Using Proven Reference Monitor Patterns for Security Evaluation
AbstractThe most effective approach to evaluating the security of complex systems is to deliberately construct the systems using security patterns specifically designed to make them evaluable. Just such an integrated set of security patterns was created decades ago based on the Reference Monitor abstraction. An associated systematic security engineering and evaluation methodology was codified as an engineering standard in the Trusted Computer System Evaluation Criteria (TCSEC). This paper explains how the TCSEC and its Trusted Network Interpretation (TNI) constitute a set of security patterns for large, complex and distributed systems and how those patterns have been repeatedly and successfully used to create and evaluate some of the most secure government and commercial systems ever developed. View Full-Text
Share & Cite This Article
Heckman, M.R.; Schell, R.R. Using Proven Reference Monitor Patterns for Security Evaluation. Information 2016, 7, 23.
Heckman MR, Schell RR. Using Proven Reference Monitor Patterns for Security Evaluation. Information. 2016; 7(2):23.Chicago/Turabian Style
Heckman, Mark R.; Schell, Roger R. 2016. "Using Proven Reference Monitor Patterns for Security Evaluation." Information 7, no. 2: 23.
Note that from the first issue of 2016, MDPI journals use article numbers instead of page numbers. See further details here.