Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

// request.cf · coarse context

A page that knows where it met you.

Only coarse request metadata is shown. This demo does not display or persist visitor IP addresses.

Country
US
Cloudflare location
CMH
Connection
HTTP/2
Language
Not provided

Ray ID: a463293759ceb965

Jump to content

// Workers AI · dad joke modeWhat did the high-water mark say? I've peaked.

From Wikipedia, the free encyclopedia

In the fields of physical security and information security, the high-water mark for access control was introduced by Clark Weissman in 1969.[1] It pre-dates the Bell–LaPadula security model, whose first volume appeared in 1972.

Under high-water mark, any object less than the user's security level can be opened, but the object is relabeled to reflect the highest security level currently open, hence the name.

The practical effect of the high-water mark was a gradual movement of all objects towards the highest security level in the system. If user A is writing a CONFIDENTIAL document, and checks the unclassified dictionary, the dictionary becomes CONFIDENTIAL. Then, when user B is writing a SECRET report and checks the spelling of a word, the dictionary becomes SECRET. Finally, if user C is assigned to assemble the daily intelligence briefing at the TOP SECRET level, reference to the dictionary makes the dictionary TOP SECRET, too.

Low-water mark

[edit]

Low-water mark is an extension to Biba Model. In the Biba model, no-write-up and no-read-down rules are enforced. In this model, the rules are exactly opposite of the rules in Bell-La Padula model. In the low-water mark model, read down is permitted, but the subject label, after reading, will be degraded to object label. It can be classified in floating label security models.[2][3]

See also

[edit]

References

[edit]
  1. ↑ Clark Weissman (1969). "Security controls in the ADEPT-50 timesharing system". AFIPS Conference Proceedings FJCC. Vol. 35. pp. 119–133. doi:10.1145/1478559.1478574.
  2. ↑ "The LOMAC project". Retrieved 16 February 2011.
  3. ↑ NAI Labs Advanced Research. "LOMAC: Low Water-Mark Integrity Protection for Linux" (PDF). Archived from the original (PDF) on 16 July 2011. Retrieved 16 February 2011.