Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

The Bell–LaPadula security model is a formal model for protecting confidentiality in computer systems that handle information at multiple security levels. It uses rules about a subject’s clearance, an object’s classification, and the permitted access mode to control how information can be read or written.

What the Bell–LaPadula model means

The Internet Engineering Task Force (IETF) defines Bell–LaPadula as “A formal, mathematical, state-transition model of confidentiality policy for multilevel-secure computer systems.” In this context, a subject is an active entity, such as a user or process, and an object is a passive resource, such as a file. The model describes which access operations are allowed while the system remains in a secure state.

Security levels can include both a classification and compartments or categories. The model therefore uses the relation dominates, rather than assuming every level can be represented by a simple rank. Whether an operation is permitted depends on the subject, the object, the access mode, and the policy rules in force. RFC 4949, Internet Security Glossary, Version 2

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What are the main Bell–LaPadula rules?

Simple security property: no read up

A subject may read an object only if the subject’s clearance dominates the object’s classification. Put simply, a subject cannot read information above its clearance. This mandatory rule limits disclosure through reading.

#1 Best Overall

*-property: no write down

The *-property restricts writing so that a subject cannot pass information from a higher security level to a lower one in a way that discloses the higher-level information. It is commonly summarized as “no write down.” RFC 4949 also calls it the confinement property.

Discretionary security property

Bell–LaPadula also includes a discretionary rule. In addition to satisfying mandatory label-based restrictions, a subject must have permission for the particular object and access mode, often represented with an access matrix. A discretionary permission does not override a mandatory security-level restriction. NIST, Proceedings of the 9th National Computer Security Conference

Why the rules matter

Together, the familiar “no read up” and “no write down” rules aim to prevent information from flowing to subjects or destinations that should not receive it under the confidentiality policy. They describe restrictions on access and information flow; they are not a complete security architecture or a guarantee that a system is secure simply because it assigns labels.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The model addresses confidentiality, not every security objective. For example, it does not by itself provide a complete account of integrity or availability. RFC 4949 contrasts Bell–LaPadula with the Biba model, which addresses integrity and whose rules are duals of corresponding Bell–LaPadula rules. RFC 4949

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Origin and historical nuance

RFC 4949 attributes the model to David Bell and Leonard LaPadula at MITRE in 1973. The University of California, Davis Security Lab archive lists their 1973 mathematical-model reports and their 1976 report, Secure Computer System: Unified Exposition and MULTICS Interpretation. The archive describes the 1976 work as collecting earlier material and adapting rules to the evolving Multics security-kernel design. UC Davis Security Lab, Computer Security History

One version-dependent detail is tranquility, the principle that security labels do not change in ways that undermine the policy. RFC 4949 includes tranquility among the model’s properties. However, the NIST-hosted 1986 proceedings explain that the original 1973 version included it, while the 1976 version removed it to allow controlled changes to active-object security levels. The safeguards for such changes depend on the application, so tranquility should not be treated as an invariant of every Bell–LaPadula formulation. NIST proceedings

What the model does not establish

  • It does not prove that a real system is secure merely because the system uses classifications or clearances.
  • Its conclusions depend on how the system is modeled, which levels and access modes it defines, and whether its rules preserve secure states.
  • It is a confidentiality policy model, not a standalone solution for integrity, availability, or every security threat.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.