Issue No. 02 - February (1987 vol. 13)
J.T. Haigh , Honeywell Secure Computing Technology Center
This paper examines the application of two covert channel analysis techniques to a high level design for a real system, the Honeywell Secure Ada? Target (SAT). The techniques used were a version of the noninterference model of multilevel security due to Goguen and Meseguer and the shared resource matrix method of Kemmerer. Both techniques were applied to the Gypsy Abstract Model of the SAT. The paper discusses the application of the techniques and the nature of the covert channels discovered. The relative strengths and weaknesses of the two methods are discussed and criteria for an ideal covert channel tool are developed.
shared resource matrix, Covert channels, formal specification, formal verification, multilevel security, noninterference security policies
J. Mchugh, W.D. Young, J.T. Haigh, R.A. Kemmerer, "An Experience Using Two Covert Channel Analysis Techniques on a Real System Design", IEEE Transactions on Software Engineering, vol. 13, no. , pp. 157-168, February 1987, doi:10.1109/TSE.1987.226479