Great Circle Associates Firewalls
(December 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: chroot vs TE (Was Re: William of Occam)
From: Rick Smith <smith @ sctc . com>
Date: Mon, 11 Dec 1995 13:56:02 -0600
To: firewalls @ greatcircle . com
Cc: smith @ sctc . com, anton @ the-wire . com

Anton J Aylward <anton @
 the-wire .
 com> writes:

>The difference is that the Ptolemaic model was wrong in that it was
>theoretically inadequate.  The UNIX model isn't wrong, it isn't even
>inadequate; its lack of application to the networking interface was
>inadequate. 

Adequate with respect to _what_ ?? That's the question.

While the alleged Unix protection model may be adequate for something,
I argue that it's inadequate for a firewall because it does not
enforce a *mandatory* protection in the classic sense. It isn't always
invoked, it isn't tamperproof, and it is bypassable.

This is *not* a slam on Unix or its builders: just an observation that
we're trying to make it do something it wasn't designed to do.

The firewall is the first commercial device I know of that really,
really needs mandatory access controls. Mandatory controls are
designed to resist attacks by overtly malicious people that really
know what they're doing. They work because they draw explicit
boundaries that *no* software should cross. The kernel doesn't get
caught in this problem of yielding to good guys who are really bad
guys playing a masquerade.

Rick.
smith @
 sctc .
 com           secure computing corporation


Follow-Ups:
Indexed By Date Previous: RE: HP-UX Based Firewalls
From: ted @ lsli . com
Next: Re: modems and accessing the internal network
From: H Morrow Long <long-morrow @ CS . YALE . EDU>
Indexed By Thread Previous: chroot vs TE (Was Re: William of Occam)
From: Anton J Aylward <anton @ the-wire . com>
Next: Re: chroot vs TE (Was Re: William of Occam)
From: peter @ nmti . com (Peter da Silva)

Google
 
Search Internet Search www.greatcircle.com