Материал: Крючков Фундаменталс оф Нуцлеар Материалс Пхысицал Протецтион 2011

Внимание! Если размещение файла нарушает Ваши авторские права, то обязательно сообщите нам

components at separate sites and establish communication between these by dispatching information on carriers by special hand delivery.

Therefore, the task at hand is to have base software certified to information access security class 2. Class 1 NM A&C systems will be needed in the event where it is necessary to transmit information over open information channels. This requirement is now part of the Federal Information System (FIS) development program for the period up to the year 2010.

Requirements to information access security systems depending on the NM A&C system classes

The requirements of Gostekhkomissiya identify four subsystems of the Information Access Security System (IASS). These are:

∙an information access control subsystem;

∙a logging and accounting subsystem;

∙a cryptographic subsystem;

∙an integrity support subsystem.

Certification and qualification requirements are specified for each subsystem depending on the NM A&C system class. Table 8.2 lists the requirements with respect to classes for various components of these four subsystems. “+” means the existence of respective r equirements to the given class, and “–“ means the absence of such requiremen ts.

386

 

 

 

 

Table 8.2

 

 

 

 

 

 

 

Subsystems and requirements

A&C system

 

 

 

 

classes

 

 

 

III

 

II

I

 

1. Access control subsystem

 

 

 

 

 

1.1. Identification, authentication checks and control of access

 

 

 

 

 

subjects:

 

 

 

 

 

∙

when logging into the operating system

+

 

+

+

 

∙

when getting access to the DBMS

+

 

+

+

 

∙

when getting access to the OS objects (workstations,

+

 

+

+

 

servers, networks, domains, communication channels, ports,

 

 

 

 

 

storage areas, peripherals and network components, processes,

 

 

 

 

 

disks, volumes, catalogs, files, etc.) and to the DBMS subjects

 

 

 

 

 

(files, tables, indices, records, entry fields, diagrams,

 

 

 

 

 

procedures, etc.)

 

 

 

 

 

 

 

+

 

+

+

 

1.2. Control of transmitted (received) data in the network

–

 

+

+

 

1.3. Limitation of processes to access data

–

 

+

+

 

1.4. Control of information flows

–

 

+

+

 

2. Logging and accounting subsystem

 

 

 

 

 

2.1. Logging and accounting of:

 

 

 

 

 

∙

login/logout of access subjects into/of the system

+

 

+

+

 

(workstation, server)

 

 

 

 

 

∙

output of printed (graphic) documents

+

 

+

+

 

∙

launch (closure) of all programs (processes, assignments)

+

 

+

+

 

∙

access of software (processes, programs, tasks,

+

 

+

+

 

assignments) to secured files and catalogs

 

 

 

 

 

∙

access of software (processes) to network fragments and

–

 

+

+

 

components (domains, servers, workstations), ports (lines,

 

 

 

 

 

communication channels), peripherals and network devices,

 

 

 

 

 

and processes

 

 

 

 

 

∙

access to the DBMS objects (files, tables, indices,

+

 

+

+

 

records, entry fields, diagrams, procedures, etc.)

 

 

 

 

 

∙

changes in access subject powers and access object status

–

 

–

+

 

∙

created secured access objects

–

 

+

+

 

∙

all network data exchange breakdowns

–

 

+

+

 

∙

the establishment of communication between remote

–

 

–

+

 

processes

 

 

 

 

 

387

Table 8.2 (continued)

Subsystems and requirements

A&C system

 

 

classes

 

III

 

II

I

2.2. Accounting of information carriers

+

 

+

+

2.3. Cleaning (zeroing, initialization, depersonalization) of

–

 

+

+

vacated computer and outside accumulator storage areas

 

 

 

 

2.4. Alarms of attempted compromises

–

 

–

+

3.2. Use of certified encryption-based safeguards

–

 

–

+

4. Integrity assurance subsystem

 

 

 

 

4.1. Software and processed data integrity assurance

+

 

+

+

4.2. Connection integrity assurance

–

 

–

+

4.3. Data transmission and delivery proofing

–

 

–

+

4.4. Physical protection of rooms, computers and information

+

 

+

+

carriers

 

 

 

 

4.5. Presence of the information security administrator

–

 

+

+

(service) in the A&C system

 

 

 

 

4.6. Periodic testing of the IASS

+

 

+

+

4.7. Presence of the IASS recovery facilities

+

 

+

+

4.8. Use of secure communication lines

–

 

+

+

4.9. Use of certified fire walls

–

 

–

+

4.10. Use of certified security features

+

 

+

+

Requirements to certification of the IASS depending on the NM A&C system classes

Certification of information security features (ISF) is understood as the establishment of the ISF conformity to a set of requirements that ensure protection of data of the respective secrecy level. The procedures for carrying out mandatory ISF certification and the organizations authorized to carry out certification are described in detail in the section “Development and Commissioning of Computerized NM A&C Systems”. This section presents certification requirements to different subsystems of an A&C system depending on the class thereof. The requirements for a higher class automatically include the requirements for a lower class.

Below, we set forth requirements for class 3 A&C systems. The requirements to components of an access control subsystem demand the following:

388

∙identification and authentication of the users logging into the operating system;

∙identification and authentication of the users during the access to the database management control system (DBMS);

∙identification of servers, workstations, peripherals and network components by physical addresses;

∙identification of subjects and objects by names;

∙identification of the database objects by names.

We shall explain some of the concepts. The identification process consists in that the system identifies the user. To this end, the user logging in to the system enters his/her identifier (login). Authentication verifies the trustworthiness of the user, that is, the fact that the identifier has been entered by the user himself/herself. To this end, a password (a secret word) known only to the user is entered. The requirements of Russia’s Gostekhkomissiya establish that a password should comprise not less than 8 characters. Besides this requirement, recommendations exist based on long-term practices. Specifically, it is recommended that passwords should use not only letters but other symbols as well. Characters should be entered with different cases selected. A password must by no means be a meaningful word or contain personal information. All this is expected to make it more difficult to crack the password electronically. The password length of 8 characters was chosen in view that it takes about half a year to guess a combination of 8 characters by a simple search method using an up- to-date computer. The password validity normally expires over this time. At present time, because of increasing computer capabilities, the recommended password length is not less than 10 characters. User passwords should be accessible only to specially authorized personnel (administrators). The password expiry date is to be fixed with passwords to be changed from time to time.

A subject of a system is any system process initialized by the user and run in the user interests. An object of an operating system and a database object is any resource in the OS or the DBMS. This is discussed in more details in the “Base Software” section.

The following requirements are imposed on components of the logging and accounting subsystem. The following events are subjected to logging:

∙user login/logout into/out of the operating system, as well as logging of the operating system loading and programmed shutdown;

∙launch/closure of all programs;

∙attempted access of software to secured files and catalogs;

389

∙access to database objects.

Logging facilities should be accessible only to the administrator and include for him/her respective facilities for viewing and reviewing stored events by the above parameters and archiving these.

The following should be indicated during logging:

∙time and date of the user login/logout into/out of the system and of the system loading/shutdown;

∙the identifier of the user initializing the process;

∙the result of the action (successful or unsuccessful – unauthorized).

When files or database objects are accessed, specification of the access object and the code of the operation requested for are also logged.

The integrity assurance subsystem should ensure:

∙integrity of the IASS software and database.

∙integrity of the IASS database in the DBMS through isolation of this from users and online recovery on the part of the administrator.

No class 3 A&C systems have a cryptosystem.

Hereinafter, requirements to class 3 A&C systems are set forth. An access control subsystem should:

∙identify communication channels by physical addresses;

∙control the access of subjects to secured OS resources in accordance with the access matrix based on a discrete principle;

∙control the access of subjects to the DBMS objects in accordance with the access matrix by sampling, modification, insert, deletion and other operations;

∙limit user access to secured objects using only strictly specified processes;

∙realize a mandate principle of access control;

∙control information flows using the subject and object secrecy attribute;

∙transmit data over the network together with secrecy attributes which should be secured.

Unauthorized operations on networked data and unauthorized duplication of data should be safely identified as an error and logged respectively.

We shall clarify the requirement of the access control mandate principle. Theoretically, there are two basic principles (or models) to control access to resources. These are a discrete model and a mandate model. When the discrete principle of access to objects is realized, each object contains an access control listing, i.e. a list of users with a permit of access. An access matrix is specified for each user, that is, what action exactly the given user

390

Источник: https://studfile.net/preview/16708779/