Thirty years later: lessons from the Multics security evaluation
The work
| Authors | P.A. Karger; R.R. Schell |
|---|---|
| Type | inproceedings |
| Year | 2002 |
| Citekey | karger2002thirty |
Where it appeared
| Published in | 18th Annual Computer Security Applications Conference (ACSAC 2002) |
|---|---|
| Publisher | IEEE Comput. Soc |
| Pages | 119--126 |
Identifiers
| DOI | 10.1109/csac.2002.1176285 |
|---|
Access
| Landing page | https://doi.org/10.1109/csac.2002.1176285 |
|---|
Related
| Distinct from | karger2002multics Companion papers, both at ACSAC 2002. One is the reprint of Karger and Schell's 1974 report Multics Security Evaluation: Vulnerability Analysis (ESD-TR-74-193 Vol. II); the other is their retrospective written to accompany it, 'Thirty years later'. Neither reprints or supersedes the other -- they were published together and are meant to be read that way, the evidence and the authors' later assessment of it. |
|---|
Abstract
Almost thirty years ago a vulnerability assessment of Multics identified significant vulnerabilities, despite the fact that Multics was more secure than other contemporary (and current) computer systems. Considerably more important than any of the individual design and implementation flaws was the demonstration of subversion of the protection mechanism using malicious software (e.g., trap doors and Trojan horses). A series of enhancements were suggested that enabled Multics to serve in a relatively benign environment. These included addition of "mandatory access controls" and these enhancements were greatly enabled by the fact the Multics was designed from the start for security. However, the bottom-line conclusion was that "restructuring is essential" around a verifiable "security kernel" before using Multics (or any other system) in an open environment (as in today's Internet) with the existence of well-motivated professional attackers employing subversion. The lessons learned from the vulnerability assessment are highly applicable today as governments and industry strive (unsuccessfully) to "secure" today's weaker operating systems through add-ons, "hardening", and intrusion detection schemes.
How it got here
| How it got here | agent via unpaywall |
|---|---|
| Added | 2026-08-13 00:00 UTC |
| Not denied by | a person 2026-08-14 11:37 UTC |
Filed under
Cite it as
@inproceedings{karger2002thirty,
title = {Thirty years later: lessons from the Multics security evaluation},
author = {P.A. Karger and R.R. Schell},
year = {2002},
booktitle = {18th Annual Computer Security Applications Conference (ACSAC 2002)},
pages = {119--126},
publisher = {IEEE Comput. Soc},
doi = {10.1109/csac.2002.1176285},
}
This record lives at https://refs.drheap.org/karger2002thirty/ and will keep doing so.