Great Circle Associates Firewalls
(January 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Security Clea..- Firewall related
From: Rick Smith <smith @ sctc . com>
Date: Wed, 24 Jan 1996 15:39:19 -0600
To: firewalls @ greatcircle . com
Cc: smith @ sctc . com

Karen Goertzel writes:

> I agree that attempting to apply military classification labels to
> commercial data makes little sense.  But what amazes me is that so
> many people can't see beyond the actual labels to the much more
> important underlying concept, which is the idea of a hierarchical
> mandatory policy for classifying information, instead of a
> discretionary policy. 

My own experience is that the hierarchical concept is a good one but
the hierarchical mechanism is not. While it is intuitively appealing,
it doesn't seem to work effectively in practice. For example, note how
the MLS firewall implementation uses mutually inaccessible
compartments instead of "high" versus "low" domains for the different
networks.  I've seen this happen in many MLS applications, too.  Too
often we need to protect against more than just disclosure.

Note this is a gripe about *hierarchical* access control rules, not
about mandatory mechanisms in general.

Rick.
smith @
 sctc .
 com          secure computing corporation

Indexed By Date Previous: Re: IP-address translation
From: Ron DuFresne <dufresne @ winternet . com>
Next: Re: IPSEC == end of firewalls
From: Leonard Miyata <leonard @ geminisecure . com>
Indexed By Thread Previous: Re: Security Clea..- Firewall related
From: "KM" <goertzek @ gateway . wangfed . com>
Next: Product selection
From: smcc @ pipeline . com (System Management Consulting Company)

Google
 
Search Internet Search www.greatcircle.com