Материал: Крючков Фундаменталс оф Нуцлеар Материалс Пхысицал Протецтион 2011

Внимание! Если размещение файла нарушает Ваши авторские права, то обязательно сообщите нам

if execution of the command has been authorized and either permits or prohibits execution. Such approach realizes a client/server architecture. If the request made has been authorized, the microkernel calls the respective server process to realize it.

The security system of Windows NT is based on an objective protection model. Object is understood as any OS resource (file, devices, program, memory area).

Each Windows NT user should log in to the system. He/she has a login and a password entered in the database.

When logging in, the user undergoes identification and authentication procedures (Fig. 7.3). Identification means confirmation that the user who is logging in has an account in the database of registered users. This procedure checks the user name (login). Authentication confirms the identity of the user logging in. This procedure checks if the password entered is valid. The user enters his/her login and password. The security account manager checks if the user with such credentials exists and permits or denies access to the system. A so-called access token is generated that contains user data needed to have access to resources (objects), any process to be further initiated by the user to receive a copy of this token. This process is called the user account subject and has the same rights of access to objects as the user himself/herself.

Identification and authentication are rather formal in many current operating systems so it is quite easy for a subject to pass himself/herself off as another subject and use his/her rights of access to data. No authentication altogether is required for network interaction in Internet where global compatibility requirements are binding.

 

 

 

 

 

 

 

 

Access

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Win32

 

 

 

 

 

 

 

 

 

 

token

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Access

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

token

 

 

 

 

 

 

 

 

 

 

 

 

 

New process

 

 

 

 

 

 

 

 

Account

 

Security

 

 

 

 

 

 

 

 

Access

 

subsystem

 

 

 

 

 

security

 

 

 

token

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

manager

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Fig. 7.3. Login access token creation procedure

316

Control of access to resources includes check of the user’s rights to use the given object when an OS resource is requested for. There are a number of models realizing this function. We shall look into how two models, a discretionary model and a mandatory model, are organized [11]. The discretionary access control model is realized in Windows NT [12] and realization of mandatory access control is the necessary condition for an OS to be certified to access security class 2.

The discretionary model requires that each OS object should possess the so-called security descriptor that contains the object owner data and the system access control list to check the right of access to the object. By default, the creator of the object becomes the owner thereof, the right of ownership being transferable. The owner has the right to create and change the rights of access to the object. The access control list consists of access control records that specify the permits for the user to address the object. Access control records contain an access mask that defines what can be done with the object. For example, the access mask for a file contains “no access”, “full access”, “read”, “write”, “change” a nd “execute” operations. When an object is addressed to, the security monitor checks the object’s access control list and grants or limits, as the access mask defines, or denies access (Fig. 7.4).

 

 

 

 

 

 

 

 

File

 

 

 

 

Access token

 

 

 

Askjadsf,d,s

 

 

 

 

 

 

 

Ashksaaslsa

 

 

 

 

SID,

 

 

 

dlsajdaslsla

 

 

 

 

group, etc.

 

 

 

 

 

 

 

 

 

Object ACL - File

 

 

 

 

 

 

 

 

 

 

 

 

 

 

User=Read

 

Security monitor

 

 

Group1=Full

 

 

 

Group2=No access

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Access

 

 

 

 

 

 

 

 

 

definition

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Fig. 7.4. User’s resource access procedure

The mandatory access control model is based on classified document management rules. All objects and users are given a special label called security level with dominance relations established among levels, e.g. the

317

Top Secret level is superior to the Secret level. Control of access to data is established based on two simple rules:

1.A user is entitled to getting only data of the security level not higher than that of his/her.

2.A user has the right to enter data only in objects of the security level not lower than that of his/her.

The first of the rules ensures data protection from being accessible to lower-level users. The second (and more important) rule prevents data leakage on the part of high-level users.

Mandatory access control does not differentiate between entities and is normally used, along with a discretionary model, for better flexibility.

Apart from access control, secure operating systems are expected to allow event auditing. This is normally realized in the form of security event logs by reviewing which the IT administrator traces down the user actions with respect to information security.

As computerized NM A&C systems are basically systems designed to operate in corporate local area networks, operating systems used to support functionality of these need to have built-in tools to support computer network operations. Thus, Windows NT operating systems have support of distributed network protocols and help organize PCs into logic groups or domains. Inside domains, users have to log in on the primary domain controller only. Whatever workstation is used for logging in, the rights of access are checked on a centralized basis. This makes the same security policy to be easily organized and pursued on all computers within the domain.

NT-based operating systems include a component termed Internet Information Services. When installed, it allows creation of a Web-server on the computer, thus enabling use of Internet global network technologies to be used in local corporate NM A&C system networks.

7.3.2. Database management systems

Database forms the core of any computerized accounting and control system. A computer database is an array of specifically arranged information. Database management systems (DBMS) are employed to operate databases and give a computerized support to storing and handling of data. To a great extent, DBMS selection defines the future user characteristics of the NM A&C system under construction, including speed of response, the amount of information to be stored and security attributes

318

to protect information against both unauthorized access and objective factors.

The industry standard imposes the following requirements on DBMSs. A DBMS should offer convenience of backup copy creation and data recovery. Where required, a DBMS may include a convenient user interface and DB automatic replication features.

A DBMS shall support:

∙networking operations;

∙high speed of response and capacity. Where required it also supports:

∙the driver ODMC;

∙security of data and data access control;

∙an SQL query language.

Two of these requirements are clearly defined: a DBMS should support data backup and networking capabilities. The rest are either general (high capacity) or not binding (“as required”). DBMSs are also subject to data access security certification. As of the time this chapter was being written, three DBMSs, including Microsoft SQL Server 6.5 and two Oracle versions, had been certified to access security class 3. These are systems that support client/server architectures and operate relational databases. In fact, these two requirements are presently the accepted industry standards. The client/server architecture was discussed above. In general, things with certifying modern DBMS systems stand in the same way as with operating systems.

As to open-code base software, PosgreSQL 7.4.6 DBMS was certified by NPO “Luch” in parallel with their Yanux 2.0 oper ating system. Therefore, in the context of open-code software applications, there is now a complete set of certified software required to develop and operate computerized NM A&C systems.

Relational databases

There are a number of requirements to satisfy to which a relational DB is expected to:

∙submit information as tables;

∙support the logical data structure irrespective of the physical presentation form;

∙use a high-level language to execute requests and change data in databases;

∙support basic relational and set operations;

319

∙support virtual tables for alternative data viewing;

∙discriminate unknown values, zero values and gaps in data;

∙support data integrity, authorization, transaction and recovery mechanisms.

Tables consist of columns (fields) and rows (entries), each entry describing the entity the data whereof is contained in the table. Entry fields contain properties (attributes) of this entity. For unambiguous identification of an entity (an entry), the table contains a special field called the primary key. The value of this key must be unique in the given table. More than one field (composite key) may be used for the primary key. In the NM A&C system practices, a special ID field is introduced to be used as the primary key. For relation to other tables, the table also has fields called foreign keys. The foreign key is the primary key for another table. Foreign keys relate a table entry to a particular object (entry) of another table (Fig. 7.5).

Personnel table

ID position

Ivanov

7

 

Petrov

3

 

 

 

 

 

 

Foreign key

 

Primary key

Table of offices

ID position

Office

7

engineer

14

assistant

 

professor

Fig. 7.5. Relationship between tables via key fields

A key aspect in a database design is identification of entities and organization of relationships among them. This should be done keeping in mind how stored data will be further handled.

The selection of entities should be followed by normalization of data to give the database the status as would prevent corruption of data and facilitate data manipulation. There is a set of rules which help, if adhered to, with achieving different levels of data “normal ity” (normal forms). A database is considered to be operational if the third normal form is achieved. Each subsequent normal form includes the requirements of the

320

Источник: https://studfile.net/preview/16708779/