08-Mandatory Access Control-MAC
08-Mandatory Access Control-MAC
• BLP consists of
• Example
• Based on Bell-LaPadula
– Subject, Objects have
• Integrity Levels with dominance relation
– Higher levels
• More reliable/trustworthy
• More accurate
Biba
• Let I(O) denote the integrity of object O and
I(S) denote the integrity of subject S
• Biba can be stated as
Write Access Rule: S can write O if and only if I(O) I(S)
(otherwise O will be contaminated with the
untrusted S)
15
BLP vs. Biba