@inproceedings{Neumann-al:ICSE76,
author = {Peter G. Neumann and
Richard J. Feiertag and
Karl N. Levitt and
Lawrence Robinson},
title = {Software Development and Proofs of {Multi-Level} Security},
booktitle = {ICSE},
pages = {421--428},
publisher = {{IEEE} Computer Society},
year = {1976},
}