A Framework For System Security

Clark Thomborson
DOI: https://doi.org/10.1007/978-3-642-04117-4_1
2010-01-01
Abstract:Actors in our general framework for secure systems can exert four types of control over other actors' systems, depending on the tem- porality (prospective vs. retrospective) of the control and on the power relationship (hierarchical vs. peering) between the actors. We make clear distinctions between security, functionality, trust, and distrust by identi- fying two orthogonal properties: feedback and assessment. We distinguish four types of system requirements using two more orthogonal properties: strictness and activity. We use our terminology to describe specialised types of secure systems such as access control systems, Clark-Wilson sys- tems, and the Collaboration Oriented Architecture recently proposed by
What problem does this paper attempt to address?