Access Control



tải về 2.19 Mb.
trang11/15
Chuyển đổi dữ liệu01.03.2024
Kích2.19 Mb.
#56689
1   ...   7   8   9   10   11   12   13   14   15
Lecture 04 Access control new (1)

Orange Book Outline

  • Goals
    • Provide way to assess security products
    • Provide general guidance/philosophy on how to build more secure products
  • Four divisions labeled D thru A
  • Divisions split into numbered classes

D and C Divisions

  • D  minimal protection
    • Losers that can’t get into higher division
  • C  discretionary protection, i.e., don’t enforce security, just have means to detect breaches (audit)
    • C1  discretionary security protection
    • C2  controlled access protection
    • C2 slightly stronger than C1 (both vague)

B Division

  • B  mandatory protection
  • B is a huge step up from C
    • C: break security, you might get caught
    • B: “mandatory”, so you can’t break it
  • B1  labeled security protection
    • All data labeled, which restricts what can be done with it
    • This access control cannot be violated

B and A Divisions

  • B2  structured protection
    • Adds covert channel protection onto B1
  • B3  security domains
    • On top of B2 protection, adds that code must be tamperproof and “small”
  • A  verified protection

Orange Book: Last Word

  • Also a 2nd part, discusses rationale
  • Not very practical or sensible, IMHO
  • But some people insist we’d be better off if we’d followed it
  • Others think it was a dead end
    • And resulted in lots of wasted effort
    • Aside… people who made the orange book, now set security education standards

Common Criteria

  • Successor to the orange book (ca. 1998)
    • Due to inflation, more than 1000 pages
  • An international government standard
    • And it reads like it…
    • Won’t ever stir same passions as orange book
  • CC is relevant in practice, but usually only if you want to sell to the government
  • Evaluation Assurance Levels (EALs)
    • 1 thru 7, from lowest to highest security

tải về 2.19 Mb.

Chia sẻ với bạn bè của bạn:
1   ...   7   8   9   10   11   12   13   14   15




Cơ sở dữ liệu được bảo vệ bởi bản quyền ©hocday.com 2024
được sử dụng cho việc quản lý

    Quê hương