Protection And Security



1058.pngProtection: mechanisms that prevent accidental or intentional misuse of a system.

  • Accidents: generally easier to solve (make them unlikely)
  • Malicious abuse: much more difficult to eliminate (can’t leave any loopholes, can’t use probabilities).

1063.pngThree aspects to a protection mechanism:

  • Authentication: identify a responsible party (principal) behind each action.
  • Authorization: determine which principals are allowed to perform which actions.
  • Access enforcement: combine authentication and authorization to control access.

