Материал: Крючков Фундаменталс оф Нуцлеар Материалс Пхысицал Протецтион 2011

Внимание! Если размещение файла нарушает Ваши авторские права, то обязательно сообщите нам

in this respect) requires 37K of memory per connection, which may be a potential problem with large networks;

∙ any change to the business logic leads to the necessity of changing software for all workstations.

Being simple, this model is highly convenient in environments with a limited number of workstations. An optimum exists beyond which problems start to arise as described above.

An alternative dual-linked circuit is a model with a “thin” client and a “thick” server. Unlike the previous model, this has business logic moved to the server. This is a diversely realizable model using different software. In particular, MS SQL Server enables the writing of so-called stored procedures in a query language. These procedures realize business logic. Some DBMSs have auxiliary capabilities, including change, rule incorporation or data value limiting admissibility checks, with no excessive data communicated over the network. Such systems however require the server RAM for each connection so new constraints additionally emerge. First, this requires rather a high-power DBMS. For example, unlike the first model realizable in MS Access, the second model requires MS SQL Server to realize. Furthermore, different firmware has somewhat different query language syntax. This makes the approach in question somewhat limiting to the system evolution capabilities and requires use of a more powerful DBMS, e.g. Oracle.

The client/server model is evolving further towards a decentralized computation process, and multilink client/server systems are realized so. Fig. 7.2 shows a schematic of a triple-linked client/server model.

Such architecture offers an extra link between the “thin” client and the “thin” server and has components of it linked via s tandard network protocols, say, TCP/IP. This auxiliary feature contains core business logic. The distinction of these systems is that they do not need RAM on the database server to support each connection to the client.

Where triple-linked systems are set up, all three application levels (presentation logic, business logic and data access logic) are partitioned throughout. This gives the system more flexibility and makes it easier to upgrade any level. Such system has extra services, e.g. Internet, e-mail and phone or fax communications, easily connected thereto.

Database and application servers for small networks and slack applications can be physically combined in one computer. This, however, will still make a triple-linked system because it has a functionally separated logic.

311

Workstations

∙ Presentation logic

(interface)

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

∙ Business logic

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

∙ Data access logic

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

(accountancy rules)

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Application

Database

server

server

Fig. 7.2. A triple-linked client/server model

The multilink model tends to evolve towards so-called n–linked client/server systems. These systems retain all the benefits offered by the triple-linked model and have business logic distributed among a number of servers, this making it possible for the client to choose the one it needs at the time. Connection to different database servers is also in place. Such a system displays excellent flexibility, ease of modification and a capability for new applications to be inserted. The system components can be spatially separated. Global Internet is a global example. Any user can exploit business logic of many search servers and select data from the source required.

The most recent technology of multilink model realization is Web– service. This technology makes it possible to get required data in standard formats without dedicated software or hardware.

Microsoft experts give the following definition of Web–service: Web– service based on XML is used for exchange of data between applications and enables other applications to be called irrespective of how these are organized, what platform is used for operation and what tools are employed to make them accessible.

Requests come to Web–services via various standard network protocols from applications realized based on different software and hardware platforms with the result going back in standard XML coding. Large

312

applications are broken down into independent parts which exist on the application servers as Web–services.

7.3. Base software

The industry standard [1] identifies the following three types of base software:

∙operating systems;

∙database management systems;

∙development tools.

Base software used in computerized NM A&C systems must be certified to the respective information access security class. The requirements to information security are set forth in the Guidelines of the Russian Federation’s Gostekhkomissiya (State Technical Commission) which govern the classification of NM A&C systems [4]. Details of the base software classification and information security requirements, depending on the specified class, will be discussed in Chapter 8. There are no special requirements to development tools.

Hereinafter, we shall consider in more details each base software type. Requirements imposed on these by the industry standard will be discussed, modern software will be reviewed in brief and advanced software considered.

7.3.1. Operating systems

Operating system (OS) is essential software needed to form the NM A&C system’s working environment. OS is what primarily secures the information system against unauthorized access and defines reliability thereof.

The requirements to operating systems are set forth in the industry standard and in data access security requirements of Gostekhkomissiya. The industry standard requires that an operating system should contain and ensure:

∙networking features;

∙data access security features;

∙log-in access control;

∙memory protection;

∙discrete and accounted for access to resources;

∙error handling facilities;

∙operability support facilities;

313

∙advanced database access providers;

∙support of distributed network protocols;

∙hardware fault tolerance;

∙system operation statistics. An OS may support:

∙client/server technology;

∙multitasking with a prioritization system;

∙workstation networking capabilities;

∙uninterruptible power supply. The standard’s requirements are rather general and do not establish particular criteria. More specified requirements imposed on operating systems by the classification of NM A&C systems introduced are set forth in Gostekhkomissiya’s Guidelines [4]. The document specifies requirements to various data security subsystems, as well as certification and qualification requirements depending on the class of the system.

A major technical problem developers of computerized NM A&C systems are faced with is lack of operating systems certified to classes higher than 3. A number of Microsoft Windows NT 4.0 modifications have been currently certified by Gostekhkomissiya for use in computerized NM A&C systems. The system itself is certified to data access security class 3, the certificate thereof having been renewed more than once.

An OS certified to access security class 3 do not permit operating data of different sensitivity levels, this making it impossible to use it at most nuclear material handling sites. More than that, Windows NT 4.0 is a legacy system. Microsoft said they would stop to support this OS in 2004. So a top-priority task the Federal Information System is faced with now is to certify a new OS for use in class 3 systems and choose a system to build class 2 NM A&C systems.

There are two ways to address the problem. The first one is to use Microsoft software. Prerequisites exist for Windows 2000 to be accepted as an advanced operating system. This operating system has been internationally certified to class 4 [5–7], so cert ifying it to class 3 under Gostekhkomissiya’s requirements to NM A&C systems is not expected to be technically complicated. The system is an evolution of NT-based operating systems, so it will not be a problem to adapt existing applied software to the new system. Responding to the criticism of its software openness policies, Microsoft after all announced its GSP (Government Security Program). The GSP is Microsoft’s answer to states’ demand for secure information systems. The partnership in the GSP has entitled

314

Russian organizations to getting access to Windows source code. The GSP will also connect developers in Russia to joint work with Microsoft to verify security functions and to other research activities planned as part of the program. Apart from the source code access, the GSP members will be provided with the Windows platform technical details to enable design and creation of still more secure computation systems. Experts in the industry believe the GSP may help bring Microsoft products, Windows 2000 in particular, to the level of security class 2 [8]. Another approach relies on plain-code base software meaning use of a Linux-based operating system. This approach is based on a license agreement enabling the system to be readily modified with a capability to build a Linux distributive to be certified to security class 2. The reasoning behind the latter approach is that open-code software is relatively cheap.

As of the time this handbook was being redacted, things with getting operating systems certified stood like this. Because of organizational problems, which were partly due to the restructuring of the industry’s executive bodies, the Windows 2000 codes were made available only in late 2006. This operating system had been obsolete by the time. So the requirement now is to have Windows XP and Windows 2003 Server, Microsoft’s next-generation operating systems, certified. Accordingly, no work is under way to bring the Windows NT family operating systems to the level of the access security class 2 requirements for NM A&C systems.

In parallel, Yanux 2.0 [9], a secure Linux-based operating system, was built by NPO “Luch” in Podolsk. Subject to [10], th is system was certified in 2005 to access security class 2 under requirements for NM A&C systems [4].

Further listed are the major features a secure operating system is expected to possess and the implementation thereof will be looked at using Windows NT operating systems as an example.

A secure OS is expected to feature [11]:

∙identification and authentication capabilities;

∙management and control of access to all system resources;

∙auditing of events;

∙resiliency and resilience tools;

∙control of covert data leakage channels.

Most secure operating systems operate on a microkernel basis. The microkernel resides in memory and controls data flows among components of the system. Any application refers to the microkernel for the permit to execute commands. Using special server processes, the microkernel checks

315

Источник: https://studfile.net/preview/16708779/