Добавил:
ivanov666
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз:
Предмет:
Файл:Information protection in digital communication systems. Textbook
.pdf
A.M. Golikov
INFORMATION PROTECTION
IN DIGITAL COMMUNICATION
SYSTEMS
Textbook
Translation from the Russian
Participant of the 1st All-Russian competition
of author’s publications and innovative content
“Digital University Library”
Moscow
IPR Media
2024

А.М. Голиков
ЗАЩИТА ИНФОРМАЦИИ
В ЦИФРОВЫХ СИСТЕМАХ СВЯЗИ
Учебник
Участник I Всероссийского конкурса
авторских публикаций и инновационного контента
«Библиотека цифрового университета»
Москва
Ай Пи Ар Медиа

UDC 621.39
BBK 32.973
G60
Author:
Golikov A.M. — Ph.D. of Engineering Sciences, Associate Professor
at the Department of Radio Engineering Systems of Tomsk State University
ofcontrol systems and radio electronics
Reviewer:
Krasnenko N.P. — Holder of an Advanced Doctorate (Doctor of Science)
in Physico-mathematical Sciences, Chief Research Officer of Institute
of Climate and Ecological Systems Monitoring of Siberian Branch
of the Russian Academy of Sciences, Professor at the Department
of Tomsk State University of control systems and radio electronics
Golikov, Alexander Mikhailovich.
G60 Information protection in digital communication systems : textbook /
A.M. Golikov. — Moscow : IPR Media, 2024. — 322 p. — Text : digital.
ISBN 978-5-4497-3194-4
The textbook examines the basic concepts of the theory of information security, the
methodology for constructing security systems for digital communication systems (DCS), the
concept of formal security policies, and provides a classification of mathematical models of
information security. The main discretionary and mandatory models, security criteria, including
international standards are described: ISO 15408 “Evaluation criteria for IT security” Common
Criteria and ISO “Code of practice for information security management”, as well as the main
means of information security, including informal (legislative, administrative, procedural) and
formal (software and technical). A standard model of the security of an enterprise information
network, methods and means of auditing the security of information systems are presented.
The textbook is intended for students of a larger group of specialties and areas of training
“Electronics, radio engineering and communication systems”, studying the disciplines “Digital
radio communication systems and devices”, “Secure communication systems”, “Radio
communication systems”, and will also be useful for studying the disciplines “Systems
Engineering”, “General Theory of Communications”, “Mobile communication systems based
on noise-like signals”, “Networks and mobile communication systems”, “Radio access
systems”, “Theory and technology of information transmission”.
Educational digital edition
ISBN 978-5-4497-3194-4 (en) © Голиков A.M., 2022
ISBN 978-5-4497-1742-9 (rus) © ООО Компания «Ай Пи Ар Медиа», 2022
© English edition, translation, design.
LLC “IPR Media”, 2024

Educational publication
Golikov Alexander Mikhailovich
Editor A.D. Talmaeva
Technical editor, computer layout Yu.Yu. Zheltova, N.G. Shindina
Proofreader O.A. Adyasova, А. Ashirbaeva
Cover by Y.A. Kirsanov, S.S. Siziumova, photo bank “Freepik”
Signed for use on 03.07.2024. Data volume 9 Mb
LLC Company “IPR Media”
8 800 555 22 35 (toll-free within Russia)
E-mail: sales@iprmedia.ru

5
CONTENT
INTRODUCTION ...................................................................................... 9
CHAPTER 1. STRUCTURE OF INFORMATION
SECURITY THEORY ............................................................................. 11
1.1. Basic concepts of information security theory ............................ 11
1.2. Value of information .................................................................... 13
1.3. Analysis of information security threats ...................................... 14
1.4. Structure of information security theory ...................................... 20
1.5. Main types of attacks on dcs ........................................................ 23
CHAPTER 2. METHODOLOGY FOR BUILDING DCS
PROTECTION SYSTEMS ..................................................................... 32
2.1. Building a system for protection against the threat
of violation of confidentiality information ......................................... 32
2.2. Building a system for protection against the threat
of integrity violation ............................................................................ 40
2.3. Building a system for protection against the threat
of information access denial ............................................................... 43
2.4. Building protection systems against the threat of
disclosure of information system parameters ..................................... 45
2.5. Methodology for building secured dcs ........................................ 51
CHAPTER 3. FORMAL SECURITY POLICIES ............................... 62
3.1. The concept of formal security policy ......................................... 62
3.2. Concept of access and security monitor ...................................... 64
3.3. Main types of formal security policies ........................................ 72
3.4. Development and implementation of formal
security policies ................................................................................... 74

6
CHAPTER 4. MATHEMATICAL MODELS
OF INFORMATION SECURITY ........................................................ 102
4.1. Classification of mathematical models
of information security by main types of threats .............................. 104
4.2. Access condition models ............................................................ 105
4.2.1. Description of the protection system using
the access matrix ........................................................................ 105
4.2.2. Harrison — Ruzzo — Ullman discretionary model......... 107
4.2.3. Take-Grant model ............................................................ 111
4.2.4. Extended Take-Grant Model ............................................ 114
4.2.5. Model ADEPT-50............................................................. 116
4.2.6. Hurston model .................................................................. 117
4.2.7. Mandatory Bell — LaPadula model ................................ 118
4.2.8. Security level grid ............................................................ 120
4.2.9. Classic Bell — LaPadula mandate model ....................... 121
4.2.10. Safe transition function .................................................. 123
4.2.11. Authorized Subjects ........................................................ 124
4.2.12. Sharing model ................................................................ 125
4.2.13. Application of mandate models ..................................... 126
4.2.14. Role-based security policy ............................................. 127
4.2.15. Probabilistic models ...................................................... 134
4.2.16. Information models ........................................................ 136
4.3. Integrity control models ............................................................. 137
4.3.1. Biba model ....................................................................... 137
4.3.2. Clark-Wilson model ......................................................... 139
4.4. Mechanism for protection against the threat
of denial of service ............................................................................ 140
4.4.1. Mandate model ................................................................. 140
4.4.2. Millen model — resource allocation model .................... 141

7
CHAPTER 5. BASIC CRITERIA FOR
THE SECURITY OF DCS. SECURITY CLASSES .......................... 143
5.1. TCSEC computer systems security assessment standard
(“Orange book”) ................................................................................ 143
5.2. Concepts of protection of DCS and computing equipment
according to guidance documents of the Russian Federation’s
State technical commission ............................................................... 155
5.3. Criteria for assessing the security of information
technology (Common Criteria) ......................................................... 159
CHAPTER 6. MAIN STAGES OF BUILDING A SECURE
INFORMATION SYSTEM .................................................................. 167
6.1. Legislative level ......................................................................... 169
6.1.1. Federal Law “On Information, Information
Technologies and Information Protection” ............................... 169
6.1.2. Federal Law “On Licensing
of Certain Types of Activities”................................................... 172
6.1.3. Set of guiding documents of the State Technical
Commission under the President of the
Russian Federation .................................................................... 173
6.2. Administrative level ................................................................... 186
6.2.1. Security policy .................................................................. 187
6.2.2. Risk analysis ..................................................................... 193
6.3. Procedural level .......................................................................... 199
6.4. Software and technical level ...................................................... 213
6.4.1. Identification and Authentication .................................... 213
6.4.2. Access control .................................................................. 222
6.4.3. Registration and audit ..................................................... 228
6.4.4. Cryptography ................................................................... 230
6.4.5. Shielding ........................................................................... 232
6.4.6. Antivirus protection ......................................................... 236

8
6.5. Security model of an enterprise information network ............... 240
6.6. Standard security policy for a small and medium
business — set of documents and instructions ................................. 244
6.6.1. Typical Security Policy .................................................... 244
6.6.2. Standard documents and instructions.............................. 247
CHAPTER 7. INFORMATION SYSTEM
SECURITY CONTROL ........................................................................ 254
7.1. Regulatory framework for audit ................................................ 254
7.1.1. Review of legislation in the field
of security auditing .................................................................... 254
7.1.2. Auditing Standards........................................................... 262
7.2. Methods and tools of auditing security
of information systems ...................................................................... 272
7.2.1. Basic concepts and definitions ......................................... 272
7.2.2. Main stages of the audit ................................................... 277
7.2.3. Security analysis technique .............................................. 289
7.2.4. Security analysis tools ..................................................... 298
7.2.5. Architecture of audit systems ........................................... 306
7.2.6. Requirements for active audit systems ............................. 309
7.2.7. Possible criteria for evaluating
active audit systems .................................................................... 312
7.2.8. Audit results ..................................................................... 316
CONCLUSION ....................................................................................... 317
BIBLIOGRAPHICAL LIST ................................................................. 321

9
INTRODUCTION
Information protection is currently one of the leading areas of ensuring
the security of the state, organization, and individual. Problems of various
aspects of security are increasingly occupying the minds of specialists, since
from their own experience people come to the conclusion that it is
impossible to ensure the effective functioning of the state and organization,
as well as a decent “quality” of human life, fighting off threats like
mosquitoes in a swampy place — a lot of effort, but little use. The path to
solving a security problem, like other problems, begins with a systematic
approach to it and its system analysis. The more clearly the sources of
protected information, the places and conditions of their location, the
methods and means of obtaining information by an attacker are defined, the
more specifically the protection tasks and requirements for the appropriate
means can be formulated. Specificity of tasks and requirements is a
necessary condition for the targeted and rational use of allocated resources.
Sources of information are determined as a result of structuring the protected
information, and the places and conditions of their location are determined
based on the results of modeling the objects of protection. The increase in
the number and types of threats to information security, accompanying the
increasing importance of information in the life of society and people, is a
trend that cannot be ignored. An example of this is the consequences of the
widespread introduction of digital communication systems (DCS). Along
with the great advantages for users of this relatively new type of
communication for Russia compared to traditional wired telephone
communications, where a very serious problem has arisen in ensuring the
confidentiality of conversations and data transmission.
The main provisions of information security are the study and analysis
of the causes of violations of the security of information systems.
Development of effective security models that are adequate to the current
level of development of software and hardware, as well as the capabilities
of attackers and destructive software. Creation of methods and means for

10
the correct implementation of security models in existing digital data
centers, with the possibility of flexible security management depending on
the requirements put forward, acceptable risk and resource consumption.
The need to develop tools for analyzing the security of information systems
using test actions.
As a result of mastering the textbook material, according to the
educational standard, students must know the methods of protecting digital
systems, be able to use modern mathematical apparatus to solve the problem
of protecting information in digital systems, and master methods for
optimizing the protection of designed digital systems.
In preparing this textbook, materials from various sources given in the
bibliography were used.
Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]
