2003/06/26 by Paul A. Karger, Roger R. Schell · 1 citation
Computer Science · #Advanced Malware Detection Techniques #Security and Verification in Computing #Network Security and Intrusion Detection #Trojan #Computer security #Subversion #Computer science #Doors #Malware #Hacker #Vulnerability (computing) #Vulnerability assessment #Internet privacy #Operating system #Political science #Law
paper · doi:10.1109/csac.2002.1176285
openalex publication_date 2003/06/26 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/29
Almost thirty years ago a vulnerability assessment of Multics identified significant vulnerabilities, despite the fact that Multics was more secure than other contemporary (and current) computer systems. Considerably more important than any of the individual design and implementation flaws was the demonstration of subversion of the protection mechanism using malicious software (e.g., trap doors and Trojan horses). A series of enhancements were suggested that enabled Multics to serve in a relatively benign environment. These included addition of "mandatory access controls" and these enhancements were greatly enabled by the fact the Multics was designed from the start for security. However, the bottom-line conclusion was that "restructuring is essential" around a verifiable "security kernel" before using Multics (or any other system) in an open environment (as in today's Internet) with the existence of well-motivated professional attackers employing subversion. The lessons learned from the vulnerability assessment are highly applicable today as governments and industry strive (unsuccessfully) to "secure" today's weaker operating systems through add-ons, "hardening", and intrusion detection schemes.