Management of Computing and Information Systems--- security(2)
The current, widespread use of computer networks has led to increased concerns about security. This paper deals with network security in general, and concentrates on corporate networks in particular. A method to develop security concepts for corporate netw
5.
6. 7.
8.
nisms are using cryptological protocols to hide this
information. The transmission of a password is a typical, and commonly used simple authentication exchange mechanism, whereas challenge-response systems and zero-knowledge interactive proof systems are used for strong authentication. In establishing a constant data ow between communicating entities, tra c padding mechanisms are to prevent from tra c analysis attacks. The aim is to make it impossible for an intruder to distinguish data that carry information from data that don't carry information. Routing control mechanisms are to avoid vulnerable links from being used for data transmission. A network with alternative routes is required here, one of which is comparably safe. The security of security mechanisms sometimes depend on the public availability of certain parameters, like public keys in a PKC. Notarization implies that these parameters can be certi ed and published by a trusted certi cation authority. ITU-T X.509 describes a hierarchical layering of certi cation authorities ITU87]. Access control mechanisms have to make sure that users can only access resources in a correct and prede ned way. Discretionary and mandatory access controls are used in closed systems. They are not suitable in open systems; discretionary access controls because of a missing limitation of subject and object sets, and mandatory access controls because of possible incompatibilities among the security labels.
The OSI security architecture has been extended by a multi-part standard, known as open system security frameworks. Each security framework addresses, at a general level, one speci c topic. A working group of JTC1 is dealing with management aspects of OSI security, too.
6 ConclusionsA method to develop security concepts for corporate networks is outlined in this paper. The method follows a layered approach: On the top level there has a policy to be de ned for every security concept. Based on this policy, di erent security services and corresponding mechanisms can be evaluated. Authentication services are fundamental for any network; if authentication is not given, the discussion of further security services is useless. A lot of research is actually being done in developping authentication and key distribution systems. Examples are Kerberos from MIT SNS88], NetSP (former KryptoKnight) from IBM MTVHZ92], SPX from DEC TA91], and TESS from the European Institute
The current, widespread use of computer networks has led to increased concerns about security. This paper deals with network security in general, and concentrates on corporate networks in particular. A method to develop security concepts for corporate netw
for System Security (E.I.S.S.) Bet91]. A Kerberos-like authentication system has been chosen by the Open Software Foundation (OSF) for its Distributed Computing Environment (DCE). Based on the key distribution functionality of an authentication system, data condentiality, integrity, and non-repuiation services can be added straightforward. With regard to a corporate network that is actually being built for the Swiss federal administration authorities, the authentication and key distribution systems that are available today are being considered and evaluated by the Institute for Computer Science and Ap
plied Mathematics (IAM) of the University of Berne, and the information security section of the Swiss Federal O ce of Information Technology and Systems (BFI).
AcknowledgementThe authors would like to express their thanks to Mr. P. Trachsel and Mr. M. Frauenknecht from the Swiss Federal O ce of Information Technology and Systems (BFI) for their support and encouragement.
ReferencesBet91] T. Beth. TESS| The Exponential Security System. Report 91/13, Europaisches Institut fur Systemsicherheit (E.I.S.S), Universitat Karlsruhe, Am Fasanengarten 5, D-76128 Karlsruhe, 1991. DH76] W. Di e and M.E. Hellman. New Directions in Cryptography. IEEE Transactions on Information Theory, IT-22(6):644{ 654, 1976. ISO89] ISO/IEC. Information Processing Systems| Open Systems Interconnection Reference Model| Part 2: Security Architecture. ISO/IEC 7498-2, 1989. ITU87] ITU. The Directory| Authentication Framework. Recommendation X.509, November 1987. MTVHZ92] R. Molva, G. Tsudik, E. Van Herreweghen, and S. Zatti. KryptoKnight Authentication and Key Distribution System. In Y. Deswarte, G. Eizenberg, and J.J. Quisquater, editors, Computer Security| ESORICS '92, pages 155{ 174. Springer-Verlag, 1992. 2nd European Symposium on Research in Computer Security.
The current, widespread use of computer networks has led to increased concerns about security. This paper deals with network security in general, and concentrates on corporate networks in particular. A method to develop security concepts for corporate netw
NIS91] OH92] OH93]
Opp92] OS94] RHA92] SNS88]
TA91]
NIST. A proposed Federal Information Processing Standard for Digital Signature Standard (DSS). Draft Technical Report FIPS PUB XX, Gaithersburg, MD, August 1991. R. Oppliger and D. Hogrefe. Sicherheit in unternehmensweiten Kommunikationsnetzen (CCN). Praxis der Informationsverarbeitung und Kommunikation, 15(4):213{ 217, 1992. R. Oppliger and D. Hogrefe. Corporate Network Security. In Proceedings of the IEEE Singapore International Conference on Networks and International Conference on Information Engineering (SICON/ICIE '93), pages 426{ 430, 1993. R. Oppliger. Computersicherheit. Vieweg-Verlag, 1992. R. Oppliger and P.J. Stussi. Unternehmensweite Kommunikationsnetze. Vieweg-Verlag, 1994. R.L. Rivest, M.E. Hellman, and J.C. An …… 此处隐藏:4407字,全部文档内容请下载后查看。喜欢就下载吧 ……
相关推荐:
- [资格考试]石油钻采专业设备项目可行性研究报告编
- [资格考试]2012-2013学年度第二学期麻风病防治知
- [资格考试]道路勘测设计 绪论
- [资格考试]控烟戒烟知识培训资料
- [资格考试]建设工程安全生产管理(三类人员安全员
- [资格考试]photoshop制作茶叶包装盒步骤平面效果
- [资格考试]授课进度计划表封面(09-10下施工)
- [资格考试]麦肯锡卓越工作方法读后感
- [资格考试]2007年广西区农村信用社招聘考试试题
- [资格考试]软件实施工程师笔试题
- [资格考试]2014年初三数学复习专练第一章 数与式(
- [资格考试]中国糯玉米汁饮料市场发展概况及投资战
- [资格考试]塑钢门窗安装((专项方案)15)
- [资格考试]初中数学答题卡模板2
- [资格考试]2015-2020年中国效率手册行业市场调查
- [资格考试]华北电力大学学习实践活动领导小组办公
- [资格考试]溃疡性结肠炎研究的新进展
- [资格考试]人教版高中语文1—5册(必修)背诵篇目名
- [资格考试]ISO9001-2018质量管理体系最新版标准
- [资格考试]论文之希尔顿酒店集团进入中国的战略研
- 全国中小学生转学申请表
- 《奇迹暖暖》17-支2文学少女小满(9)公
- 2019-2020学年八年级地理下册 第六章
- 2005年高考试题——英语(天津卷)
- 无纺布耐磨测试方法及标准
- 建筑工程施工劳动力安排计划
- (目录)中国中央空调行业市场深度调研分
- 中国期货价格期限结构模型实证分析
- AutoCAD 2016基础教程第2章 AutoCAD基
- 2014-2015学年西城初三期末数学试题及
- 机械加工工艺基础(完整版)
- 归因理论在管理中的应用[1]0
- 突破瓶颈 实现医院可持续发展
- 2014年南京师范大学商学院决策学招生目
- 现浇箱梁支架预压报告
- Excel_2010函数图表入门与实战
- 人教版新课标初中数学 13.1 轴对称 (
- Visual Basic 6.0程序设计教程电子教案
- 2010北京助理工程师考试复习《建筑施工
- 国外5大医疗互联网模式分析




