教学文库网 - 权威文档分享云平台
您的当前位置:首页 > 文库大全 > 资格考试 >

Management of Computing and Information Systems--- security(2)

来源:网络收集 时间:2026-08-31
导读: The current, widespread use of computer networks has led to increased concerns about security. This paper deals with network security in general, and concentrates on corporate networks in particular.

The current, widespread use of computer networks has led to increased concerns about security. This paper deals with network security in general, and concentrates on corporate networks in particular. A method to develop security concepts for corporate netw

5.

6. 7.

8.

nisms are using cryptological protocols to hide this

information. The transmission of a password is a typical, and commonly used simple authentication exchange mechanism, whereas challenge-response systems and zero-knowledge interactive proof systems are used for strong authentication. In establishing a constant data ow between communicating entities, tra c padding mechanisms are to prevent from tra c analysis attacks. The aim is to make it impossible for an intruder to distinguish data that carry information from data that don't carry information. Routing control mechanisms are to avoid vulnerable links from being used for data transmission. A network with alternative routes is required here, one of which is comparably safe. The security of security mechanisms sometimes depend on the public availability of certain parameters, like public keys in a PKC. Notarization implies that these parameters can be certi ed and published by a trusted certi cation authority. ITU-T X.509 describes a hierarchical layering of certi cation authorities ITU87]. Access control mechanisms have to make sure that users can only access resources in a correct and prede ned way. Discretionary and mandatory access controls are used in closed systems. They are not suitable in open systems; discretionary access controls because of a missing limitation of subject and object sets, and mandatory access controls because of possible incompatibilities among the security labels.

The OSI security architecture has been extended by a multi-part standard, known as open system security frameworks. Each security framework addresses, at a general level, one speci c topic. A working group of JTC1 is dealing with management aspects of OSI security, too.

6 ConclusionsA method to develop security concepts for corporate networks is outlined in this paper. The method follows a layered approach: On the top level there has a policy to be de ned for every security concept. Based on this policy, di erent security services and corresponding mechanisms can be evaluated. Authentication services are fundamental for any network; if authentication is not given, the discussion of further security services is useless. A lot of research is actually being done in developping authentication and key distribution systems. Examples are Kerberos from MIT SNS88], NetSP (former KryptoKnight) from IBM MTVHZ92], SPX from DEC TA91], and TESS from the European Institute

The current, widespread use of computer networks has led to increased concerns about security. This paper deals with network security in general, and concentrates on corporate networks in particular. A method to develop security concepts for corporate netw

for System Security (E.I.S.S.) Bet91]. A Kerberos-like authentication system has been chosen by the Open Software Foundation (OSF) for its Distributed Computing Environment (DCE). Based on the key distribution functionality of an authentication system, data condentiality, integrity, and non-repuiation services can be added straightforward. With regard to a corporate network that is actually being built for the Swiss federal administration authorities, the authentication and key distribution systems that are available today are being considered and evaluated by the Institute for Computer Science and Ap

plied Mathematics (IAM) of the University of Berne, and the information security section of the Swiss Federal O ce of Information Technology and Systems (BFI).

AcknowledgementThe authors would like to express their thanks to Mr. P. Trachsel and Mr. M. Frauenknecht from the Swiss Federal O ce of Information Technology and Systems (BFI) for their support and encouragement.

ReferencesBet91] T. Beth. TESS| The Exponential Security System. Report 91/13, Europaisches Institut fur Systemsicherheit (E.I.S.S), Universitat Karlsruhe, Am Fasanengarten 5, D-76128 Karlsruhe, 1991. DH76] W. Di e and M.E. Hellman. New Directions in Cryptography. IEEE Transactions on Information Theory, IT-22(6):644{ 654, 1976. ISO89] ISO/IEC. Information Processing Systems| Open Systems Interconnection Reference Model| Part 2: Security Architecture. ISO/IEC 7498-2, 1989. ITU87] ITU. The Directory| Authentication Framework. Recommendation X.509, November 1987. MTVHZ92] R. Molva, G. Tsudik, E. Van Herreweghen, and S. Zatti. KryptoKnight Authentication and Key Distribution System. In Y. Deswarte, G. Eizenberg, and J.J. Quisquater, editors, Computer Security| ESORICS '92, pages 155{ 174. Springer-Verlag, 1992. 2nd European Symposium on Research in Computer Security.

The current, widespread use of computer networks has led to increased concerns about security. This paper deals with network security in general, and concentrates on corporate networks in particular. A method to develop security concepts for corporate netw

NIS91] OH92] OH93]

Opp92] OS94] RHA92] SNS88]

TA91]

NIST. A proposed Federal Information Processing Standard for Digital Signature Standard (DSS). Draft Technical Report FIPS PUB XX, Gaithersburg, MD, August 1991. R. Oppliger and D. Hogrefe. Sicherheit in unternehmensweiten Kommunikationsnetzen (CCN). Praxis der Informationsverarbeitung und Kommunikation, 15(4):213{ 217, 1992. R. Oppliger and D. Hogrefe. Corporate Network Security. In Proceedings of the IEEE Singapore International Conference on Networks and International Conference on Information Engineering (SICON/ICIE '93), pages 426{ 430, 1993. R. Oppliger. Computersicherheit. Vieweg-Verlag, 1992. R. Oppliger and P.J. Stussi. Unternehmensweite Kommunikationsnetze. Vieweg-Verlag, 1994. R.L. Rivest, M.E. Hellman, and J.C. An …… 此处隐藏:4407字,全部文档内容请下载后查看。喜欢就下载吧 ……

Management of Computing and Information Systems--- security(2).doc 将本文的Word文档下载到电脑,方便复制、编辑、收藏和打印
本文链接:https://www.jiaowen.net/wenku/104394.html(转载请注明文章来源)
Copyright © 2020-2025 教文网 版权所有
声明 :本网站尊重并保护知识产权,根据《信息网络传播权保护条例》,如果我们转载的作品侵犯了您的权利,请在一个月内通知我们,我们会及时删除。
客服QQ:78024566 邮箱:78024566@qq.com
苏ICP备19068818号-2
Top
× 游客快捷下载通道(下载后可以自由复制和排版)
VIP包月下载
特价:29 元/月 原价:99元
低至 0.3 元/份 每月下载150
全站内容免费自由复制
VIP包月下载
特价:29 元/月 原价:99元
低至 0.3 元/份 每月下载150
全站内容免费自由复制
注:下载文档有可能出现无法下载或内容有问题,请联系客服协助您处理。
× 常见问题(客服时间:周一到周五 9:30-18:00)