3.2 Security Models

CISSP Domain 3 Β· Security Architecture and Engineering

3.2 Security Models

Security models provide formal ways of describing how information, users, processes and systems should interact while preserving required security properties.

For CISSP, the most important distinction is understanding what each model is trying to protect.

πŸ”’

Bell-LaPadula

Protects confidentiality by controlling information flow between security levels.

CONFIDENTIALITY
βœ…

Biba

Protects integrity by preventing contamination from lower-integrity information.

INTEGRITY
🏦

Clark-Wilson

Protects commercial integrity using controlled transactions and separation of duties.

BUSINESS INTEGRITY

The Big Idea

A security model answers questions such as:

πŸ‘€ Subject β†’ Who is requesting access?
πŸ“„ Object β†’ What resource is being accessed?
🏷️ Label β†’ What security level applies?
πŸ“œ Rule β†’ Which interaction is permitted?
➑️ Flow β†’ Where may information move?
πŸ›‘οΈ Property β†’ What security objective must remain protected?
Start with the security objective

When CISSP asks which security model is appropriate, first identify whether the scenario is mainly concerned with:

Confidentiality Integrity Conflict of Interest Information Flow Controlled Transactions
Essential Comparison

The Four Models You Must Recognise

ModelPrimary focusMain ideaMemory aid
Bell-LaPadulaConfidentialityPrevent information leaking from higher classifications to lower classifications.No Read Up
No Write Down
BibaIntegrityPrevent high-integrity information from being contaminated by lower-integrity information.No Read Down
No Write Up
Clark-WilsonCommercial integrityProtect data through controlled transactions, validation and separation of duties.Well-Formed Transactions
Brewer-NashConflict of interestAccess changes dynamically depending on information previously accessed.Chinese Wall
πŸ‘€ Subjects and Objects The basic language used by security models

Many security models describe interactions between subjects and objects.

Subject

An active entity requesting access or performing an action.

Examples:

User Process Application Service
Object

A passive resource being accessed or manipulated.

Examples:

File Database Record Resource
Example

Alice opens a classified document.

Alice = Subject

Document = Object

Do not assume the subject must be a human

An application process acting on behalf of a user can also be a subject.

πŸ”’ Bell-LaPadula Model Protect confidentiality

The Bell-LaPadula model focuses primarily on confidentiality.

It is closely associated with environments where information and users have hierarchical security classifications.

Bell-LaPadula asks:

How do we prevent sensitive information from flowing to users who are not authorised to receive it?

Example Security Levels

πŸ”΄ Top Secret ↑ Highest sensitivity
🟠 Secret ↑ Higher sensitivity
🟑 Confidential ↑ Protected information
🟒 Unclassified ↑ Lowest sensitivity

Simple Security Property

No Read Up

Lower clearance Cannot READ higher classified information

NO READ UP

Example

Alice has:

SECRET clearance

She attempts to read a:

TOP SECRET document.

Access is denied.

No Read Up.

*-Property - Star Property

No Write Down

Higher clearance Cannot WRITE information to a lower classification

NO WRITE DOWN

Example

Alice is working with:

TOP SECRET information.

She attempts to write that information into an:

UNCLASSIFIED file.

The action is denied.

Otherwise confidential information could leak downwards.

Why these rules make sense

LOW ❌ READ HIGH
HIGH ❌ WRITE LOW
Think about information leakage

Bell-LaPadula tries to prevent sensitive information from moving downward into areas where less-cleared subjects could access it.

Discretionary Security Property

Bell-LaPadula can also incorporate discretionary access controls.

A subject may have sufficient security clearance but still require appropriate permission to access a particular object.

Example

Bob holds Secret clearance.

A document is classified Secret.

That does not necessarily mean Bob automatically receives access to every Secret document.

Tranquility Principle

Security labels should not change arbitrarily in ways that undermine the security policy.

Strong Tranquility

Security labels do not change while the system is operating.

Weak Tranquility

Labels may change only when doing so does not violate the security policy.

Bell-LaPadula

B = Bell Think of protecting secrets behind the Bell
NO READ UP Do not see information above your level
NO WRITE DOWN Do not leak information below your level

Bell-LaPadula = Confidentiality

βœ… Biba Model Protect integrity

Biba is primarily concerned with integrity.

Instead of preventing sensitive information from leaking downward, Biba attempts to prevent trusted information and processes from being contaminated by less trustworthy information.

Biba asks:

How do we prevent lower-integrity information or users from corrupting higher-integrity information?

Simple Integrity Axiom

No Read Down

Higher integrity subject Should not READ lower-integrity information

NO READ DOWN

Example

A highly trusted financial calculation process should not use unverified information from an untrusted source.

Otherwise the high-integrity process could become contaminated by unreliable input.

*-Integrity Axiom

No Write Up

Lower-integrity subject Cannot WRITE to higher-integrity information

NO WRITE UP

Example

A low-trust user cannot directly modify a highly trusted financial ledger.

Otherwise lower-integrity information could corrupt higher-integrity information.

Invocation Property

A lower-integrity subject should not be able to invoke or control a higher-integrity subject in a way that undermines the integrity model.

HIGH integrity ❌ READ LOW integrity
LOW integrity ❌ WRITE HIGH integrity
Biba is effectively the opposite direction to Bell-LaPadula

Bell-LaPadula protects secrets from leaking downward.

Biba protects trusted information from contamination moving upward.

Biba

NO READ DOWN Do not consume less trustworthy information
NO WRITE UP Do not contaminate more trustworthy information

Biba = Integrity

Bell-LaPadula vs Biba

Bell-LaPadulaBiba
ProtectsConfidentialityIntegrity
Read ruleNo Read UpNo Read Down
Write ruleNo Write DownNo Write Up
Main concernInformation leakageInformation contamination
Typical contextClassified informationTrusted information and processes

The easiest way to remember them

Bell-LaPadula Secrets should not LEAK DOWN
Biba Bad data should not CONTAMINATE UP

Bell protects SECRETS. Biba protects TRUST.

🏦 Clark-Wilson Model Commercial integrity and well-formed transactions

Clark-Wilson is an integrity model designed around the realities of commercial and business systems.

Rather than relying mainly on hierarchical integrity labels, it protects important information by requiring users to interact with it through authorised and controlled transactions.

Think banking and accounting

Users should not directly manipulate critical business data.

They should perform authorised transactions that preserve the integrity of that data.

Well-Formed Transactions

Critical data should be modified only through approved programs or procedures that transform the information in a controlled way.

Bank example

A bank employee should not directly edit:

Account Balance = Β£10,000

and change it to:

Account Balance = Β£50,000.

Instead, the employee performs an authorised transaction:

Deposit Β£40,000

The trusted application performs the appropriate validation and updates the account.

Clark-Wilson Components

CDI

Constrained Data Item

Data whose integrity must be protected.

UDI

Unconstrained Data Item

Input that has not yet been validated as trusted.

TP

Transformation Procedure

An authorised operation that changes protected data while preserving integrity.

IVP

Integrity Verification Procedure

Checks that protected data remains in a valid state.

Untrusted Input β†’ UDI
Validation / Transaction β†’ TP
Protected Business Data β†’ CDI
Integrity Check β†’ IVP

Separation of Duties

Clark-Wilson also strongly supports separation of duties.

Example

Employee A:

Creates a payment

Employee B:

Approves the payment

The system:

Processes the authorised transaction

Clark-Wilson

CDI Protected data
UDI Untrusted input
TP Controlled transformation
IVP Verify integrity

Clark-Wilson = Transactions + Separation of Duties

🧱 Brewer-Nash Model The Chinese Wall model

The Brewer-Nash model addresses conflicts of interest.

Access decisions can change dynamically depending on information a subject has previously accessed.

Consultancy example

A consultancy advises several competing banks:

Bank A Bank B Bank C

Alice starts working on:

Bank A.

She may now be prevented from accessing confidential information belonging to:

Bank B or Bank C

because they belong to the same conflict-of-interest class.

Access Bank A β†’ Allowed
Later access Bank A β†’ Allowed
Later access competitor Bank B β†’ DENIED
Access changes dynamically

This is what makes Brewer-Nash different from a simple static clearance model.

Previous access affects future access decisions.

Brewer-Nash

Chinese Wall Separate competing interests
Previous Access Influences future permissions

Brewer-Nash = Conflict of Interest

βš™οΈ State Machine Model Secure states and secure transitions

A state machine model represents a system as a collection of states.

Operations cause the system to move from one state to another.

Secure State A β†’ Authorised Transition
Authorised Transition β†’ Secure State B
Core concept

If the system begins in a secure state and every permitted transition preserves the security policy, the resulting state should remain secure.

Simple example

A file begins:

Protected

A permitted operation modifies the file while maintaining authorised permissions.

The system transitions to another:

Protected state.

State Machine

Secure State +
Secure Transition =
Secure State Security preserved
➑️ Information Flow Model Control where information is allowed to move

Information flow models focus on how information moves between subjects, objects and security domains.

The concern is not simply whether an entity can open a particular file.

The concern is:

Can information move from one security level or domain to another?
Example

Information moves from:

Top Secret β†’ Public

Even if no user directly opened the original Top Secret document, the information flow itself could violate confidentiality.

Bell-LaPadula is strongly related to information flow

Its rules attempt to stop classified information from flowing into lower-security areas.

🚧 Noninterference Model Higher-level activity should not influence lower-level observations

Noninterference attempts to ensure that activity at a higher security level cannot influence what a lower-level subject can observe in a way that reveals protected information.

Conceptual example

A Top Secret process performs a confidential calculation.

An Unclassified user should not be able to determine information about that calculation by observing effects visible at their own level.

Think isolation between security levels

High-level activity should not interfere with lower-level observations in ways that leak protected information.

Noninterference

HIGH activity should not reveal itself through
LOW observations in a security-relevant way
πŸ•ΈοΈ Lattice-Based Security Models Labels, dominance and information flow

Lattice-based access models use security labels and mathematical relationships between those labels to determine permitted information flows.

Simple classification example
Top Secret dominates Secret
Secret dominates Confidential
Confidential dominates Unclassified

Real security labels can also contain categories or compartments.

Example

Alice:

SECRET {NUCLEAR, EUROPE}

Document:

SECRET {NUCLEAR}

Alice's label may dominate the document label because her classification is sufficient and she possesses the required category.

Classification alone may not be enough

Categories or compartments can further restrict access even when the user's overall clearance level is sufficiently high.

From Model to Enforcement

Reference Monitor, Security Kernel and TCB

A security policy or model is useful only if the system has mechanisms capable of enforcing it.

Reference Monitor

An abstract concept representing the mechanism that mediates access between subjects and objects.

Security Kernel

The hardware and software mechanisms that implement the core reference-monitor functionality.

Trusted Computing Base - TCB

The collection of protection mechanisms within a system that must operate correctly for the system's security policy to be enforced.

Reference Monitor Requirements

1️⃣ Complete Mediation β†’ Every relevant access must be checked
2️⃣ Tamper Resistant β†’ The mechanism must be protected from modification
3️⃣ Verifiable β†’ It must be small/simple enough to analyse and test

Reference Monitor

ALWAYS checks access
CANNOT be bypassed or modified easily
CAN be verified

Mediates. Protected. Verifiable.

πŸ“š Other Models Worth Recognising Useful supporting CISSP knowledge
Take-Grant Model

Represents permissions using a graph and examines how rights can be transferred between subjects and objects.

Think: Who can give or take rights?

Graham-Denning Model

Examines secure creation and deletion of subjects and objects and how access rights can be transferred.

Think: Managing access rights securely.

Harrison-Ruzzo-Ullman Model

Examines access rights and whether a protection system can reach a state where particular rights are acquired.

Think: Access-right safety.

Access Matrix

Represents the rights subjects have over objects.

Rows commonly represent subjects and columns represent objects.

Exam priority

Bell-LaPadula, Biba, Clark-Wilson and Brewer-Nash are generally the models you should recognise most quickly.

The others are useful for understanding the broader theory of access-control and protection systems.

Practical Scenario

Designing a Financial Trading Platform

A financial organisation is designing a platform used by traders, financial analysts, compliance staff and administrators.

Different security models may address different parts of the problem.

Bell-LaPadula

Prevent highly confidential deal information from being disclosed to users without sufficient clearance.

Biba

Prevent low-trust information from directly contaminating trusted financial calculations.

Clark-Wilson

Require financial records to be changed through authorised transactions rather than direct editing.

Brewer-Nash

Prevent consultants or analysts from accessing confidential information belonging to competing clients.

State Machine

Ensure permitted operations transition the system between valid and secure states.

Information Flow

Prevent protected information from moving into unauthorised security domains.

πŸŽ“ CISSP Scenarios Identify the model from the requirement
Scenario 1

A Secret-cleared user attempts to read a Top Secret document.

Which model and rule apply?

Bell-LaPadula - No Read Up.

Scenario 2

A Top Secret process attempts to copy classified information into an Unclassified file.

Which rule prevents this?

Bell-LaPadula - No Write Down.

Scenario 3

A highly trusted financial process is prevented from consuming data from an untrusted source.

Which model?

Biba - No Read Down.

Scenario 4

A low-integrity user is prevented from modifying a high-integrity accounting record.

Which model?

Biba - No Write Up.

Scenario 5

Employees may modify financial balances only through authorised business transactions.

Which model?

Clark-Wilson.

Scenario 6

One employee initiates a payment and another must approve it.

Which model strongly supports this concept?

Clark-Wilson - Separation of Duties.

Scenario 7

A consultant accesses confidential records belonging to Bank A and is subsequently prevented from accessing Bank B's records.

Which model?

Brewer-Nash / Chinese Wall.

Scenario 8

An architect wants to demonstrate that every permitted system transition moves the system from one secure condition to another.

Which model?

State Machine Model.

Scenario 9

The primary concern is preventing information from moving between security domains in an unauthorised direction.

Which model concept?

Information Flow Model.

Scenario 10

Activity in a highly classified environment must not affect outputs observable by low-classification users in a way that reveals information.

Which model?

Noninterference.

Scenario 11

A system compares a user's security label with an object's label and determines access based on dominance relationships.

Which concept?

Lattice-Based Security.

Scenario 12

A security mechanism must mediate every subject-to-object access, resist tampering and be capable of verification.

Which concept?

Reference Monitor.

CISSP Exam Perspective

Recognise the Clue Words

Confidentiality

Classified information

No Read Up

No Write Down

Bell-LaPadula

Integrity

Trusted data

No Read Down

No Write Up

Biba

Business Transactions

CDI / UDI

TP / IVP

Separation of Duties

Clark-Wilson

Conflict of Interest

Consultants

Competitors

Previous access

Brewer-Nash

Secure Transitions

Secure state

State transition

State Machine

Information Movement

Information direction

Security domains

Information Flow

Isolation

High activity must not influence low observations

Noninterference

Labels & Dominance

Clearance

Classification

Compartments

Lattice
⚠️ Common CISSP Mistakes These models are deliberately easy to confuse
Bell-LaPadula β‰  Integrity

Bell-LaPadula's primary concern is CONFIDENTIALITY.

Biba β‰  Confidentiality

Biba's primary concern is INTEGRITY.

The Bell/Biba memory rules are reversed

Bell-LaPadula: No Read Up, No Write Down.

Biba: No Read Down, No Write Up.

Clark-Wilson is not simply another label model

Its key ideas are controlled transformation, validation and separation of duties.

Brewer-Nash permissions are dynamic

What you accessed previously may determine what you are allowed to access next.

Clearance does not always equal permission

Having an adequate security level does not necessarily mean a subject has a legitimate requirement or discretionary permission to access every object at that level.

Security models describe policy

A model does not automatically enforce itself.

The system requires trustworthy mechanisms capable of implementing and enforcing the model.

Fast Identification Table

If you see...Think...
Military-style confidentialityBell-LaPadula
No Read UpBell-LaPadula
No Write DownBell-LaPadula
Protect integrityBiba
No Read DownBiba
No Write UpBiba
Well-formed transactionsClark-Wilson
CDI / UDI / TP / IVPClark-Wilson
Separation of duties + integrityClark-Wilson
Consultants working with competitorsBrewer-Nash
Chinese WallBrewer-Nash
Secure state β†’ secure stateState Machine
Direction information is allowed to moveInformation Flow
High-level activity must not affect low-level observationNoninterference
Labels, compartments and dominanceLattice Model
Mediates every accessReference Monitor

Security Models Master Memory Aid

Bell-LaPadula CONFIDENTIALITY
Biba INTEGRITY
Clark-Wilson BUSINESS TRANSACTIONS
Brewer-Nash CONFLICT OF INTEREST
State Machine SECURE TRANSITIONS
Information Flow WHERE DATA MAY MOVE
Noninterference HIGH MUST NOT REVEAL TO LOW

Bell = Secrets Β· Biba = Trust Β· Clark = Transactions Β· Brewer = Conflict

The Bell & Biba Shortcut

Bell-LaPadula NO READ UP
Bell-LaPadula NO WRITE DOWN
Biba NO READ DOWN
Biba NO WRITE UP

Bell stops secrets going DOWN. Biba stops bad data going UP.

Key Takeaways

Security models describe rules for protecting information and controlling interactions between subjects and objects.

Bell-LaPadula protects confidentiality.

Its core memory rules are No Read Up and No Write Down.

Biba protects integrity.

Its core memory rules are No Read Down and No Write Up.

Bell-LaPadula prevents sensitive information from leaking downward while Biba prevents less-trusted information from contaminating higher-integrity information.

Clark-Wilson focuses on commercial integrity through well-formed transactions, validation and separation of duties.

Clark-Wilson uses concepts including CDIs, UDIs, Transformation Procedures and Integrity Verification Procedures.

Brewer-Nash addresses conflicts of interest and is also known as the Chinese Wall model.

Brewer-Nash is dynamic because previous access can influence future access decisions.

State machine models focus on preserving security while the system moves between different states.

Information flow models focus on whether information is permitted to move between subjects, objects or security domains.

Noninterference aims to prevent higher-security activity from affecting what lower-security subjects can observe in a security-relevant way.

Lattice models use security labels and dominance relationships to determine permitted access and information flow.

The reference monitor concept describes a mechanism that mediates security-relevant access and should be protected from tampering, consistently invoked and capable of verification.

For CISSP, first identify the objective: confidentiality, integrity, business integrity or conflict of interest. The correct model usually becomes much easier to recognise.

πŸ“š Sources & Further Reading Security model terminology and architecture references