Multics security evaluation: vulnerability analysis

The work

AuthorsPaul A. Karger; Roger R. Schell
Typeinproceedings
Year2002
Citekeykarger2002multics

Where it appeared

Published in18th Annual Computer Security Applications Conference (ACSAC 2002)
Pages127--146

Related

Distinct fromkarger2002thirty Companion papers, both at ACSAC 2002. One is the reprint of Karger and Schell's 1974 report Multics Security Evaluation: Vulnerability Analysis (ESD-TR-74-193 Vol. II); the other is their retrospective written to accompany it, 'Thirty years later'. Neither reprints or supersedes the other -- they were published together and are meant to be read that way, the evidence and the authors' later assessment of it.

Abstract

A security evaluation of Multics for potential use as a two-level (Secret/Top Secret) system in the Air Force Data Services Center (AFDSC) is presented. An overview is provided of the present implementation of the Multics Security controls. The report then details the results of a penetration exercise of Multics on the HIS 645 computer. In addition, preliminary results of a penetration exercise of Multics on the new HIS 6180 computer are presented. The report concludes that Multics as implemented today is not certifiably secure and cannot be used in an open use multi-level system. However, the Multics security design principles are significantly better than other contemporary systems. Thus, Multics as implemented today, can be used in a benign Secret/Top Secret environment. In addition, Multics forms a base from which a certifiably secure open use multi-level system can be developed.

A copy is held

pdf, 2.2 MB. Not published — it may be under copyright. The facts and links here are.

How it got here

How it got hereagent via openalex
Added2026-08-13 00:00 UTC
Approved bya person 2026-08-16 15:34 UTC

Cite it as

@inproceedings{karger2002multics,
  title        = {Multics security evaluation: vulnerability analysis},
  author       = {Paul A. Karger and Roger R. Schell},
  year         = {2002},
  booktitle    = {18th Annual Computer Security Applications Conference (ACSAC 2002)},
  pages        = {127--146},
  doi          = {10.1109/csac.2002.1176286},
}

This record lives at https://refs.drheap.org/karger2002multics/ and will keep doing so.