluation
San Diego California
December 09-December 13
ISBN: 0-7695-1828-1
Paul A. Karger, IBM Corp., T. J. Watson Research Center
Roger R. Schell, Aesec Corporation
Almost thirty years ago a vulnerability assessment of Multics identified significant vulnerabilities, despite the fact that Multics was more secure than other contemporary (and current) computer systems. Considerably more important than any of the individual design and implementation flaws was the demonstration of subversion of the protection mechanism using malicious software (e.g., trap doors and Trojan horses). A series of enhancements were suggested that enabled Multics to serve in a relatively benign environment. These included addition of "Mandatory Access Controls" and these enhancements were greatly enabled by the fact the Multics was designed from the start for security. However, the bottom-line conclusion was that "restructuring is essential" around a verifiable "security kernel" before using Multics (or any other system) in an open environment (as in today?s Internet) with the existence of well-motivated professional attackers employing subversion. The lessons learned from the vulnerability assessment are highly applicable today as governments and industry strive (unsuccessfully) to "secure" today?s weaker operating systems through add-ons, "hardening", and intrusion detection schemes.
Citation:
Paul A. Karger, Roger R. Schell, "Thirty Years Later: Lessons from the Multics Security Evaluation," acsac, pp.119, 18th Annual Computer Security Applications Conference (ACSAC '02), 2002
Usage of this product signifies your acceptance of the Terms of Use.