-
3
-
-
0026154766
-
Verification of secure distributed systems in higher order logic: a modular approach using generic components
-
Oakland, CA
-
Alves-Foss, J. and Levitt, K. (1991) ‘Verification of secure distributed systems in higher order logic: a modular approach using generic components’, Proc. IEEE Symposium on Research in Security and Privacy, Oakland, CA, pp.122–135.
-
(1991)
Proc. IEEE Symposium on Research in Security and Privacy
, pp. 122-135
-
-
Alves-Foss, J.1
Levitt, K.2
-
5
-
-
12344297027
-
Real-time software goes modular
-
September
-
Ames, B. (2003) ‘Real-time software goes modular’, Military and Aerospace Electronics, September, Vol. 14, No. 9.
-
(2003)
Military and Aerospace Electronics
, vol.14
, Issue.9
-
-
Ames, B.1
-
6
-
-
0004200684
-
Computer security technology planning study
-
Tech. Rep. ESD-TR-73–51, October, Bedford, Mass
-
Anderson, J. (1972) ‘Computer security technology planning study’, USAF Electronic Systems Div., Tech. Rep. ESD-TR-73–51, October, Bedford, Mass.
-
(1972)
USAF Electronic Systems Div.
-
-
Anderson, J.1
-
7
-
-
0003400251
-
-
Tech. Rep. MTR-2997, The MITRE Corporation, July, Bedford, MA
-
Bell, D.E. and LaPadula, L.J. (1975) Secure Computer Systems: Unified Exposition and Multics Interpretation’, Tech. Rep. MTR-2997, The MITRE Corporation, July, Bedford, MA.
-
(1975)
Secure Computer Systems: Unified Exposition and Multics Interpretation
-
-
Bell, D.E.1
LaPadula, L.J.2
-
10
-
-
48249125979
-
Formal construction of the mathematicaly analyzed separation kernel
-
Martin, W., White, P., Taylor, F. and Goldberg, A. (2001) ‘Formal construction of the mathematicaly analyzed separation kernel’, Proc. of the 15th International Conference on Automated Software Engineering, pp.133–141.
-
(2001)
Proc. of the 15th International Conference on Automated Software Engineering
, pp. 133-141
-
-
Martin, W.1
White, P.2
Taylor, F.3
Goldberg, A.4
-
11
-
-
0023829319
-
Noninterference and the composability of security properties
-
Oakland, CA
-
McCullough, D. (1988a) ‘Noninterference and the composability of security properties’, Proc. IEEE Symposium on Security and Privacy, Oakland, CA, pp.177–187.
-
(1988)
Proc. IEEE Symposium on Security and Privacy
, pp. 177-187
-
-
McCullough, D.1
-
13
-
-
84949687909
-
-
Master’s Thesis, Dept. Computer Science, University of Idaho, Moscow, ID, December
-
O’Connell, P. (2003) The Idaho Partitioning Machine: A Mils Partitioning Kernel Model in ACL2, Master’s Thesis, Dept. Computer Science, University of Idaho, Moscow, ID, December.
-
(2003)
The Idaho Partitioning Machine: A Mils Partitioning Kernel Model in ACL2
-
-
O’Connell, P.1
-
16
-
-
0020273088
-
Proof of separability: a verification technique for a class of security kernels
-
Lecture Notes in Computer Science, Torino, Italy
-
Rushby, J. (1982) ‘Proof of separability: a verification technique for a class of security kernels’, Proc. International Symposium on Programming, Lecture Notes in Computer Science, Torino, Italy, Vol. 137, pp.352–367.
-
(1982)
Proc. International Symposium on Programming
, vol.137
, pp. 352-367
-
-
Rushby, J.1
-
17
-
-
0020779556
-
A distributed secure system
-
Rushby, J. and Randell, B. (1983) ‘A distributed secure system’, IEEE Computer, Vol. 16, No. 7, pp.55–67.
-
(1983)
IEEE Computer
, vol.16
, Issue.7
, pp. 55-67
-
-
Rushby, J.1
Randell, B.2
-
18
-
-
0016555241
-
The protection of information in computer systems
-
September
-
Saltzer, J. and Schroeder, M. (1975) ‘The protection of information in computer systems’, Proceedings of the IEEE, September, Vol. 63, No. 9, pp.1278–1308.
-
(1975)
Proceedings of the IEEE
, vol.63
, Issue.9
, pp. 1278-1308
-
-
Saltzer, J.1
Schroeder, M.2
-
19
-
-
0026851778
-
BLACKER: Security for the DDN examples of A1 security engineering trades
-
Oakland, CA
-
Weissman, C. (1992) ‘BLACKER: Security for the DDN examples of A1 security engineering trades’, Proc. IEEE Symposium on Research in Security and PrivacyOakland, CA, pp.286–292.
-
(1992)
Proc. IEEE Symposium on Research in Security and Privacy
, pp. 286-292
-
-
Weissman, C.1
-
20
-
-
33747861237
-
-
October, Draft
-
White, P., van Fleet, W. and Dailey, C. (2000) High Assurance Architecture Via Separation Kernel, October, Draft.
-
(2000)
High Assurance Architecture Via Separation Kernel
-
-
White, P.1
van Fleet, W.2
Dailey, C.3
-
21
-
-
84949687910
-
-
Software considerations in airborne systems and equipment certification (RTCA DO-178b), RTCA Std., December 1992
-
Software considerations in airborne systems and equipment certification (RTCA DO-178b), RTCA Std., December 1992.
-
-
-
-
22
-
-
84949687911
-
-
Requirements specification for Avionics Computer Resource (ACR) (RTCA DO-255), RTCA Std., June 2000
-
Requirements specification for Avionics Computer Resource (ACR) (RTCA DO-255), RTCA Std., June 2000.
-
-
-
-
23
-
-
84949687912
-
-
Common criteria for information technology security evaluation, Version 2.1, common criteria project sponsoring organisation std., August 1999
-
Common criteria for information technology security evaluation, Version 2.1, common criteria project sponsoring organisation std., August 1999.
-
-
-
-
24
-
-
84949687913
-
-
Avionic application software standard interface (Draft 3 of Supplement 1) (Specification ARINC 653), ARINC Std., 2003
-
Avionic application software standard interface (Draft 3 of Supplement 1) (Specification ARINC 653), ARINC Std., 2003.
-
-
-
-
25
-
-
84949687914
-
-
Department of defense trusted computer system evaluation criteria, department of defense computer security center std. DoD 5200.28-STD, December 1985
-
Department of defense trusted computer system evaluation criteria, department of defense computer security center std. DoD 5200.28-STD, December 1985.
-
-
-
-
26
-
-
84949687915
-
-
The partitioning kernel protection profile, the open group, June 2003, draft under review
-
The partitioning kernel protection profile, the open group, June 2003, draft under review.
-
-
-
-
27
-
-
84949687916
-
-
In general, MILS inter-partition communication may occur through any verified communication channel offered through the kernel
-
In general, MILS inter-partition communication may occur through any verified communication channel offered through the kernel.
-
-
-
|