Teaching Assistant: Michael Covington (covingto@cc)
Room and time: 260 Architecture (New), MWF 2:05-2:55
pm
President's Commission on Critical Infrastructure Protection Report
The inevitability
of failure: The flawed assumption of security in modern computing systems
Week 3: Authentication
Password Security: A Case History
Unix Password Security: 10 Years Later
The Design and Analysis of Graphical Passwords
Going Beyond the Sanbox: New Security Architectures in JDK 1.2
Improving the Granularity of Access Control in Windows NT, ACM SACMAT, 2001.
Providing Policy Control Over Object Operations in a Mach Based System
Other Models
Information Flow Models
A Decentralized Model for Information Flow
A
note on the confinement problem
NCSC Guide to Understanding Covert Channel Analysis
Weeks 10: Security Kernels
Chapter 10 of Gasser's book.
Security kernel design and implementation: an introduction, IEEE Computer,
July 1983.
Weeks 11-12: Distributed Systems Security
Authentication and access control in distributed systems
A Global Authentication Service without Global Trust
Week 13-15: Secure Database Systems
SeaView Model by Denning and Lunt (available from IEEE xplore database)
Recovering from malicious transactions by Ammann, Jajodia and Liu
Programming Project I
Homework I
Programming Project II