3.2 Security Models
3.2 Security Models
Security models provide formal ways of describing how information, users, processes and systems should interact while preserving required security properties.
For CISSP, the most important distinction is understanding what each model is trying to protect.
Bell-LaPadula
Protects confidentiality by controlling information flow between security levels.
CONFIDENTIALITYBiba
Protects integrity by preventing contamination from lower-integrity information.
INTEGRITYClark-Wilson
Protects commercial integrity using controlled transactions and separation of duties.
BUSINESS INTEGRITYThe Big Idea
A security model answers questions such as:
When CISSP asks which security model is appropriate, first identify whether the scenario is mainly concerned with:
The Four Models You Must Recognise
| Model | Primary focus | Main idea | Memory aid |
|---|---|---|---|
| Bell-LaPadula | Confidentiality | Prevent information leaking from higher classifications to lower classifications. | No Read Up No Write Down |
| Biba | Integrity | Prevent high-integrity information from being contaminated by lower-integrity information. | No Read Down No Write Up |
| Clark-Wilson | Commercial integrity | Protect data through controlled transactions, validation and separation of duties. | Well-Formed Transactions |
| Brewer-Nash | Conflict of interest | Access changes dynamically depending on information previously accessed. | Chinese Wall |
π€ Subjects and Objects The basic language used by security models
Many security models describe interactions between subjects and objects.
An active entity requesting access or performing an action.
Examples:
A passive resource being accessed or manipulated.
Examples:
Alice opens a classified document.
Alice = Subject
Document = Object
An application process acting on behalf of a user can also be a subject.
π Bell-LaPadula Model Protect confidentiality
The Bell-LaPadula model focuses primarily on confidentiality.
It is closely associated with environments where information and users have hierarchical security classifications.
How do we prevent sensitive information from flowing to users who are not authorised to receive it?
Example Security Levels
Simple Security Property
No Read Up
NO READ UP
Alice has:
SECRET clearance
She attempts to read a:
TOP SECRET document.
Access is denied.
No Read Up.*-Property - Star Property
No Write Down
NO WRITE DOWN
Alice is working with:
TOP SECRET information.
She attempts to write that information into an:
UNCLASSIFIED file.
The action is denied.
Otherwise confidential information could leak downwards.Why these rules make sense
Bell-LaPadula tries to prevent sensitive information from moving downward into areas where less-cleared subjects could access it.
Discretionary Security Property
Bell-LaPadula can also incorporate discretionary access controls.
A subject may have sufficient security clearance but still require appropriate permission to access a particular object.
Bob holds Secret clearance.
A document is classified Secret.
That does not necessarily mean Bob automatically receives access to every Secret document.
Tranquility Principle
Security labels should not change arbitrarily in ways that undermine the security policy.
Security labels do not change while the system is operating.
Labels may change only when doing so does not violate the security policy.
Bell-LaPadula
Bell-LaPadula = Confidentiality
β Biba Model Protect integrity
Biba is primarily concerned with integrity.
Instead of preventing sensitive information from leaking downward, Biba attempts to prevent trusted information and processes from being contaminated by less trustworthy information.
How do we prevent lower-integrity information or users from corrupting higher-integrity information?
Simple Integrity Axiom
No Read Down
NO READ DOWN
A highly trusted financial calculation process should not use unverified information from an untrusted source.
Otherwise the high-integrity process could become contaminated by unreliable input.
*-Integrity Axiom
No Write Up
NO WRITE UP
A low-trust user cannot directly modify a highly trusted financial ledger.
Otherwise lower-integrity information could corrupt higher-integrity information.Invocation Property
A lower-integrity subject should not be able to invoke or control a higher-integrity subject in a way that undermines the integrity model.
Bell-LaPadula protects secrets from leaking downward.
Biba protects trusted information from contamination moving upward.
Biba
Biba = Integrity
Bell-LaPadula vs Biba
| Bell-LaPadula | Biba | |
|---|---|---|
| Protects | Confidentiality | Integrity |
| Read rule | No Read Up | No Read Down |
| Write rule | No Write Down | No Write Up |
| Main concern | Information leakage | Information contamination |
| Typical context | Classified information | Trusted information and processes |
The easiest way to remember them
Bell protects SECRETS. Biba protects TRUST.
π¦ Clark-Wilson Model Commercial integrity and well-formed transactions
Clark-Wilson is an integrity model designed around the realities of commercial and business systems.
Rather than relying mainly on hierarchical integrity labels, it protects important information by requiring users to interact with it through authorised and controlled transactions.
Users should not directly manipulate critical business data.
They should perform authorised transactions that preserve the integrity of that data.
Well-Formed Transactions
Critical data should be modified only through approved programs or procedures that transform the information in a controlled way.
A bank employee should not directly edit:
Account Balance = Β£10,000
and change it to:
Account Balance = Β£50,000.
Instead, the employee performs an authorised transaction:
Deposit Β£40,000
The trusted application performs the appropriate validation and updates the account.
Clark-Wilson Components
Constrained Data Item
Data whose integrity must be protected.
Unconstrained Data Item
Input that has not yet been validated as trusted.
Transformation Procedure
An authorised operation that changes protected data while preserving integrity.
Integrity Verification Procedure
Checks that protected data remains in a valid state.
Separation of Duties
Clark-Wilson also strongly supports separation of duties.
Employee A:
Creates a payment
Employee B:
Approves the payment
The system:
Processes the authorised transaction
Clark-Wilson
Clark-Wilson = Transactions + Separation of Duties
π§± Brewer-Nash Model The Chinese Wall model
The Brewer-Nash model addresses conflicts of interest.
Access decisions can change dynamically depending on information a subject has previously accessed.
A consultancy advises several competing banks:
Alice starts working on:
Bank A.
She may now be prevented from accessing confidential information belonging to:
Bank B or Bank C
because they belong to the same conflict-of-interest class.
This is what makes Brewer-Nash different from a simple static clearance model.
Previous access affects future access decisions.
Brewer-Nash
Brewer-Nash = Conflict of Interest
βοΈ State Machine Model Secure states and secure transitions
A state machine model represents a system as a collection of states.
Operations cause the system to move from one state to another.
If the system begins in a secure state and every permitted transition preserves the security policy, the resulting state should remain secure.
A file begins:
Protected
A permitted operation modifies the file while maintaining authorised permissions.
The system transitions to another:
Protected state.
State Machine
β‘οΈ Information Flow Model Control where information is allowed to move
Information flow models focus on how information moves between subjects, objects and security domains.
The concern is not simply whether an entity can open a particular file.
The concern is:
Information moves from:
Top Secret β Public
Even if no user directly opened the original Top Secret document, the information flow itself could violate confidentiality.
Its rules attempt to stop classified information from flowing into lower-security areas.
π§ Noninterference Model Higher-level activity should not influence lower-level observations
Noninterference attempts to ensure that activity at a higher security level cannot influence what a lower-level subject can observe in a way that reveals protected information.
A Top Secret process performs a confidential calculation.
An Unclassified user should not be able to determine information about that calculation by observing effects visible at their own level.
High-level activity should not interfere with lower-level observations in ways that leak protected information.
Noninterference
πΈοΈ Lattice-Based Security Models Labels, dominance and information flow
Lattice-based access models use security labels and mathematical relationships between those labels to determine permitted information flows.
Real security labels can also contain categories or compartments.
Alice:
SECRET {NUCLEAR, EUROPE}
Document:
SECRET {NUCLEAR}
Alice's label may dominate the document label because her classification is sufficient and she possesses the required category.
Categories or compartments can further restrict access even when the user's overall clearance level is sufficiently high.
Reference Monitor, Security Kernel and TCB
A security policy or model is useful only if the system has mechanisms capable of enforcing it.
An abstract concept representing the mechanism that mediates access between subjects and objects.
The hardware and software mechanisms that implement the core reference-monitor functionality.
The collection of protection mechanisms within a system that must operate correctly for the system's security policy to be enforced.
Reference Monitor Requirements
Reference Monitor
Mediates. Protected. Verifiable.
π Other Models Worth Recognising Useful supporting CISSP knowledge
Represents permissions using a graph and examines how rights can be transferred between subjects and objects.
Think: Who can give or take rights?
Examines secure creation and deletion of subjects and objects and how access rights can be transferred.
Think: Managing access rights securely.
Examines access rights and whether a protection system can reach a state where particular rights are acquired.
Think: Access-right safety.
Represents the rights subjects have over objects.
Rows commonly represent subjects and columns represent objects.
Bell-LaPadula, Biba, Clark-Wilson and Brewer-Nash are generally the models you should recognise most quickly.
The others are useful for understanding the broader theory of access-control and protection systems.
Designing a Financial Trading Platform
A financial organisation is designing a platform used by traders, financial analysts, compliance staff and administrators.
Different security models may address different parts of the problem.
Prevent highly confidential deal information from being disclosed to users without sufficient clearance.
Prevent low-trust information from directly contaminating trusted financial calculations.
Require financial records to be changed through authorised transactions rather than direct editing.
Prevent consultants or analysts from accessing confidential information belonging to competing clients.
Ensure permitted operations transition the system between valid and secure states.
Prevent protected information from moving into unauthorised security domains.
π CISSP Scenarios Identify the model from the requirement
A Secret-cleared user attempts to read a Top Secret document.
Which model and rule apply?
Bell-LaPadula - No Read Up.
A Top Secret process attempts to copy classified information into an Unclassified file.
Which rule prevents this?
Bell-LaPadula - No Write Down.
A highly trusted financial process is prevented from consuming data from an untrusted source.
Which model?
Biba - No Read Down.
A low-integrity user is prevented from modifying a high-integrity accounting record.
Which model?
Biba - No Write Up.
Employees may modify financial balances only through authorised business transactions.
Which model?
Clark-Wilson.
One employee initiates a payment and another must approve it.
Which model strongly supports this concept?
Clark-Wilson - Separation of Duties.
A consultant accesses confidential records belonging to Bank A and is subsequently prevented from accessing Bank B's records.
Which model?
Brewer-Nash / Chinese Wall.
An architect wants to demonstrate that every permitted system transition moves the system from one secure condition to another.
Which model?
State Machine Model.
The primary concern is preventing information from moving between security domains in an unauthorised direction.
Which model concept?
Information Flow Model.
Activity in a highly classified environment must not affect outputs observable by low-classification users in a way that reveals information.
Which model?
Noninterference.
A system compares a user's security label with an object's label and determines access based on dominance relationships.
Which concept?
Lattice-Based Security.
A security mechanism must mediate every subject-to-object access, resist tampering and be capable of verification.
Which concept?
Reference Monitor.
Recognise the Clue Words
Confidentiality
Classified information
No Read Up
No Write Down
Bell-LaPadulaIntegrity
Trusted data
No Read Down
No Write Up
BibaBusiness Transactions
CDI / UDI
TP / IVP
Separation of Duties
Clark-WilsonConflict of Interest
Consultants
Competitors
Previous access
Brewer-NashSecure Transitions
Secure state
State transition
State MachineInformation Movement
Information direction
Security domains
Information FlowIsolation
High activity must not influence low observations
NoninterferenceLabels & Dominance
Clearance
Classification
Compartments
Latticeβ οΈ Common CISSP Mistakes These models are deliberately easy to confuse
Bell-LaPadula's primary concern is CONFIDENTIALITY.
Biba's primary concern is INTEGRITY.
Bell-LaPadula: No Read Up, No Write Down.
Biba: No Read Down, No Write Up.
Its key ideas are controlled transformation, validation and separation of duties.
What you accessed previously may determine what you are allowed to access next.
Having an adequate security level does not necessarily mean a subject has a legitimate requirement or discretionary permission to access every object at that level.
A model does not automatically enforce itself.
The system requires trustworthy mechanisms capable of implementing and enforcing the model.
Fast Identification Table
| If you see... | Think... |
|---|---|
| Military-style confidentiality | Bell-LaPadula |
| No Read Up | Bell-LaPadula |
| No Write Down | Bell-LaPadula |
| Protect integrity | Biba |
| No Read Down | Biba |
| No Write Up | Biba |
| Well-formed transactions | Clark-Wilson |
| CDI / UDI / TP / IVP | Clark-Wilson |
| Separation of duties + integrity | Clark-Wilson |
| Consultants working with competitors | Brewer-Nash |
| Chinese Wall | Brewer-Nash |
| Secure state β secure state | State Machine |
| Direction information is allowed to move | Information Flow |
| High-level activity must not affect low-level observation | Noninterference |
| Labels, compartments and dominance | Lattice Model |
| Mediates every access | Reference Monitor |
Security Models Master Memory Aid
Bell = Secrets Β· Biba = Trust Β· Clark = Transactions Β· Brewer = Conflict
The Bell & Biba Shortcut
Bell stops secrets going DOWN. Biba stops bad data going UP.
Key Takeaways
Security models describe rules for protecting information and controlling interactions between subjects and objects.
Bell-LaPadula protects confidentiality.
Its core memory rules are No Read Up and No Write Down.
Biba protects integrity.
Its core memory rules are No Read Down and No Write Up.
Bell-LaPadula prevents sensitive information from leaking downward while Biba prevents less-trusted information from contaminating higher-integrity information.
Clark-Wilson focuses on commercial integrity through well-formed transactions, validation and separation of duties.
Clark-Wilson uses concepts including CDIs, UDIs, Transformation Procedures and Integrity Verification Procedures.
Brewer-Nash addresses conflicts of interest and is also known as the Chinese Wall model.
Brewer-Nash is dynamic because previous access can influence future access decisions.
State machine models focus on preserving security while the system moves between different states.
Information flow models focus on whether information is permitted to move between subjects, objects or security domains.
Noninterference aims to prevent higher-security activity from affecting what lower-security subjects can observe in a security-relevant way.
Lattice models use security labels and dominance relationships to determine permitted access and information flow.
The reference monitor concept describes a mechanism that mediates security-relevant access and should be protected from tampering, consistently invoked and capable of verification.
For CISSP, first identify the objective: confidentiality, integrity, business integrity or conflict of interest. The correct model usually becomes much easier to recognise.
π Sources & Further Reading Security model terminology and architecture references
- ISC2 - CISSP Certification Exam Outline
View the CISSP Exam Outline - NIST Computer Security Resource Center - Glossary
Browse NIST security terminology - NIST SP 800-160 Vol. 1 Rev. 1 - Engineering Trustworthy Secure Systems
View NIST systems security engineering guidance
