Добавил:
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:

Information protection in digital communication systems. Textbook

.pdf
Скачиваний:
0
Добавлен:
07.09.2026
Размер:
2 Мб
Скачать
A.M. Golikov
INFORMATION PROTECTION
IN DIGITAL COMMUNICATION
SYSTEMS
Translation from the Russian
Participant of the 1st All-Russian competition
of author’s publications and innovative content
“Digital University Library”
Moscow
IPR Media
2024
А.М. Голиков
ЗАЩИТА ИНФОРМАЦИИ
В ЦИФРОВЫХ СИСТЕМАХ СВЯЗИ
Учебник
Участник I Всероссийского конкурса
авторских публикаций и инновационного контента
«Библиотека цифрового университета»
Москва
Ай Пи Ар Медиа
UDC 621.39 BBK 32.973
G60
Author:
Golikov A.M. — Ph.D. of Engineering Sciences, Associate Professor
at the Department of Radio Engineering Systems of Tomsk State University
ofcontrol systems and radio electronics
Reviewer:
Krasnenko N.P. — Holder of an Advanced Doctorate (Doctor of Science)
in Physico-mathematical Sciences, Chief Research Officer of Institute
of Climate and Ecological Systems Monitoring of Siberian Branch
of the Russian Academy of Sciences, Professor at the Department
of Tomsk State University of control systems and radio electronics
Golikov, Alexander Mikhailovich.
G60 Information protection in digital communication systems : textbook /
A.M. Golikov. Moscow : IPR Media, 2024. 322 p. Text : digital.
ISBN 978-5-4497-3194-4
The textbook examines the basic concepts of the theory of information security, the methodology for constructing security systems for digital communication systems (DCS), the concept of formal security policies, and provides a classification of mathematical models of information security. The main discretionary and mandatory models, security criteria, including
international standards are described: ISO 15408 “Evaluation criteria for IT security” Common Criteria and ISO “Code of practice for information security management”, as well as the main
means of information security, including informal (legislative, administrative, procedural) and formal (software and technical). A standard model of the security of an enterprise information network, methods and means of auditing the security of information systems are presented.
The textbook is intended for students of a larger group of specialties and areas of training
“Electronics, radio engineering and communication systems”, studying the disciplines “Digital
radio communication systems and devices”, “Secure communication systems”, “Radio
communication systems”, and will also be useful for studying the disciplines “Systems Engineering”, “General Theory of Communications”, “Mobile communication systems based
on noise-like signals”, “Networks and mobile communication systems”, “Radio access systems”, “Theory and technology of information transmission”.
Educational digital edition
ISBN 978-5-4497-3194-4 (en) © Голиков A.M., 2022 ISBN 978-5-4497-1742-9 (rus) © ООО Компания «Ай Пи Ар Медиа», 2022
© English edition, translation, design.
LLC “IPR Media”, 2024
Educational publication
Golikov Alexander Mikhailovich
Editor A.D. Talmaeva
Technical editor, computer layout Yu.Yu. Zheltova, N.G. Shindina
Proofreader O.A. Adyasova, А. Ashirbaeva
Cover by Y.A. Kirsanov, S.S. Siziumova, photo bank “Freepik”
Signed for use on 03.07.2024. Data volume 9 Mb
LLC Company IPR Media
8 800 555 22 35 (toll-free within Russia)
E-mail: sales@iprmedia.ru
5
CONTENT
INTRODUCTION ...................................................................................... 9
CHAPTER 1. STRUCTURE OF INFORMATION
SECURITY THEORY ............................................................................. 11
1.1. Basic concepts of information security theory ............................ 11
1.2. Value of information .................................................................... 13
1.3. Analysis of information security threats ...................................... 14
1.4. Structure of information security theory ...................................... 20
1.5. Main types of attacks on dcs ........................................................ 23
CHAPTER 2. METHODOLOGY FOR BUILDING DCS
PROTECTION SYSTEMS ..................................................................... 32
2.1. Building a system for protection against the threat
of violation of confidentiality information ......................................... 32
2.2. Building a system for protection against the threat
of integrity violation ............................................................................ 40
2.3. Building a system for protection against the threat
of information access denial ............................................................... 43
2.4. Building protection systems against the threat of
disclosure of information system parameters ..................................... 45
2.5. Methodology for building secured dcs ........................................ 51
CHAPTER 3. FORMAL SECURITY POLICIES ............................... 62
3.1. The concept of formal security policy ......................................... 62
3.2. Concept of access and security monitor ...................................... 64
3.3. Main types of formal security policies ........................................ 72
3.4. Development and implementation of formal
security policies ................................................................................... 74
6
CHAPTER 4. MATHEMATICAL MODELS
OF INFORMATION SECURITY ........................................................ 102
4.1. Classification of mathematical models
of information security by main types of threats .............................. 104
4.2. Access condition models ............................................................ 105
4.2.1. Description of the protection system using
the access matrix ........................................................................ 105
4.2.2. Harrison Ruzzo Ullman discretionary model......... 107
4.2.3. Take-Grant model ............................................................ 111
4.2.4. Extended Take-Grant Model ............................................ 114
4.2.5. Model ADEPT-50............................................................. 116
4.2.6. Hurston model .................................................................. 117
4.2.7. Mandatory Bell LaPadula model ................................ 118
4.2.8. Security level grid ............................................................ 120
4.2.9. Classic Bell LaPadula mandate model ....................... 121
4.2.10. Safe transition function .................................................. 123
4.2.11. Authorized Subjects ........................................................ 124
4.2.12. Sharing model ................................................................ 125
4.2.13. Application of mandate models ..................................... 126
4.2.14. Role-based security policy ............................................. 127
4.2.15. Probabilistic models ...................................................... 134
4.2.16. Information models ........................................................ 136
4.3. Integrity control models ............................................................. 137
4.3.1. Biba model ....................................................................... 137
4.3.2. Clark-Wilson model ......................................................... 139
4.4. Mechanism for protection against the threat
of denial of service ............................................................................ 140
4.4.1. Mandate model ................................................................. 140
4.4.2. Millen model resource allocation model .................... 141
7
CHAPTER 5. BASIC CRITERIA FOR
THE SECURITY OF DCS. SECURITY CLASSES .......................... 143
5.1. TCSEC computer systems security assessment standard
(“Orange book”) ................................................................................ 143
5.2. Concepts of protection of DCS and computing equipment according to guidance documents of the Russian Federation’s
State technical commission ............................................................... 155
5.3. Criteria for assessing the security of information
technology (Common Criteria) ......................................................... 159
CHAPTER 6. MAIN STAGES OF BUILDING A SECURE
INFORMATION SYSTEM .................................................................. 167
6.1. Legislative level ......................................................................... 169
6.1.1. Federal Law “On Information, Information
Technologies and Information Protection” ............................... 169
6.1.2. Federal Law “On Licensing
of Certain Types of Activities”................................................... 172
6.1.3. Set of guiding documents of the State Technical Commission under the President of the
Russian Federation .................................................................... 173
6.2. Administrative level ................................................................... 186
6.2.1. Security policy .................................................................. 187
6.2.2. Risk analysis ..................................................................... 193
6.3. Procedural level .......................................................................... 199
6.4. Software and technical level ...................................................... 213
6.4.1. Identification and Authentication .................................... 213
6.4.2. Access control .................................................................. 222
6.4.3. Registration and audit ..................................................... 228
6.4.4. Cryptography ................................................................... 230
6.4.5. Shielding ........................................................................... 232
6.4.6. Antivirus protection ......................................................... 236
8
6.5. Security model of an enterprise information network ............... 240
6.6. Standard security policy for a small and medium
business set of documents and instructions ................................. 244
6.6.1. Typical Security Policy .................................................... 244
6.6.2. Standard documents and instructions.............................. 247
CHAPTER 7. INFORMATION SYSTEM
SECURITY CONTROL ........................................................................ 254
7.1. Regulatory framework for audit ................................................ 254
7.1.1. Review of legislation in the field
of security auditing .................................................................... 254
7.1.2. Auditing Standards........................................................... 262
7.2. Methods and tools of auditing security
of information systems ...................................................................... 272
7.2.1. Basic concepts and definitions ......................................... 272
7.2.2. Main stages of the audit ................................................... 277
7.2.3. Security analysis technique .............................................. 289
7.2.4. Security analysis tools ..................................................... 298
7.2.5. Architecture of audit systems ........................................... 306
7.2.6. Requirements for active audit systems ............................. 309
7.2.7. Possible criteria for evaluating
active audit systems .................................................................... 312
7.2.8. Audit results ..................................................................... 316
CONCLUSION ....................................................................................... 317
BIBLIOGRAPHICAL LIST ................................................................. 321
9
INTRODUCTION
Information protection is currently one of the leading areas of ensuring the security of the state, organization, and individual. Problems of various aspects of security are increasingly occupying the minds of specialists, since from their own experience people come to the conclusion that it is impossible to ensure the effective functioning of the state and organization,
as well as a decent “quality” of human life, fighting off threats like
mosquitoes in a swampy place a lot of effort, but little use. The path to solving a security problem, like other problems, begins with a systematic approach to it and its system analysis. The more clearly the sources of protected information, the places and conditions of their location, the methods and means of obtaining information by an attacker are defined, the more specifically the protection tasks and requirements for the appropriate means can be formulated. Specificity of tasks and requirements is a necessary condition for the targeted and rational use of allocated resources. Sources of information are determined as a result of structuring the protected information, and the places and conditions of their location are determined based on the results of modeling the objects of protection. The increase in the number and types of threats to information security, accompanying the increasing importance of information in the life of society and people, is a trend that cannot be ignored. An example of this is the consequences of the widespread introduction of digital communication systems (DCS). Along with the great advantages for users of this relatively new type of communication for Russia compared to traditional wired telephone communications, where a very serious problem has arisen in ensuring the confidentiality of conversations and data transmission.
The main provisions of information security are the study and analysis of the causes of violations of the security of information systems. Development of effective security models that are adequate to the current level of development of software and hardware, as well as the capabilities of attackers and destructive software. Creation of methods and means for
10
the correct implementation of security models in existing digital data centers, with the possibility of flexible security management depending on the requirements put forward, acceptable risk and resource consumption. The need to develop tools for analyzing the security of information systems using test actions.
As a result of mastering the textbook material, according to the educational standard, students must know the methods of protecting digital systems, be able to use modern mathematical apparatus to solve the problem of protecting information in digital systems, and master methods for optimizing the protection of designed digital systems.
In preparing this textbook, materials from various sources given in the bibliography were used.