Great Circle Associates Firewalls
(September 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: C2 certified OS that can run a firewall
From: spencerj @ dg-rtp . dg . com (Jon Spencer)
Date: Thu, 5 Sep 1996 18:19:32 -0400 (EDT)
To: mcnabb @ argus . cu-online . com (Paul McNabb)
Cc: firewalls @ greatcircle . com
In-reply-to: <199609041436 . JAA13457 @ argus . cu-online . com> from "Paul McNabb" at Sep 4, 96 09:36:14 am

> Of course C2 security is better than no security, but C2 was never

Welll .......  it is if you understand its limitations.  Otherwise ...

> "designed for commercial use" as is sometimes written in articles and
> email.  If you are in an environment where the system administrators
> want to *enforce* security on the users, B1 and higher security features
> are needed.  But remember, none of the TCSEC ("Orange Book") security
> levels were designed for anything other than military/government use.
> It just happens that a lot of the security they specify is general-
> purpose and works well in all kinds of environments.

(1) B1 is not much better than C2.
(2) The strengths of B2 and above are related to the high assurance issues
    rather than to the features.  At B2 you have a very good expectation
    that the system actually works like it is supposed to.  After that, you
    must determine if the high assurance features really address the
    threats in your environment.


I would also argue the issue that TCSEC strictly addressed the military.
The issues addressed by the TCSEC primarily, at B2 and above, focus on "how
do you know it works - prove it!"  The sad truth is that people who
generated TCSEC systems focused on meeting precisely their interpretation
of the minimum system that met the TCSEC requirements.  That is not the
TCSEC's fault.


-- 
Jon F. Spencer   spencerj @
 rtp .
 dg .
 com  (uunet!rtp.dg.com!spencerj)
Data General Corp.                  Phone : (919)248-6246
62 T.W. Alexander Dr, MS #119       FAX   : (919)248-6108
Research Triangle Park, NC  27709   Office RTP 121/9

	Reality is an illusion - perception is what counts.

	No success can compensate for failure in the home.
			President David O. McKay

***** UCC 1-207 ********


Follow-Ups:
References:
Indexed By Date Previous: Re: fw-1 2.0: Menu too large for screen
From: Jeff Murphy <jcmurphy @ smurfland . cit . buffalo . edu>
Next: RE: Secure Access Firwall (Ascend)??
From: Bill Maples <Bill . Maples @ express-hr . com>
Indexed By Thread Previous: Re: C2 certified OS that can run a firewall
From: Ng Pheng Siong <ngps @ pacific . net . sg>
Next: Re: C2 certified OS that can run a firewall
From: Rabid Wombat <wombat @ mcfeely . bsfs . org>

Google
 
Search Internet Search www.greatcircle.com