Multics Security Evaluation Volume 2: Vulnerability Analysis

Abstract

A security evaluation of MULTICS for potential use as a two-level (Secret/Top Secret) system in the Air Force Data Services Center (AFDSC) is presented. An overview is provided of the present implementation of the Multics Security controls. The report then details the results of a penetration exercise of Multics on the HIS 645 computer. In addition, preliminary results of a penetration exercise of MULTICS on the new HIS 6180 computer are presented. The report concludes that MULTICS as implemented today is not certifiably secure and cannot be used in an open use multi-level system. However, the Multics security design principles are significantly better than other contemporary systems. Thus, MULTICS as implemented today, can be used in a benign Secret/Top Secret environment. In addition, MULTICS forms a base from which a certifiably secure open use multi-level system can be developed.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Jun 01, 1974
Accession Number
ADA001120

Entities

People

  • Paul A. Karger
  • Roger R. Schell

Tags

Communities of Interest

  • Weapons Technologies

DTIC Thesaurus Topics

  • Air Force
  • Artificial Intelligence
  • Computer Access Control
  • Computer Programming
  • Computer Programs
  • Computers
  • Cybersecurity
  • Debugging
  • Identification
  • Information Systems
  • Language
  • Maintenance Personnel
  • Manpower Utilization
  • Object Code
  • Operating Systems
  • Procurement
  • Standards

Fields of Study

  • Computer science
  • Engineering

Readers

  • Computer Science.
  • Cybersecurity.