Download Security Models and Graphical Representation of Security

Transcript
Chapter 1 – Introduction
1.1 Motivation and Aim of the Project
When attempting to understand computer security models, people are often exposed to a vast amount
of formal and mathematical detail and little visual representation. This can make it difficult to
understand what the models represent and what the properties of each model mean. It is often difficult
to visualise security models and this can also make it harder for people to understand them. Therefore,
this project aimed to simplify the complexity of security models by representing them graphically.
The aim of this project was to investigate different models for computer security and to produce a
piece of software, which demonstrated one or more of these models through the use of graphical
metaphors. Through this, the goal was to determine whether security can be represented adequately
through the use of graphical metaphors and also to determine how much these metaphors can aid in
the understanding of the structure and the features of a security model.
1.2 Minimum Requirements
The minimum requirements agreed for this project were:
1. To investigate at least two different computer security models.
2. To compare these security models with SQL Server 2000's security model.
3. To devise a suitable graphical metaphor to represent one of these security models.
4. To design and develop software that implements at least one graphical metaphor.
5. To test and evaluate the software that has been produced
1.3 Evaluation Criteria
Upon the completion of the project, the success of the project was to be evaluated. To evaluate the
project, a set of evaluation criteria were defined. These were: -
1. Evaluating the Objectives and Minimum Requirements
•
Has the project achieved the objectives that have been set out?
This criterion will evaluate the success of the project in relation to the objectives that were set
out at the start of the project.
•
Has the project achieved the minimum requirements or have they been exceeded?
This criterion will evaluate whether the project has actually achieved the minimum
requirements that were set out and whether or not these were exceeded in any way.
1