4/04/2008

Computer Security

is a branch of technology known as information security as applied to computers. The objective of computer security varies and can include protection of information from theft or corruption, or the preservation of availability, as defined in the security policy.

Computer security imposes requirements on computers that are different from most system requirements because they often take the form of constraints on what computers are not supposed to do. This makes computer security particularly challenging because we find it hard enough just to make computer programs just do everything they are designed to do correctly. Furthermore, negative requirements are deceptively complicated to satisfy and require exhaustive testing to verify, which is impractical for most computer programs. Computer security provides a technical strategy to convert negative requirements to positive enforceable rules. For this reason, computer security is often more technical and mathematical than some computer science fields.[citation needed]

Typical approaches to computer security (in approximate order of strength) can include the following:

* Physically limit access to computers to only those who will not compromise security.
* Hardware mechanisms that impose rules on computer programs, thus avoiding depending the computer programs for computer security.
* Operating system mechanisms that impose rules on programs to avoid trusting computer programs.
* Programming strategies to make computer programs dependable and resist subversion.
Secure operating systems

One use of the term computer security refers to technology to implement a secure operating system. Much of this technology is based on science developed in the 1980s and used to produce what may be some of the most impenetrable operating systems ever. Though still valid, the technology is almost inactive today, perhaps because it is complex or not widely understood. Such ultra-strong secure operating systems are based on operating system kernel technology that can guarantee that certain security policies are absolutely enforced in an operating environment. An example of such a Computer security policy is the Bell-LaPadula model. The strategy is based on a coupling of special microprocessor hardware features, often involving the memory management unit, to a special correctly implemented operating system kernel. This forms the foundation for a secure operating system which, if certain critical parts are designed and implemented correctly, can ensure the absolute impossibility of penetration by hostile elements. This capability is enabled because the configuration not only imposes a security policy, but in theory completely protects itself from corruption. Ordinary operating systems, on the other hand, lack the features that assure this maximal level of security. The design methodology to produce such secure systems is precise, deterministic and logical.

Systems designed with such methodology represent the state of the art of computer security and the capability to produce them is not widely known. In sharp contrast to most kinds of software, they meet specifications with verifiable certainty comparable to specifications for size, weight and power. Secure operating systems designed this way are used primarily to protect national security information and military secrets. These are very powerful security tools and very few secure operating systems have been certified at the highest level (Orange Book A-1) to operate over the range of "Top Secret" to "unclassified" (including Honeywell SCOMP, USAF SACDIN, NSA Blacker and Boeing MLS LAN.) The assurance of security depends not only on the soundness of the design strategy, but also on the assurance of correctness of the implementation, and therefore there are degrees of security strength defined for COMPUSEC. The Common Criteria quantifies security strength of products in terms of two components, security capability (as Protection Profile) and assurance levels (as EAL levels.) None of these ultra-high assurance secure general purpose operating systems have been produced for decades or certified under the Common Criteria.

[edit] Security architecture

Security Architecture can be defined as "The design artifacts that describe how the security controls (= security countermeasures) are positioned, and how they relate to the overall IT Architecture. These controls serve the purpose to maintain the system’s quality attributes, among them confidentiality, integrity, availability, accountability and assurance."[1]. In simpler words, a security architecture is the plan that shows where security measures need to be placed. If the plan describes a specific solution then, prior to building such a plan, one would make a risk analysis. If the plan describes a generic high level design then (reference architecture) then the plan should be based on a threat analysis.

[edit] Security by design

The technologies of computer security are based on logic. There is no universal standard notion of what secure behavior is. "Security" is a concept that is unique to each situation. Security is extraneous to the function of a computer application, rather than ancillary to it, thus security necessarily imposes restrictions on the application's behavior.

There are several approaches to security in computing, sometimes a combination of approaches is valid:

1. Trust all the software to abide by a security policy but the software is not trustworthy (this is computer insecurity).
2. Trust all the software to abide by a security policy and the software is validated as trustworthy (by tedious branch and path analysis for example).
3. Trust no software but enforce a security policy with mechanisms that are not trustworthy (again this is computer insecurity).
4. Trust no software but enforce a security policy with trustworthy mechanisms.

Many systems have unintentionally resulted in the first possibility. Approaches one and three lead to failure. Since approach two is expensive and non-deterministic, its use is very limited. Because approach number four is often based on hardware mechanisms and avoid abstractions and a multiplicity of degrees of freedom, it is more practical. Combinations of approaches two and four are often used in a layered architecture with thin layers of two and thick layers of four.

There are myriad strategies and techniques used to design security systems. There are few, if any, effective strategies to enhance security after design.

One technique enforces the principle of least privilege to great extent, where an entity has only the privileges that are needed for its function. That way even if an attacker gains access to one part of the system, fine-grained security ensures that it is just as difficult for them to access the rest.

Furthermore, by breaking the system up into smaller components, the complexity of individual components is reduced, opening up the possibility of using techniques such as automated theorem proving to prove the correctness of crucial software subsystems. This enables a closed form solution to security that works well when only a single well-characterized property can be isolated as critical, and that property is also assessable to math. Not surprisingly, it is impractical for generalized correctness, which probably cannot even be defined, much less proven. Where formal correctness proofs are not possible, rigorous use of code review and unit testing represent a best-effort approach to make modules secure.

The design should use "defense in depth", where more than one subsystem needs to be violated to compromise the integrity of the system and the information it holds. Defense in depth works when the breaching of one security measure does not provide a platform to facilitate subverting another. Also, the cascading principle acknowledges that several low hurdles does not make a high hurdle. So cascading several weak mechanisms does not provide the safety of a single stronger mechanism.

Subsystems should default to secure settings, and wherever possible should be designed to "fail secure" rather than "fail insecure" (see fail safe for the equivalent in safety engineering). Ideally, a secure system should require a deliberate, conscious, knowledgeable and free decision on the part of legitimate authorities in order to make it insecure.

In addition, security should not be an all or nothing issue. The designers and operators of systems should assume that security breaches are inevitable. Full audit trails should be kept of system activity, so that when a security breach occurs, the mechanism and extent of the breach can be determined. Storing audit trails remotely, where they can only be appended to, can keep intruders from covering their tracks. Finally, full disclosure helps to ensure that when bugs are found the "window of vulnerability" is kept as short as possible.
Early history of security by design

The early Multics operating system was notable for its early emphasis on computer security by design, and Multics was possibly the very first operating system to be designed as a secure system from the ground up. In spite of this, Multics' security was broken, not once, but repeatedly. The strategy was known as 'penetrate and test' and has become widely known as a non-terminating process that fails to produce computer security. This led to further work on computer security that prefigured modern security engineering techniques producing closed form processes that terminate.

76 comments:

monkey said...

080 免費聊天網.交友嘟嘟聯誼網.影音視訊聊天.淫娃免費視訊聊天室.本土自拍-交友網.男人幫.520視訊聊天室.成人聊天fm1768.love104 影音視訊 love 秀.小高視訊聊天室.真愛視訊聊天室.限制寫真女郎.免費影音視訊hibb.五分鐘護半身視訊美女.激情網愛聊天室.一葉情貼圖片區.sex888免費影片.uthome 免費聊天室.後宮視訊聊天網.藍色情人視訊網.啦咧影音聊天室.本土自拍.網路交友hibb 17hi.go2av影片.美女交友-免費視訊.show girl5320貼影片.一葉晴視訊聊天av127.視訊交友愛戀之.kiss成人聊天室.免費視訊妹.情色交友視訊.台灣情綜合論壇.小弟弟成人娛樂網.104愛戀速配網.18美女視訊.1111 視訊網愛.美女交友elove.嘟嘟本土自拍網.完美女人視訊網.男女聊天室.影音交友mmshow tw.美眉1768 meet520 com.免費性感影片.交友網meet520.免費交友go.ut 視訊聊天室.色美媚部落格2a片.免費視訊辣妹sex女優王國.85cc成人影城.視訊網愛聊天室網路援交168論壇.免費成人視訊.av美美色網影片.台中援交友留言成人 視訊.北台灣視訊http sex520 net.jp成人.視訊聊天室捷克論壇.一夜情台北視訊.sex520 net視訊美女.情色視訊交友壞朋友論壇.69性殿.aaa免費看影片.s383情色大網咖視訊美眉共和國

shanteparkhurst said...

你的部落格感覺很棒,nice job!..................................................

香水 said...

Birthdays are good for you. The more you have, the longer you live.............................................

今天 said...

天下沒有走不通的路,沒有克服不了的困難,沒有打不敗的敵人。........................................

相信的一天 said...

GOOD........................................

ya said...

More haste, less speed.........................................

she said...

我從來不認為不同意我的看法就是冒犯........................................

茂一 said...

安心亞寫真top1069拓網交友做愛自拍免費情色影片寫真集美女正妹照片正妹貼圖正妹視訊250av女優免費影片旺來出品辣妹寫真鋼管秀旺來風情寫真秀-辣妹過招旺來風情寫真秀旺來蓬萊仙山寫真集 vcd旺旺仙貝的狂想境地早洩韭南籽早期歐美a片早期范冰冰照片早春小老婆日本三性影片美女 視訊洪爺sex免費看a片論壇秘密情人影音視訊網 bt成人網av一葉情貼影色網18 禁一葉情貼影入口女生自衛影片免費聊天女同志聊天室成人聊天室做愛影片網交聊天室性愛姿勢免費av影片觀看拓峰交友plus論壇hbo論壇一夜情視訊聊天室五分鐘護半身視訊美女激情網愛聊天室臺灣情色網

怡如 said...

All roads lead to Rome. 堅持自己所選! .........................................

v奎峰奎峰 said...

how do u do?

v奎峰奎峰 said...

我們唯一需要恐懼的事,是恐懼本身........................................

上宜俊宇芳心 said...

一個人想法的大小,決定他成就的大小。......................................................

張啟達 said...

He who would climb the ladder must begin at the bottom.......................................................

G702aynelleKress0 said...

果然是好文章 受益良多 感謝分享 ̄ 3 ̄........................................

雲亨 said...

困難要靠自己克服,障礙要靠自己衝破 ..................................................

志源 said...

Well done!........................................

林60102asai_sistrunk said...

很用心的blog,推推哦 ........................................

育偉倫航 said...

我們老得太快,卻聰明得太遲。 ....................................................

黃k0822oryb_card said...

我們老得太快,卻聰明得太遲。 ....................................................

玄雨 said...

一定要保持最佳狀況呦,加油!!!期待你發表的新文章!

ValarieEdmon靜宜 said...

失去金錢的人,失去很多;失去朋友的人,失去更多;失去信心的人,失去所有。...............................................................

韋于倫成 said...

思想與理論,貴呼先於行動,但行動較思想或理論更高貴..................................................

M12aeganT_Moe12 said...

成人情色論壇 aa 片俱樂部視訊i68美女 視訊女郎成人 情色 aa片免費看影片色漫畫帝國 免費a網,免費視訊辣妹 免費av999 sex影片視訊分享區 免費視訊聊天 ex jp成人-免費聊天室 夜色網 avhigh 視訊交友av1688 閃亮天使520聊天室 bt名模論壇 性感辣妹,sex女優 免費影片直播網 免費無碼影片 g8mm 網 34c高雄視訊聊天 正妹影音mmshow 成人a片網 oec 喔伊細辣妹視訊交友 yam交友天堂 777視訊美女 666成人網 哈啦視訊聊天室 性愛姿勢,sogo 色論壇 新竹援交a片免費線上看 a片-癡電車漢 kk俱樂部thmt aa成人漫畫 18禁聊天 18禁成人網 免費影片觀賞 洪爺免費a影片線上直 jp激麻a電影 聊天室交友b shop 成人視訊mela ,g點,免費a片,免費18影片 聊天室環球辣妹聊天室 90691 免費 aa 片試看情色文學 線上 aa 片試看嘟嘟,免費線上a電影 成人交友qk176 辣妹聊天室 90691 AV 前線 avdvd ut聊天室找一夜女 girl5320 貼片et免費影片下載 美國免費 aa 片試看aio 倉井空免費影片 wc123美色女影城 jp成人網

建霖 said...

You're gorgeous~.................................................................

韋于倫成 said...

生活總是起起伏伏,心情要保持快樂才好哦!!..................................................

慶天 said...

噴泉的高度,不會超過它的源頭。一個人的事業也是如此,它的成就絕不會超過自己的信念。..................................................

俊茹 said...

無一事而不學,無一時而不學,無一處而不學。......................................................

陳卓人 said...

愛情不是慈善事業,不能隨便施捨。............................................................

juliancu said...

April showers bring May flowers...................................................

renew said...

Variety is the very spice of life. ............................................................

SadeRa盈君iford0412 said...

Many a little makes a mickle...................................................................

麗芬 said...

nice to know you, and glad to find such a good artical!......................................................................

洪筱婷 said...

這麼好的部落格,以後看不到怎麼辦啊!!......................................................................

LesW_Saulsbu信豪 said...

成熟,就是有能力適應生活中的模糊。.................................................................                           

宛真宛真 said...

Quality is better than quantity.................................................................

幸齊幸齊 said...

一個人的價值,應該看他貢獻了什麼,而不是他取得了什麼.................................................................

嘉琬嘉琬 said...

一個人的價值,應該看他貢獻了什麼,而不是他取得了什麼............................................................

泓發 said...

人有兩眼一舌,是為了觀察倍於說話的緣故。............................................................

向霖向霖 said...

噴泉的高度,不會超過它的源頭。一個人的事業也是如此,它的成就絕不會超過自己的信念。.................................................................

芸茂芸茂 said...

安安!剛開始玩這個,來這裡逛一下^^............................................................

怡潔怡潔 said...

人因夢想而偉大,要堅持自己的理想哦..................................................................

竹青 said...

初次造訪,安安^^..................................................................

MinBar林 said...

要照顧身體歐~保重..................................................................

溫緯李娟王季 said...

感謝你的分享 要繼續發表好文章喔..................................................................

姿柯瑩柯dgdd憶曾g智曾 said...

人生最可憐的是半途而廢,最可悲的是喪失信心,最遺憾的是浪費時間,最可怕的是沒有恆心。..................................................

偉倫s倪陳合恭陳陳sgdgd陳 said...

very popular to u!..................................................................

于倫 said...

愛情不是慈善事業,不能隨便施捨。......................................................................

萬宇萬宇 said...

hello, i visited~~感謝大大分享..!..................................................................

江桂宸江桂宸 said...

從來愛都不知它的深度,非得等到別離的時候.................................................................

憲妤 said...

休息才能再次出發-隨時保持好體力-加油..................................................................

莊雅和莊雅和莊雅和 said...

^^ 謝謝你的分享,祝你生活永遠多彩多姿!..................................................................

芳瑜佩如 said...

幸福沒有鑰匙,只有梯子。.................................................................

陳水卉陳水卉 said...

凡事三思而行,跑得太快是會滑倒的。..................................................

潘凱花潘凱花 said...

甘巴嗲!祝你愈來愈好!............................................................

吳淑懷名明惠 said...

真是太有道理了~~我支持你~~~..................................................

吳淑芬吳淑芬 said...

什麼樣的學習計畫並不重要,重要的是你是什麼樣的人。............................................................

童祖如童祖如 said...

Man is not made for defeat. A mean can be destroyed but not defeated...................................................................

柏陳勳 said...

每日都有新日光,每日都有新希望。..................................................

黃於志豪士賢 said...

世界上沒有本來就應該的事,因為老天爺也沒有劇本..................................................

承王蓁 said...

文章是心情的反應~~祝妳天天寫的都是讓人開心的好文章哦!!...............................................................

伸周怡周怡 said...

愛,拆開來是心和受兩個字。用心去接受對方的一切,用心去愛對方的所有。......................................................................

周志v豪 said...

人逢順境不逞強,身處逆境不示弱。............................................................

王辛江淑萍康 said...

一個人的價值,應該看他貢獻了什麼,而不是他取得了什麼.................................................................

尚铭 said...

永遠不要躊躇伸出你的手。也永遠不要躊躇接受別人伸出的手。.................................................................

凱v胡倫 said...

工作,是愛的具體化~~~~努力吧!........................................

子怡谷怡谷怡谷翔 said...

這麼好的部落格,以後看不到怎麼辦啊!!!............................................................

幸平平平平杰 said...

在莫非定律中有項笨蛋定律:「一個組織中的笨蛋,恆大於等於三分之二。」............................................................

雅玲張雅玲張雅玲張 said...

路過~很有趣吶...............................................................

王辛江淑萍康 said...

初次拜訪,祝你人氣一百分..................................................................

怡靜怡靜怡靜怡雯 said...

相見亦無事,不來常思君......................................................................

佳張張張張燕張張張張張 said...

死亡是悲哀的,但活得不快樂更悲哀。. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

怡靜怡靜怡靜怡雯 said...

喜歡看大家的文章,祝你順心~^^

蕾蕾 said...

在莫非定律中有項笨蛋定律:「一個組織中的笨蛋,恆大於等於三分之二。」............................................................

黃英吳思潔吳思潔邦 said...

在莫非定律中有項笨蛋定律:「一個組織中的笨蛋,恆大於等於三分之二。」..................................................

SadeRa盈君iford0412 said...

在莫非定律中有項笨蛋定律:「一個組織中的笨蛋,恆大於等於三分之二。」..................................................

王辛江淑萍康 said...

時間就是塑造生命的材料。......................................................................