A multilevel secure constrained intrusion detection system prototype

Approved for public release; distribution is unlimited === The Monterey Security Architecture (MYSEA) provides a distributed multilevel secure (MLS) environment consisting of a MLS local area network (LAN) and multiple single-level networks. The MYSEA server enforces a mandatory access control polic...

Full description

Bibliographic Details
Main Author: Ang, Kah Kin.
Other Authors: Irvine, Cynthia E.
Published: Monterey, California. Naval Postgraduate School 2012
Online Access:http://hdl.handle.net/10945/5026
id ndltd-nps.edu-oai-calhoun.nps.edu-10945-5026
record_format oai_dc
spelling ndltd-nps.edu-oai-calhoun.nps.edu-10945-50262015-08-06T16:02:08Z A multilevel secure constrained intrusion detection system prototype Ang, Kah Kin. Irvine, Cynthia E. Nguyen, Thuy D. Naval Postgraduate School (U.S.) Computer Science Approved for public release; distribution is unlimited The Monterey Security Architecture (MYSEA) provides a distributed multilevel secure (MLS) environment consisting of a MLS local area network (LAN) and multiple single-level networks. The MYSEA server enforces a mandatory access control policy to ensure that users can only access data for which they are authorized. Intrusion detection systems (IDS) placed on a single-level network can store the alerts in the IDS databases at the same classification level as the network being monitored. As most databases do not support the enforcement of mandatory security policies, access to these databases is restricted to singlelevel access only. Thus, administrators are not presented with a coherent view of IDS alerts from all of the connected networks. The objective of this thesis is to design a database proxy to allow administrators to view and analyze IDS information at multiple classification levels while enforcing the systems overall mandatory policy. Based on the derived concept of operations and the requirements, a design for the database proxy that mediates access to databases at different levels was conceived. A prototype database proxy was implemented along with modifications to a web-based analysis tool to allow the viewing and analysis of IDS information at multiple classification levels. 2012-03-14T17:43:57Z 2012-03-14T17:43:57Z 2010-12 Thesis http://hdl.handle.net/10945/5026 698376301 This publication is a work of the U.S. Government as defined in Title 17, United States Code, Section 101. As such, it is in the public domain, and under the provisions of Title 17, United States Code, Section 105, it may not be copyrighted. Monterey, California. Naval Postgraduate School
collection NDLTD
sources NDLTD
description Approved for public release; distribution is unlimited === The Monterey Security Architecture (MYSEA) provides a distributed multilevel secure (MLS) environment consisting of a MLS local area network (LAN) and multiple single-level networks. The MYSEA server enforces a mandatory access control policy to ensure that users can only access data for which they are authorized. Intrusion detection systems (IDS) placed on a single-level network can store the alerts in the IDS databases at the same classification level as the network being monitored. As most databases do not support the enforcement of mandatory security policies, access to these databases is restricted to singlelevel access only. Thus, administrators are not presented with a coherent view of IDS alerts from all of the connected networks. The objective of this thesis is to design a database proxy to allow administrators to view and analyze IDS information at multiple classification levels while enforcing the systems overall mandatory policy. Based on the derived concept of operations and the requirements, a design for the database proxy that mediates access to databases at different levels was conceived. A prototype database proxy was implemented along with modifications to a web-based analysis tool to allow the viewing and analysis of IDS information at multiple classification levels.
author2 Irvine, Cynthia E.
author_facet Irvine, Cynthia E.
Ang, Kah Kin.
author Ang, Kah Kin.
spellingShingle Ang, Kah Kin.
A multilevel secure constrained intrusion detection system prototype
author_sort Ang, Kah Kin.
title A multilevel secure constrained intrusion detection system prototype
title_short A multilevel secure constrained intrusion detection system prototype
title_full A multilevel secure constrained intrusion detection system prototype
title_fullStr A multilevel secure constrained intrusion detection system prototype
title_full_unstemmed A multilevel secure constrained intrusion detection system prototype
title_sort multilevel secure constrained intrusion detection system prototype
publisher Monterey, California. Naval Postgraduate School
publishDate 2012
url http://hdl.handle.net/10945/5026
work_keys_str_mv AT angkahkin amultilevelsecureconstrainedintrusiondetectionsystemprototype
AT angkahkin multilevelsecureconstrainedintrusiondetectionsystemprototype
_version_ 1716815985944559616