Separate authentication from authorization, model access rights, apply least privilege and trace how the kernel reference monitor protects system objects.
Level 12 of 15Intermediate100–125 minutesPolicy decision lab
BY THE END, YOU CAN
Reason about protection
Apply CIA and least privilege.
Compare ACLs and capabilities.
Separate identity and permission.
Explain common OS attack classes.
Design layered controls and audits.
01 • DEFINE THE SECURITY GOAL
Protection Controls Use; Security Resists Misuse
CONFIDENTIALITY
Prevent unauthorized disclosure
Permissions, isolation and encryption limit who can observe information.
INTEGRITY
Prevent unauthorized change
Access control, signed code, audit logs and safe update paths protect correctness.
AVAILABILITY
Keep service usable
Quotas, rate limits, redundancy and recovery reduce accidental and deliberate disruption.
least privilegedefault denycomplete mediationdefense in depthseparation of duty
A trusted reference monitor must mediate every access, resist tampering and remain small enough to analyze. User/kernel mode, page permissions and system calls provide the mechanism; policy decides which accesses should be granted.
02 • REPRESENT WHO MAY DO WHAT
Access Matrix Rows Are Subjects; Columns Are Objects
Strong central control; less discretionary flexibility
Authentication establishes an identity using evidence. Authorization evaluates that identity, requested operation, target object and context. Auditing records what occurred; it does not itself prevent the action.
03 • INTERACTIVE REFERENCE-MONITOR LAB
Evaluate Role, Resource and Action
READY
Default deny
Select an access request to see the explicit policy decision.