Материал: Крючков Фундаменталс оф Нуцлеар Материалс Пхысицал Протецтион 2011

Внимание! Если размещение файла нарушает Ваши авторские права, то обязательно сообщите нам

CHAPTER 8

INFORMATION SECURITY OF COMPUTERIZED NM A&C

SYSTEMS

8.1. Secure information processing systems

Integrity of information and information access security are two of the critical aspects involved in design and operation of automated nuclear material accounting and control systems. Information security is given top priority in NM A&C systems which are established to handle national security information. Any intentional or unpremeditated loss, distortion or theft of information in these systems may have harmful effects, so the industry standard that regulates hardware support for NM A&C systems [1] requires any NM A&C system to have an information protection system as its integral part. All NM A&C system’s operation stages need to involve information protection ensured through a combination of measures taken to avoid leakage of information or exclude influences thereon to be exerted over technical channels, as well as to prevent premeditated software and hardware impacts to violate the integrity of information in process, transmission or storage, or break down hardware.

Confidential information is handled based on regulatory documents that govern protection of national security information. A shift from processing of paper documents to computerized handling of information demand that these requirements to be fulfilled on a continuous basis. A computerized system intended to process classified data is expected to be organized as these documents require. Thus, one requirement is to have user access to information in computerized systems to be arranged in such manner as defined by the document’s secrecy class or the officer’s access level.

Electronic handling of confidential data involves extra factors which are potentially compromising to an information system. These factors are called security threats. Some security threats are inherited by computerized systems from conventional data processing systems, e.g. theft or disclosure of information. At the same time, however, computerization brings about new threats. These come from the fact that automation of data processing keeps humans away from direct operations with data carriers. Powers are delegated to computer programs which may disturb confidential data handling as the result of premeditated actions or program code errors. To be usable for automated confidential data handling, a computer system needs to counter security threats successfully.

376

Russia, lastly, has a well-established system of information security standards. A system used to handle nuclear material data is expected to satisfy to the criteria required by these standards. This conformity is subject to verification by qualification tests. There are also industry standards and guides in effect at the enterprise level. These contain requirements to be also taken into account.

Therefore, a secure information processing system [2], specifically a computerized NM A&C system, should satisfy to the following three requirements and, subject to these, is expected to:

∙automate confidential data handling processes, including all aspects thereof involved in ensuring security of the data processed;

∙counter security threats that act in a particular environment;

∙meet the requirements and criteria of security information standards.

Secure information processing systems should ensure information security. Information security, as viewed by the expert community, is security of the information environment that supports its formation and evolution in the interests of an organization or the state. Prevention of information security threats and response to these is achieved through a combination of organizational, legal, technical and technological measures known, collectively, as information protection features.

8.2. Information protection in accounting and control of nuclear material

In recent years, security of information technologies has been the cause of an increasingly growing concern, while analytical surveys show a yearly increasing damage from security violations. Here are some figures to illustrate the level of damage from computer viruses for the several past years. The virus-caused damage was about 13 billion US dollars in 2001 and 20 to 30 billion in 2002 reaching, a year later, 55 billion. Nearly the same was the damage, as some estimates show, from the Mydom virus in January 2004. Therefore, there is every reason to speak about a crisis in the field of IT security.

The security crisis has its roots in the rapidly evolving information technologies and the security provisions lagging behind the technological advances both in theoretical and practical terms. The huge computational capabilities of modern computer systems are combined with the handiness of these. The formation of the global information environment makes information resources accessible to a great number of differently skilled users. Most users are not competent enough to keep security of their

377

computer systems at required levels. Most computer-virus plagues could be realized because of users failing to check their computers on a routine basis, update antivirus databases and install timely operating system upgrades which eliminate software errors revealed.

The advancement in computer technologies brings about an explosive development of software. Newly built and distributed software products often fail to conform to security requirements. One example is the software built by Microsoft, the world’s most powerful IT corporation. Microsoft’s operating systems (OS) and database management systems (DBMS) have somewhat limited information security features and feature a great deal of “undocumented capabilities”. These make it possible for intruders to infiltrate information systems via global networks, crack user passwords, give themselves arbitrary access levels and, ultimately, easily manipulate confidential information.

With the theoretical basis of information security lagging behind the technological advances and new security threats coming out continuously, most security systems have their protection systems simply “patched” for the loopholes found therein.

The status of computer security is greatly influenced by the existing national information security standards also lagging behind the requirements imposed on security of modern information technologies. The globalization of the information space has led to the necessity of international security standards to be developed to standardize security requirements, the information security features made feasible and protection features properly realized.

A noteworthy fact is that state authorities and computer/software engineers are well aware of the existing concerns. Recent years have seen efforts to ensure protection of information placed in the forefront also in promotion of novel software. International computer security criteria was established and approved by the International Standardization Organization (ISO) in 1999 [2, 3]. This standard has been in effect in Russia since 1 January 2004. Software developers seek to have their products certified under these criteria, which is expected to improve, in general, the information security level. Thus, in 2002, the Windows 2000 operating system was certified to these criteria, followed by distributives of the Linux operating system certified in 2003.

Russia, by and large, sees its information security technologies evolving in the stream of global trends. Still, some specific points exist. This country shows a slower IT dissemination pace than economically developed countries. One explanation for this is that Russia was somewhat later in

378

building its capability to evolve commonly available information systems than more developed countries; the other one is that most Russian people cannot afford using information technologies for economic reasons. This, in turn, leads to a worse dynamics in the development of regulatory documentation for the field of information security. Thus, the first data access security guidance documents of Gostekhkomissiya under the President of the Russian Federation [4 – 8] were ad opted in 1992. The ideology of these documents was modeled after that of the US Department of Defense’s criteria, known as Orange Book, passed in 1983. Close to these is also a guide adopted in 1997 to regulate security of information in automated NM accounting and control systems [9]. It was only in 2004 that international criteria were adopted as standards in Russia.

There are no practically dedicated classified data handling systems, such as operating systems and DBMSs, offered in Russia’s home market. Those systems used as the base software are beneath criticism in security terms. Often these are commercial systems for small business and office applications that cannot be used, in principle, for the confidential data handling purposes. The existing software security products can be used for some, e.g. cryptographic, tasks, still cannot offer a solution to the problem as the whole.

A point to security of information in accounting and control of nuclear material is that use of foreign-made commercial base software to process national security information can hardly be thought normal. So governments in many countries tend to give up imported software for domestically developed software systems. One recent example is a number of countries having given up use of Microsoft products for national and regional management and control purposes. Here, two solutions are possible. The first one is to build domestic software based on a homedeveloped platform. The second solution is to update the existing software through creation of domestic information security systems (ISS) and incorporation of these in the current systems subject to license agreements. The first approach is very costly to take, so the second concept has been adopted by the Ministry for Atomic Energy to implement. As is known [3], in 2003, Microsoft made source codes of its operating systems available to authorized organizations in a number of countries as part of its GSP (Government Security Program). In Russia, such agreement with Microsoft was signed by the Federal Agency for Government Communications and Information. Microsoft was also announced to provide in due manner for appraisal the required design documentation and enable program modules

379

to be developed where no functional capabilities sought for had been realized in Microsoft products.

8.3. Threats to information security and countermeasures

Threats to information securities are understood as factors seeking to violate normal operations of a system. Threats may be purposeful (subjective) and random (objective). Russian standards focus chiefly on purposeful threats, that is, on information access security. Objective factors pose no smaller threats to normal operation of information systems. Thus, a loss of information integrity from an inadequately designed database may nullify the value of existing data. Information may be also lost throughout as the result of a hardware breakdown unless special measures are taken to archive and copy this.

The following three broad classes of threat types are identified:

∙threats to confidentiality;

∙threats to integrity;

∙threats of denial of service.

Countermeasures to objective threats relate to the system reliability. Countermeasures to subjective threats are a key information security task.

Information security experts consider different influences of threats on a computerized information system. Information, software, physical, and organizational and legal influences are identified.

Information influences mean all kinds of unauthorized manipulations of database data. These include illegal access to data, theft and unauthorized duplication of information, concealment and premeditated corruption of information, as well as compromise of the handling technology and timeliness.

Software influences mean influences on the protected system through insertion of malicious programs or hardware. These programs or devices are capable of realizing undocumented functions leading to thefts or corruption of data. Foreign-made hardware and software products are used chiefly to build automated NM A&C systems, so insertion of special “bugs” therein is very likely. Moreover, real cases of such insertions are known. A form of software influences from information security threats are currently common virus influences on computers.

Physical influences are implemented through physical impacts of various factors on computers, network components, data carriers and, ultimately, on the personnel operating confidential information and security systems. Physical threats, as evidenced by estimates from the US

380

Источник: https://studfile.net/preview/16708779/