Download Security Models and Graphical Representation of Security
Transcript
Chapter 1 – Introduction 1.1 Motivation and Aim of the Project When attempting to understand computer security models, people are often exposed to a vast amount of formal and mathematical detail and little visual representation. This can make it difficult to understand what the models represent and what the properties of each model mean. It is often difficult to visualise security models and this can also make it harder for people to understand them. Therefore, this project aimed to simplify the complexity of security models by representing them graphically. The aim of this project was to investigate different models for computer security and to produce a piece of software, which demonstrated one or more of these models through the use of graphical metaphors. Through this, the goal was to determine whether security can be represented adequately through the use of graphical metaphors and also to determine how much these metaphors can aid in the understanding of the structure and the features of a security model. 1.2 Minimum Requirements The minimum requirements agreed for this project were: 1. To investigate at least two different computer security models. 2. To compare these security models with SQL Server 2000's security model. 3. To devise a suitable graphical metaphor to represent one of these security models. 4. To design and develop software that implements at least one graphical metaphor. 5. To test and evaluate the software that has been produced 1.3 Evaluation Criteria Upon the completion of the project, the success of the project was to be evaluated. To evaluate the project, a set of evaluation criteria were defined. These were: - 1. Evaluating the Objectives and Minimum Requirements • Has the project achieved the objectives that have been set out? This criterion will evaluate the success of the project in relation to the objectives that were set out at the start of the project. • Has the project achieved the minimum requirements or have they been exceeded? This criterion will evaluate whether the project has actually achieved the minimum requirements that were set out and whether or not these were exceeded in any way. 1