Laboratory Information Management Systems

http-equiv="Content-Type" content="text/html;These axioms are meant to be implemented by
charset=utf-8">restriction of access rights that users or
07/15/ 2008processes can have to certain objects like
ABSTRACTdevices and files. The concept of trusted subjects
This is a research conducted by investigating theis a less frequently described part of the
possible practical applications of the Bell-LapadulaBell-LaPadula model.
model in library information management systemsSystems that enforce the axioms of the original
(LIMS). The main aim of modern securityBell-LaPadula model very strictly are often
research is to facilitate the construction ofimpractical, because in a real system, a user might
multilevel secure systems, which can protectneed to invoke operations that would require
information of differing classification from userssubjects to violate the property, even though
that have varying levels of clearance. Sincethey do not go against our basic intuitive concept
publication, the Bell-LaPadula model has helped inof laboratory security. For instance, there might
the advancement of science and technology bybe need in the laboratory to extract an
providing a mathematical basis for theUNCLASSIFIED paragraph from a CONFIDENTIAL
examination of laboratory security. Moreover, thisdocument for use in a document that is
model has been major component of having aUNCLASSIFIED. A system that strictly enforces
disciplined approach to the building of effective andthe properties of the original Bell-LaPadula model
secure laboratory systems.might prohibit this kind of operation. As a result, a
DECLARATIONclass of trusted subjects has had to be included in
I hereby certify that this dissertation constitutesthe Bell-LaPadula model, and is trusted not to
my own product, that where the language ofviolate security, although they might violate the
others is set forth, quotation marks so indicate,property. Laboratory systems that are based on
and that appropriate credit is given where I havethis less restrictive model usually have
used the language, ideas, expressions, or writingsmechanisms that permit some of the operations
of another.. 3that the property would normally not allow.
IntroductionIt should also be noted that a number of projects
The objective of this research is to ascertain thehave used the Bell-LaPadula model for description
ways in which the bell-lapadula model can beof their security requirements, although strict
applied to Laboratory Information Managementenforcement of the Bell-LaPadula axioms without
Systems. Laboratory automation occurs when thethe implementation of trusted subjects turns out
application of technology is used to reduce theto be overly restrictive in these projects. Thus,
need for human intervention in the laboratory.there has been widespread introduction of these
This makes it possible for scientists to exploretrusted processes to implement the concept of
data rates that otherwise may be too fast or tootrusted subjects.
slow for proper scientific examination. In recentThere are also some limitations involved in the use
years, the Bell-LaPadula model has been employedof the Bell-LaPadula model, including an absence of
more and more in scientific laboratories, and haspolicies for changing user access rights. With this
also dominated efforts to build secure computermodel, there can be secure and complete general
systems for laboratory use. Since publication, thedowngrade, and is it is intended for systems that
Bell-LaPadula model has helped in thehave static security levels.
advancement of science and technology byThe Bell-Lapadula model would be a suitable idea
providing a mathematical basis for thefor Laboratory Information Management Systems
examination of laboratory security. Moreover, thisbecause the model focuses on data confidentiality
model is a major component of having aand access to classified information, in contrast to
disciplined approach to building secure andsome other models that describe rules for data
effective laboratory systems. The Bell-LaPadulaprotection and integrity. Clear and concise access
model can also be used to abstractly describe therules for clinical information systems spells out by
computer security system in the laboratory,this model. Furthermore, it reflects current best
without regard to the system's application. Theclinical practice, and it’s informed by the
goal of modern security research is to facilitateactual threats to privacy, its objective is to the
the construction of multilevel secure systems,maximum number of records accessed by any
which can protect information of differinguser, and at the same time the number of users
classification from users that have varying levelswho can access any record and this has to do
of clearance.with controlling information flows across rather
There are some deficiencies inherent in the Bellthan down and at the same time a strong
and LaPadula model, and there have been effortsnotification property should be enforced. I will also
to develop a new approach to defining laboratorydiscuss its relationship with other existing security
security models, on the basis that security modelspolicy models available, and the possibility of its
should be derived from specific applications.usage in other applications where information
Scopeexposure must be localized, which ranges from
This dissertation covers the applicability of theprivate banking to the management of intelligence
bell-lapadula model in Laboratory Informationdata, and much more.
Management Systems, and the limitations involvedAnother area in which laboratories could benefit
in the use of the Bell-LaPadula model, including anby using the Bell-Lapadula model is the multi million
absence of policies for changing user accessdollar drug industry, which requires a high level of
rights. Also to be covered is the relationship thatsecurity and confidentiality since drug research
this model has with other existing security policysensitive, and results or findings in an ongoing
models available, and the possibility of using theresearch may sometimes need to be kept from
model in other applications where informationunauthorized persons.
exposure must be localized, for example in privateApproach
banking and in the management of intelligenceThis research will be conducted by investigating
data.the possible practical applications of the
Problem StatementBell-Lapadula model. This would be conducted and
The use of the Bell and LaPadula Model has beentested physically and objectively. A prototype will
successful in modeling information that is relevantbe built in order for it to be properly tested, since
to security, even though this success might beit is practical. The testing stage will involve
responsible for the vagueness of the model aboutprogramming codes for different levels of
its primitives. This vagueness can also besecurity and the objective is to find out if security
examined with respect to the theory that the Bellcan be breached at any stage.
and LaPadula Model and Noninterference areOutcome
equivalent. Laboratory automation makes it
possible for scientists to explore data rates thatBackground and review of literature
otherwise may be too fast or too slow toRelated Work
properly examine. Therefore, an automatedLiterature
laboratory reduces the need for humanIndustry Sources
intervention and creates a more efficientTheory
environment in which human beings andA
technology can interact to produce a great dealB
more information and accurate data that was not
possible prior to automation.Analysis and Design
Its approach is to define a set of systemA
constraints whose enforcement will prevent anyB
application program executed on the systemC
from compromising system security. The model
includes subjects, which represent active entitiesMethods and Realization
in a system (such as active processes), andA
objects, which represent passive entities (such asB
files and inactive processes). Both subjects andC
objects have security levels, and the constraints
on the system take the form of axioms thatResults and Evaluation
control the kinds of access subjects may have toA
objects. (B
While the complete formal statement of theC
Bell-LaPadula model is quite complex, the model
can be briefly summarized by these two axiomsConclusions
stated below:Lessons Learned
(a) The simple security rule, which states that aFuture Activity
subject cannot read information for which it is notProspects for Further Work
cleared (i.e. no read up)
(b) The property that states that a subjectREFRENCES
cannot move information from an object with aChristine Paszko, Elizabeth Turner, Mary D. Hinton
higher security classification to an object with a(2001).
lower classification (i.e. no write down). (