Thirty Years Later: Lessons from the Multics Security Evaluation Paul A. Karger Roger R. Schell IBM Corp., T. J. Watson Research Center Aesec Corporation Yorktown Heights, NY 10598 Pacific Grove, CA 93950
[email protected] [email protected] ABSTRACT 2 Multics Security Compared to Now Almost thirty years ago a vulnerability assessment of Multics offered considerably stronger security than Multics identified significant vulnerabilities, despite the most systems commercially available today. What factors fact that Multics was more secure than other contempo- contributed to this? rary (and current) computer systems. Considerably more important than any of the individual design and imple- mentation flaws was the demonstration of subversion of 2.1 Security as a Primary Original Goal the protection mechanism using malicious software (e.g., Multics had a primary goal of security from the very trap doors and Trojan horses). A series of enhancements beginning of its design [16, 18]. Multics was originally were suggested that enabled Multics to serve in a rela- conceived in 1965 as a computer utility – a large server tively benign environment. These included addition of system on which many different users might process data. “Mandatory Access Controls” and these enhancements This requirement was based on experience from develop- were greatly enabled by the fact the Multics was designed ing and running the CTSS time sharing system at MIT. from the start for security. However, the bottom-line con- The users might well have conflicting interests and there- clusion was that “restructuring is essential” around a fore a need to be protected from each other – a need quite verifiable “security kernel” before using Multics (or any like that faced today by a typical Application Service Pro- other system) in an open environment (as in today’s vider (ASP) or Storage Service Provider (SSP).