Harrison-Ruzzo-Ullman model: A formal model used for expressing access control policies and analyzing their security properties. Named after its creators, Michael A. Harrison, Walter L. Ruzzo, and Jeffrey D. Ullman, the model focuses on determining whether a system configuration could allow a subject to acquire unauthorized access rights. It’s particularly known for its undecidable safety problem – it’s not generally possible to determine whether a given system is ‘safe’ against privilege escalation.
Categories: CC D3: Access Controls Concepts | CCSP D5: Cloud Security Operations | CISM D3: Information Security Program | CISSP D3: Security Architecture and Engineering | Security+ D1: General Security Concepts | SSCP D2: Access Controls
« Back to Glossary Index