Материал: Крючков Фундаменталс оф Нуцлеар Материалс Пхысицал Протецтион 2011

Внимание! Если размещение файла нарушает Ваши авторские права, то обязательно сообщите нам

is permitted to undertake with respect to the given object. For files, for example, the access matrix realizes the following rights: read, write, add, create, delete, rename and execute (for exacutable files).

When a mandate principle of access control is realized, each object and subject is assigned a double attribute. The first part of the attribute should reflect one of five secrecy levels: “unclassified”, “restricted” and so on. The second attribute part should reflect one of topical categories. In this, the following rules should be observed:

∙a subject is granted the right to read information only in the event that the subject secrecy level is higher than or equal to the secrecy level of the object and the category of the object either coincides with or is a subset of the subject category;

∙a subject may get the right to write with respect to an object in the event that the object secrecy level is higher than or equal to the secrecy level of the subject, and the subject category either coincides with or is a complete subset of the category (group) of the object.

More details on access to information based on the discrete principle are given in the “Operating Systems” section.

For data networking, the requirements of Gostekhkomissiya establish that this should involve facilities that prevent transmission of data to an object of a secrecy level lower than that of the data transmitted.

The logging and accounting subsystem should:

∙log output of classified printed documents as hard copies;

∙log attempts of software access to the following secured access objects: networks components and fragments, ports, peripherals and processes;

∙log all errors of network data exchange revealed;

∙automatically account for created secured objects by giving them additional labels used in the access control subsystem;

∙clear (zero, initialize, depersonalize) vacated storage areas in computers and segregated external carriers. Clearing is done by a double random entry into any vacated storage area used to store secured information.

Printout of classified documents requires automatic labeling of sheets by numbers and accounting requisites. Simultaneously, an account card should be made out for the document with specified logging parameters.

Requirements to the integrity and cryptography support subsystems coincide in full with requirements to similar subsystems of Class 3 A&C systems.

Requirements to class 1 A&S systems include all requirements to class 2 and 3 A&C systems.

391

Requirements to access control subsystems include authentication of users during remote access to the server and the workstation using such techniques as are resistant to interception of communications and active influences on networked data. The subject, which is the source of data, should be also authenticated, that is, features should be used that verify the trustworthiness of the data block source by such techniques as are resistant to interception of communications and active influences on networked data.

The logging and accounting subsystem should log changes in the powers of access subjects and in the status of access objects. Subject to logging are also the connections between distant processes and attempted compromise alarms sent to the workstation display and the attacker.

The cryptographic subsystem should encode all classified information written on data carriers shared by various access subjects, in network communication channels, as well as on portable data media. The access of subjects to encoding operations and to respective cryptographic keys should be additionally controlled by the access control subsystem.

The integrity support subsystem should ensure:

∙the integrity of the connection to protect data transmitted over the user network against unauthorized modification, substitution or retrieval of any data using such techniques as are resistant to interception of communications and influences on networked data;

∙proofing of the data source to prevent any sender attempt to deny thereafter the transmission of data;

∙proofing of the data delivery to prevent any receiver attempt to deny thereafter the receipt of data.

Requirements to qualification of the IASS depending on the NM A&C system classes

The whole of the computerized NM A&C system is subject to qualification. Qualification is understood as documented verification of the conformity of the set of organizational and technical arrangements used in operation to requirements of standards and other information security regulations. It involves in-service qualification tests of the secure AS to determine if the measures employed and the ISS meet the required level of information security. Information is further arranged in the same manner as the qualification requirements.

Requirements to class 3 A&C systems are presented hereinafter. Components of any access control system have the following qualification requirement imposed thereon. Personnel access to the information in the

392

A&C system is expected to be effected in accordance with the valid system of user permits of access to classified documents and data.

A logging and accounting subsystem shall:

∙account for all protected data carriers with the aid of any labeling system;

∙log and account for printouts manually as per the requirements to recordkeeping of the respective secrecy level. Documents should be printed out only in accordance with the specified list of output documents indicating their secrecy level.

An integrity support subsystem shall ensure the following functions.

∙The software environment should remain invariable with the integrity of the software environment ensured by the absence of program development and debugging tools in the A&C system.

∙The functions of the IASS should be tested on a periodic basis, with the aid of tests simulating attempts of unauthorized access, any time the software environment or the A&C system personnel change.

∙The IASS recovery tools should be available, which implies operation of two IASS software copies with periodic updates and serviceability checks thereof, as well as online recovery of the IASS functions when equipment fails.

∙Rooms with the A&C system hardware, which includes carriers of classified information, should be fitted with safeguards to ensure the security level meeting the secrecy level of the information stored.

∙Information access security features certified for this A&C system class should be used.

Qualification requirements to class 2 A&C systems differ from those to class 3 A&C systems only as far as the integrity support subsystem is concerned. There should be an information security administrator to be responsible for maintenance, normal operation and online control of the IASS. The administrator should have a workstation of his/her own and the required A&C system online controls and security influence means. Additionally, secure communication lines extending to beyond the areas under control should be used.

Qualification requirements to class 1 A&C systems differ from requirements to class 2 A&C systems in that they include a cryptographic subsystem. Cryptographic facilities certified for class 1 A&C systems should be used. Besides, the integrity support subsystem should use fire walls certified for class 1 A&S systems.

393

8.4.2. Guides of Gostekhkomissiya

Five information access security guides were published by Gostekhkomissiya of Russia (the State Technical Commission of the Russian Federation) in 1992 [4–8]. These documents formed the basis for the requirements to NM A&C systems we have described above. So, now, we shall discuss in brief the most important of these.

Ideologically, these documents are based on the “Co ncept of Information Access Security (IAS)” [4] that contain s the system of Gostekhkomissiya’s views on the problem of information security and guidelines for computer system security. As developers of these documents see it, the key role of security is to make information secured against unauthorized access. No consideration is practically given to support of serviceability of information handling systems. The explanation for this bias towards maintaining secrecy is that these documents were originally developed with a view of using them within information systems of the Russian Federation Defense Ministry and security services, as well as an insufficient maturity of information technologies in the early 1990s against current analogs.

Gostekhkomissya’s guides offer two sets of security criteria: criteria of computer protection against unauthorized access and protection criteria for automated data handling systems. The former makes it possible to evaluate the security of computer system components delivered to the consumer, while the latter is intended for fully functional data handling systems. We shall look at what is provided in the document entitled “Automated Systems. Information Access Security. Classification of Automated Systems and Information Security Requirements”. Thi s document establishes the classification of automated systems in terms of information access security. It makes sense to compare this classification against the classification of automated NM A&C systems.

For automated systems, five classes of information access security are specified in Gostekhkomissya’s guides. Each of the classes is characterized by a specific combination of requirements to security means. In turn, classes are subdivided into three groups with a specific information handling concept each. Automated systems are grouped based on the following features:

∙presence of information of different confidentiality levels in the AS;

∙levels of the AS user authority with respect to the access to confidential information;

∙data processing mode used in the AS (collective or individual).

394

A hierarchy of the AS security classes is established within each group. The class matching the highest security level for the given group is indexed A, the next one being indexed B and so on.

The third group includes automated systems operated by one user with a permit to handle all AS data contained on media of one confidentiality level. The group has two classes: ЗБ and ЗA.

The second group includes automated systems in which users have equal rights of access to all information processed and/or stored in the AS on media of different confidentiality levels. The group has two classes: 2Б and 2A.

The first group includes multi-user automated systems which simultaneously process and/or store information of different confidentiality levels. Not all users have equal rights of access. This group has five classes: 1Д, 1Г, lВ, lБ and lА.

A review of the requirements in question shows that the second class of information access security in computerized NM A&C systems corresponds, by and large, to class 1Б for automated systems. A precedent exists when an automated NM A&C system qualified to information access security class 1Б is used to account for and control NM in environments matching class 2 for NM A&C systems.

The development of the said documents in the early 1990s filled up the gap in the legislative support for information security standards. Being, in fact, the first ever attempt of standardization in so a delicate field, these do have a number of shortcomings. Besides, the time since the adoption of these criteria has seen advances in both the theory of information security and approaches to formulation of information security standards. The approaches taken in the documents are mostly limiting in that the requirements for security classes are ranked only by way of identifying the presence of a set of security tools, which makes these requirements much less flexible and feasible. These documents treat the notion of security policy as the keeping of the regime of secrecy and the absence of unauthorized access. Because of this approach, security tools tend exclusively to counter external threats with no requirements practically imposed on operations of the system and its structure. A note should be made that requirements to computerized NM A&C systems adopted in 1997 are based on the documents listed and involve the same deficiencies.

395

Источник: https://studfile.net/preview/16708779/