| 1: | Suppose a system implementing Biba's model used the same labels for integrity levels and categories as for security levels and categories. Under what conditions could one subject read an object? Write to an object? |
| 2: | In Pozzo and Gray's modification of LOCUS, what would be the effect of omitting the run-untrusted command? Do you think this enhances or degrades security? |
| 3: | In the Clark-Wilson model, must the TPs be executed serially, or can they be executed in parallel? If the former, why; if the latter, what constraints must be placed on their execution? |
| 4: | Prove that applying a sequence of transformation procedures to a system in a valid state results in the system being in a (possibly different) valid state. |
| 5: | The relations certified (see ER1) and allowed (see ER2) can be collapsed into a single relation. Please do so and state the new relation. Why doesn't the Clark-Wilson model do this? |
| 6: | Show that the enforcement rules of the Clark-Wilson model can emulate the Biba model. |