FIELD NOTE / 2026.09.214 MIN READ / 7 SOURCES

The Minds Behind Computer Security Foundations – 7 People Redefining Software

Seven pioneers helped turn computer security into a discipline built on threat studies, protection principles, access models, intrusion detection, and trustworthy systems.

TL;DR

Computer security became a discipline when researchers stopped treating break-ins as isolated accidents and began developing threat models, protection architectures, design principles, formal access models, intrusion detection, and assurance methods. Ware and Anderson framed the problem; Saltzer, Schroeder, and Lampson supplied enduring protection concepts; Denning and Neumann extended the field into detection and trustworthy systems.[1][2][7]

Why you should read it anyway

Security engineering is unusually unforgiving because success means preventing unauthorized behavior that designers may never observe during normal operation. The foundational work in this article taught engineers to reason about defaults, privilege, mediation, protection domains, risk, and adversarial behavior before implementation.

Imagine where Computer Security Foundations would be without them

Without these foundations, security practice would remain more reactive—patch the breach, add a password, hide the design—rather than architectural. Operating systems, access controls, audit systems, and security evaluations would lack a shared language for reasoning about what must be protected.

Time Estimate of how many years we would be hindered without them for human progress

Editorial counterfactual estimate: 8–15 years. Government and commercial multi-user systems made security research unavoidable, but these reports and papers dramatically accelerated the formation of a coherent technical field.

The 7 people behind Computer Security Foundations

1. Willis Ware

Why they matter: Ware helped make computer security a policy and systems-engineering concern at a time when computers were becoming shared and networked. RAND’s work under his leadership examined the consequences of remote access, multi-user systems, and sensitive information processing.[6] His role was foundational threat framing: the industry had to recognize that shared computers created new security-policy problems before it could design systematic defenses.

2. James Anderson

Why they matter: Anderson’s 1972 Computer Security Technology Planning Study organized security around threats, penetration, design, testing, and the need for a systematic research program.[1] His work became a key bridge between early military/commercial security concerns and a more formal technical discipline.

3. Jerome Saltzer

Why they matter: Saltzer co-authored one of the field’s most influential security papers with Michael Schroeder, including principles such as least privilege, fail-safe defaults, complete mediation, economy of mechanism, and open design.[2][3] These principles remain standard tools for reviewing security architecture today.

4. Michael Schroeder

Why they matter: Schroeder co-authored the Saltzer-Schroeder protection paper and worked on Multics security mechanisms including protection rings.[2] His contribution linked abstract principles to operating-system architecture: security requires hardware/software mechanisms that can enforce privilege boundaries reliably.

5. Butler Lampson

Why they matter: Lampson developed the access-control matrix model and explored protection in multiprogrammed systems. Saltzer and Schroeder explicitly cite his model in their broader treatment of capabilities and access-control lists.[2] His contribution supplied a formal vocabulary for subjects, objects, and permitted operations.

6. Dorothy Denning

Why they matter: Denning became a central security researcher across information flow, cryptography policy, and intrusion detection. SRI’s history records her role with Peter Neumann in developing a real-time intrusion-detection model that became the basis for IDES.[7] Her career helped connect formal security models with detection and policy in real systems.

7. Peter Neumann

Why they matter: Neumann led work on the Provably Secure Operating System and spent decades documenting computer-related risks, security, safety, and reliability.[4][5] His contribution is systems assurance: security failures often emerge from interactions among software, hardware, people, and assumptions rather than one broken algorithm.

How they each differ from one another

Ware and Anderson framed security at policy and research-program scale; Saltzer and Schroeder articulated design principles and mechanisms; Lampson formalized access control; Denning extended security into detection and information-flow thinking; Neumann emphasized assurance and systemic risk. The field grew by connecting all of those levels.

Final Take

Many modern security failures still violate principles written down half a century ago: excessive privilege, unsafe defaults, incomplete checks, needless complexity, and dependence on secret design. The longevity of these ideas is evidence that computer security is as much about architecture and discipline as about new defenses.

RESEARCH / PROVENANCE

Works Cited

7 SOURCES
  1. 01
  2. 02
  3. 03
  4. 04
  5. 05
  6. 06
  7. 07

CodeHistory is a living archive. Citations document the evidence used for this edition; later evidence may refine the account.

Contribute / Corrections

Improve the record.

Use this moderated submission form to suggest a correction, provide a source, challenge a priority claim or identify a missing contributor. Submissions are treated as research leads, not automatically published comments.

Submit a research lead

Please do not submit confidential material or claims you cannot support.