教学文库网 - 权威文档分享云平台
您的当前位置:首页 > 文库大全 > 资格考试 >

Management of Computing and Information Systems--- security

来源:网络收集 时间:2026-08-31
导读: The current, widespread use of computer networks has led to increased concerns about security. This paper deals with network security in general, and concentrates on corporate networks in particular. A method to develop security concepts f

The current, widespread use of computer networks has led to increased concerns about security. This paper deals with network security in general, and concentrates on corporate networks in particular. A method to develop security concepts for corporate netw

SECURITY CONCEPTS FOR CORPORATE NETWORKSRolf Oppliger Dieter Hogrefe University of Berne Institute for Computer Science and Applied Mathematics Langgassstrasse 51 CH-3012 Berne, Switzerland Tel.+41 31 631 49 03 Fax.+41 31 631 39 65 Internet: foppliger,hogrefeg@iam.unibe.chCR Category and Subject Descriptor: C.2.0 Computer Systems Organization]: Computer-Communication Networks| general; K.6.5 Computing Milieux] Management of Computing and Information Systems| security and protection General Terms: Management, Security, Standardization Additional Key Words: Corporate Network, OSI, Security Architecture

AbstractThe current, widespread use of computer networks has led to increased concerns about security. This paper deals with network security in general, and concentrates on corporate networks in particular. A method to develop security concepts for corporate networks is introduced, and stepwise re ned.

The current, widespread use of computer networks has led to increased concerns about security. This paper deals with network security in general, and concentrates on corporate networks in particular. A method to develop security concepts for corporate netw

1 IntroductionIt is assumed that the reader of this paper is familiar with the fundamentals of computer networks, open systems, and OSI networks. A computer network consists of interconnected computer systems that can either be closed or open. Closed systems are proprietary, usually being able to communicate only with systems of the same manufacturer. In using standardized protocols to provide standardized services, open systems are free to communicate with other open systems, forming an OSI network (Open Systems Interconnection). OSI standards are being developed by the Joint Technical Committee 1 (JTC1) of the International Standards Organization (ISO), and the International Electrotechnical Commission (IEC). Corporate networks use public services to interconnect geographically distributed local area networks and private branch exchanges. Public services are o ered in wide area networks; examples are leased lines, circuit switched lines, and services that are provided in packet switched data networks OS94]. A security concept is needed to make a corporate network comparably secure Opp92, OH92, OH93]. A method to develop security concepts for corporate networks is introduced in this paper. It is organized as follows: Possible attacks are outlined in section two. The method is shortly described in section three, and stepwise re ned in sections four and ve. Conclusions are drawn in section six.

2 AttacksAttacks threaten the security (con dentiality, integrity, and availability) of corporate networks, and data that are stored or transmitted within. There are passive and active attacks to be distinguished: The con dentiality of data is threatened by passive attacks. The situation is shown in gure 1. The data tra c between the sender and the receiver is observed by the intruder. It has to be distinguished, whether the intruder is able to interpret the data, or not.{ In a passive wiretapping attack the intruder is able to interpret the data, and to understand its information accordingly.{ In a tra c analysis attack the intruder is not abl

e to interpret the data. He can only learn from the origins, destinations, frequencies and sizes of messages or data units. The fact that two entities are communicating may already be compromising in itself; this may be true for stock-brokers and military commanders. The feasibility of passive attacks primarily depends on the physical transmission media in use. Radio and satellite links are very easy to intercept, whereas

The current, widespread use of computer networks has led to increased concerns about security. This paper deals with network security in general, and concentrates on corporate networks in particular. A method to develop security concepts for corporate netw

Sender Intruder

Receiver

Figure 1: Passive attack metallic conductors, like twisted pairs or coaxial cables, can only be tapped if they are physically accessible by the intruder. The tapping of light wave conductors is even more di cult.Sender Intruder Receiver

Figure 2: Active attack The integrity or availability of data in transmission is threatened by active attacks. The situation is shown in gure 2. The data tra c between the sender and the receiver is fully controlled by the intruder. He can modify, extend, delay, destroy, copy, or reply messages or single data units. He can also ood the receiver. Provided with the authentication information of some legitimate user, he can masquerade, and pretend to be someone else. If passwords are used for authentication purposes, and if these passwords are transmitted within the network, the intruder can catch them with a passive wiretapping attack. As a matter of fact, the transmission of passwords is a major vulnerability of most computer networks that are in use today. Natural disasters, like lightnings, res, oods, or earthquakes, threaten the safety of corporate networks. Because they can be controlled by architectural and organizational counter-measures to a certain degree, they are not subject to this paper. A corporate network is said to be secure, if it is able to prevent from passive and active attacks. This goal is hard to reach, not only because of the huge size of a corporate network, but also because of its heterogenity; there may be various computer systems from di erent manufacturers, possibly running di erent operating systems, communication and application software, interconnected to one corporate network. Gateways may exist to public networks …… 此处隐藏:8167字,全部文档内容请下载后查看。喜欢就下载吧 ……

Management of Computing and Information Systems--- security.doc 将本文的Word文档下载到电脑,方便复制、编辑、收藏和打印
本文链接:https://www.jiaowen.net/wenku/104394.html(转载请注明文章来源)
Copyright © 2020-2025 教文网 版权所有
声明 :本网站尊重并保护知识产权,根据《信息网络传播权保护条例》,如果我们转载的作品侵犯了您的权利,请在一个月内通知我们,我们会及时删除。
客服QQ:78024566 邮箱:78024566@qq.com
苏ICP备19068818号-2
Top
× 游客快捷下载通道(下载后可以自由复制和排版)
VIP包月下载
特价:29 元/月 原价:99元
低至 0.3 元/份 每月下载150
全站内容免费自由复制
VIP包月下载
特价:29 元/月 原价:99元
低至 0.3 元/份 每月下载150
全站内容免费自由复制
注:下载文档有可能出现无法下载或内容有问题,请联系客服协助您处理。
× 常见问题(客服时间:周一到周五 9:30-18:00)