Midterm Study Guide
This is simply a guide of topics that I consider important for the
midterm. I don't promise to ask you about them all, or about any of
these in particular; but I may very well ask you about any of these, as
well as anything we discussed in class or that is in the reading.
- Fundamentals
- What is security?
- Basics of risk analysis
- Relationship of security policy to security
- Policy vs. mechanism
- Assurance and security
- Saltzer's and Schroeder's Principles of Secure Design
- Robust Programming
- Penetration Studies
- Flaw Hypothesis Methodology
- Using vulnerabilities models
- Vulnerabilities Models
- RISOS
- PA
- NRL
- Aslam
- Access Control Matrix
- Matrix
- Primitive Operations
- Commands
- Policies
- Mandatory Access Control (MAC)
- Discretionary Access Control (DAC)
- Originator-Controlled Access Control (ORCON)
- Role-Based Access Control (RBAC)
- Confidentiality Models
- Bell-LaPadula Model
- Lattices and the BLP Model
- Integrity Models
- Biba Model
- Clark-Wilson Model