James P. Anderson

Applying the Reference Monitor Concept to Security

by Dan Geer

Anderson made many contributions, but for the purpose of this nomination I will highlight a mere two of them. The first is the 1972 paper now known as "The Anderson Report" (which followed on the 1968 Defense Science Board's "Ware Report" in which Anderson also participated). That "Anderson Report" set the U.S. information security research agenda for over a decade, and rightly so. You can read it here:

Anderson also developed the ideas that we today call "Intrusion Detection" in his 1980 work "Computer Security Threat Modeling & Surveillance." Similarly, you can read that work here:

Altogether, Anderson was involved in something over two hundred reports and standards including "The Rainbow Series" and, in particular, "The Orange Book" where, amongst many other places, Anderson contributed the Reference Monitor concept. In Peter Denning's words, Anderson did not invent the RefMon term, but rather "Jim recognized the fundamental importance of the reference monitor for computer security practice and stumped endlessly for its adoption."

Gene Spafford's encomium overlaps much of this note; see:

