Management of Computing and Information Systems--- security
The current, widespread use of computer networks has led to increased concerns about security. This paper deals with network security in general, and concentrates on corporate networks in particular. A method to develop security concepts for corporate netw
SECURITY CONCEPTS FOR CORPORATE NETWORKSRolf Oppliger Dieter Hogrefe University of Berne Institute for Computer Science and Applied Mathematics Langgassstrasse 51 CH-3012 Berne, Switzerland Tel.+41 31 631 49 03 Fax.+41 31 631 39 65 Internet: foppliger,hogrefeg@iam.unibe.chCR Category and Subject Descriptor: C.2.0 Computer Systems Organization]: Computer-Communication Networks| general; K.6.5 Computing Milieux] Management of Computing and Information Systems| security and protection General Terms: Management, Security, Standardization Additional Key Words: Corporate Network, OSI, Security Architecture
AbstractThe current, widespread use of computer networks has led to increased concerns about security. This paper deals with network security in general, and concentrates on corporate networks in particular. A method to develop security concepts for corporate networks is introduced, and stepwise re ned.
The current, widespread use of computer networks has led to increased concerns about security. This paper deals with network security in general, and concentrates on corporate networks in particular. A method to develop security concepts for corporate netw
1 IntroductionIt is assumed that the reader of this paper is familiar with the fundamentals of computer networks, open systems, and OSI networks. A computer network consists of interconnected computer systems that can either be closed or open. Closed systems are proprietary, usually being able to communicate only with systems of the same manufacturer. In using standardized protocols to provide standardized services, open systems are free to communicate with other open systems, forming an OSI network (Open Systems Interconnection). OSI standards are being developed by the Joint Technical Committee 1 (JTC1) of the International Standards Organization (ISO), and the International Electrotechnical Commission (IEC). Corporate networks use public services to interconnect geographically distributed local area networks and private branch exchanges. Public services are o ered in wide area networks; examples are leased lines, circuit switched lines, and services that are provided in packet switched data networks OS94]. A security concept is needed to make a corporate network comparably secure Opp92, OH92, OH93]. A method to develop security concepts for corporate networks is introduced in this paper. It is organized as follows: Possible attacks are outlined in section two. The method is shortly described in section three, and stepwise re ned in sections four and ve. Conclusions are drawn in section six.
2 AttacksAttacks threaten the security (con dentiality, integrity, and availability) of corporate networks, and data that are stored or transmitted within. There are passive and active attacks to be distinguished: The con dentiality of data is threatened by passive attacks. The situation is shown in gure 1. The data tra c between the sender and the receiver is observed by the intruder. It has to be distinguished, whether the intruder is able to interpret the data, or not.{ In a passive wiretapping attack the intruder is able to interpret the data, and to understand its information accordingly.{ In a tra c analysis attack the intruder is not abl
e to interpret the data. He can only learn from the origins, destinations, frequencies and sizes of messages or data units. The fact that two entities are communicating may already be compromising in itself; this may be true for stock-brokers and military commanders. The feasibility of passive attacks primarily depends on the physical transmission media in use. Radio and satellite links are very easy to intercept, whereas
The current, widespread use of computer networks has led to increased concerns about security. This paper deals with network security in general, and concentrates on corporate networks in particular. A method to develop security concepts for corporate netw
Sender Intruder
Receiver
Figure 1: Passive attack metallic conductors, like twisted pairs or coaxial cables, can only be tapped if they are physically accessible by the intruder. The tapping of light wave conductors is even more di cult.Sender Intruder Receiver
Figure 2: Active attack The integrity or availability of data in transmission is threatened by active attacks. The situation is shown in gure 2. The data tra c between the sender and the receiver is fully controlled by the intruder. He can modify, extend, delay, destroy, copy, or reply messages or single data units. He can also ood the receiver. Provided with the authentication information of some legitimate user, he can masquerade, and pretend to be someone else. If passwords are used for authentication purposes, and if these passwords are transmitted within the network, the intruder can catch them with a passive wiretapping attack. As a matter of fact, the transmission of passwords is a major vulnerability of most computer networks that are in use today. Natural disasters, like lightnings, res, oods, or earthquakes, threaten the safety of corporate networks. Because they can be controlled by architectural and organizational counter-measures to a certain degree, they are not subject to this paper. A corporate network is said to be secure, if it is able to prevent from passive and active attacks. This goal is hard to reach, not only because of the huge size of a corporate network, but also because of its heterogenity; there may be various computer systems from di erent manufacturers, possibly running di erent operating systems, communication and application software, interconnected to one corporate network. Gateways may exist to public networks …… 此处隐藏:8167字,全部文档内容请下载后查看。喜欢就下载吧 ……
相关推荐:
- [资格考试]石油钻采专业设备项目可行性研究报告编
- [资格考试]2012-2013学年度第二学期麻风病防治知
- [资格考试]道路勘测设计 绪论
- [资格考试]控烟戒烟知识培训资料
- [资格考试]建设工程安全生产管理(三类人员安全员
- [资格考试]photoshop制作茶叶包装盒步骤平面效果
- [资格考试]授课进度计划表封面(09-10下施工)
- [资格考试]麦肯锡卓越工作方法读后感
- [资格考试]2007年广西区农村信用社招聘考试试题
- [资格考试]软件实施工程师笔试题
- [资格考试]2014年初三数学复习专练第一章 数与式(
- [资格考试]中国糯玉米汁饮料市场发展概况及投资战
- [资格考试]塑钢门窗安装((专项方案)15)
- [资格考试]初中数学答题卡模板2
- [资格考试]2015-2020年中国效率手册行业市场调查
- [资格考试]华北电力大学学习实践活动领导小组办公
- [资格考试]溃疡性结肠炎研究的新进展
- [资格考试]人教版高中语文1—5册(必修)背诵篇目名
- [资格考试]ISO9001-2018质量管理体系最新版标准
- [资格考试]论文之希尔顿酒店集团进入中国的战略研
- 全国中小学生转学申请表
- 《奇迹暖暖》17-支2文学少女小满(9)公
- 2019-2020学年八年级地理下册 第六章
- 2005年高考试题——英语(天津卷)
- 无纺布耐磨测试方法及标准
- 建筑工程施工劳动力安排计划
- (目录)中国中央空调行业市场深度调研分
- 中国期货价格期限结构模型实证分析
- AutoCAD 2016基础教程第2章 AutoCAD基
- 2014-2015学年西城初三期末数学试题及
- 机械加工工艺基础(完整版)
- 归因理论在管理中的应用[1]0
- 突破瓶颈 实现医院可持续发展
- 2014年南京师范大学商学院决策学招生目
- 现浇箱梁支架预压报告
- Excel_2010函数图表入门与实战
- 人教版新课标初中数学 13.1 轴对称 (
- Visual Basic 6.0程序设计教程电子教案
- 2010北京助理工程师考试复习《建筑施工
- 国外5大医疗互联网模式分析




