2. [18 points] Bell-LaPadula Model & BiBa Model.
a) Access rights under Bell-LaPadula Model and BiBa Model.
Let TOP SECRET, SECRET, CONFIDENTIAL and UNCLASSIFIED (ordered from highest to
lowest) be security levels.
Let HIGHLY TRUSTED, MEDIUM TRUST, LOW TRUST (ordered from highest to lowest)
be integrity levels.
Let A, B, C be categories.
Specify what kind of access (read, write, both or none) can the following subjects have for the
following objects when the policy is interpreted as Bell-LaPadula and (strict) BiBa, respectively.
\begin{itemize}
\item Alice is cleared for TOP SECRET (A, B) and HIGHLY TRUSTED (C).
\item Bob is cleared for CONFIDENTIAL (B, C) and MEDIUM TRUST (A, C).
\item Document 1 is classified as TOP SECRET (A) and HIGHLY TRUSTED (B, C).
\item Document 2 is classified as CONFIDENTIAL (B), MEDIUM TRUST (C).
\item Document 3 is UNCLASSIFIED and with LOW TRUST.
\end{itemize}
b) Suppose a system uses the same labels (e.g., high, medium, low) for both security levels
and integrity levels. Under what conditions could a subject read an object? Under what
conditions could a subject write to an object? Use Bell-LaPadula Model and BiBa Model
to explain. [6 points]
Bell-LaPadula Model [6 points]
Subject\Object
Alice
Bob
BIBa Model [6 points]
Subject\Object
Alice
Bob
Document 1
Document 2
Document 3
Document 1
Document 2
Document 3