Добавил:
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:

Information protection in digital communication systems. Textbook

.pdf
Скачиваний:
0
Добавлен:
07.09.2026
Размер:
2 Мб
Скачать
171
3) prevention of unauthorized actions to destroy, modify, distort, copy,
block information;
4) protection of constitutional rights to maintain personal privacy and
confidentiality of personal information;
5) maintaining state secrets and confidentiality of information.
According to the above Law, control over compliance with information protection requirements, the operation of special information protection means, as well as ensuring organizational measures for the protection of information systems that process information with limited access in non-state structures are entrusted to government bodies. This means that monitoring the state of protection must cover all three components of information with limited access included in government information resources:
• information constituting a state secret;
• confidential information;
• personal data about citizens.
The law defines the rights and obligations of subjects in the field of information protection. In particular, it obliges the owner of the information system to ensure the necessary level of protection of confidential information and to notify the owners of information resources about violations of the information protection regime. The risk associated with the use of uncertified information systems and means of providing and protecting them rests with the owner (holder) of the systems and means. The risk associated with the use of information obtained from such systems lies with the consumer of the information. Clause 4 establishes the right of the owner of documents or information systems to contact organizations that certify the means of protecting such systems to analyze the sufficiency of measures to protect their resources and systems and receive advice.
A separate article of the law is devoted to the protection of the rights of subjects in the field of information processes and informatization. According to it, the protection of the rights of subjects in this area is carried out by the court, the arbitration court and arbitration courts, which can be created on a permanent or temporary basis.
172
6.1.2. Federal Law “On Licensing of Certain Types of Activities”
Law “On licensing of certain types of activities” dated May 4, 2011
No. 99-FZ. Let’s start with basic definitions.
Article 12 of the Law establishes a list of types of activities for which licenses are required. Consider the following types:
1) distribution of encryption (cryptographic) tools;
2) maintenance of encryption (cryptographic) tools;
3) provision of services in the field of information encryption;
4) development and production of encryption (cryptographic) means protected using encryption (cryptographic) means of information systems, telecommunication systems;
5) issuance of certificates of keys for electronic digital signatures, registration of owners of electronic digital signatures, provision of services related to the use of electronic digital signatures and confirmation of the authenticity of electronic digital signatures;
6) identification of electronic devices intended for secretly obtaining information in premises and technical means (except for the case if the specified activity is carried out to meet the own needs of a legal entity or individual entrepreneur);
7) development and (or) production of means of protecting confidential information;
8) technical protection of confidential information;
9) development, production, sale and acquisition for the purpose of sale of special technical means intended for secretly obtaining information by individual entrepreneurs and legal entities engaged in business activities.
This Law does not apply to the following types of activities:
• activities related to the protection of state secrets;
• activities in the field of communications;
• educational activities.
The main licensing authorities in the field of information protection are the FSB and FSTEC, which is in charge of everything related to cryptography, and the State Technical Commission, which licenses
173
activities for the protection of confidential information. In addition, the import and export of cryptographic information protection means (encryption equipment) and regulatory and technical documentation for it can be carried out exclusively on the basis of a license from the Ministry of Foreign Economic Relations of the Russian Federation, issued on the basis of a decision of the Federal Service for Technical and Export Control. All these issues are regulated by relevant decrees of the President and resolutions of the Government of the Russian Federation.
6.1.3. Set of guiding documents of the State Technical
Commission under the President of the Russian Federation
In 1992, the State Technical Commission under the President of the
Russian Federation published five “Guiding Documents” devoted to the
problem of protection from unauthorized access (UNA) to information processed by computer technology (CT) and automated systems (AS) [2]:
• “Guidance document. The concept of protecting computer equipment
(CE) and automated systems (AS) from unauthorized access (UNA) to information (State Technical Commission of Russia, March 30, 1992);
“Guidance document. Computer facilities. Protection against unauthorized access to information. Indicators of security from unauthorized access to information(State Technical Commission of Russia, March 30, 1992);
“Guidance document. Automated systems. Protection against unauthorized access to information. Classification of automated systems and requirements for information protection (State Technical Commission of Russia, March 30, 1992);
“Guidance document. Temporary regulations on organizing the development, production and operation of software and hardware for protecting information from unauthorized access in automated systems and computer
equipment” (State Technical Commission of Russia, March 30, 1992);
• “Guidance document. Protection against unauthorized access to
information. Terms and definitions (State Technical Commission of Russia, March 30, 1992).
174
In 1997, another one was added to these documents [9]:
“Guidance document. Computer facilities. Firewalls. Protection against unauthorized access to information. Indicators of security against unauthorized access to information.”
The concept of protecting computer equipment
and AS from unauthorized access to information
The central element (ideological basis) of the set of governing
documents of the State Technical Commission is the “Guiding Document.
The concept of protecting CE and AS from unauthorized access to information” [9]. This document sets out a system of views and basic principles that form the basis of the problem of protecting information from unauthorized access, which is part of the general problem of information security.
The Concept distinguishes between two concepts corresponding to
two groups of safety criteria:
1) indicators of security of computer equipment;
2) security criteria for automated systems.
The “Concept” provides for the existence of two relatively
independent and distinct directions in the problem of protecting information from unauthorized access. This is the direction associated with CE and the direction associated with AS. The difference between the two directions is generated by the fact that CEs are developed and supplied to the market only as elements from which function-oriented systems are subsequently built, and therefore, without solving applied problems, CEs do not contain user information.
In addition to user information, when creating an AS, such characteristics of the AS that were absent during the development of CE, such as user powers, an intruder model, and information processing technology, appear.
There are various methods of attacking information security: radio engineering, acoustic, software, etc. Among them, unauthorized access is
175
distinguished as access to information that violates the established rules of access control, using standard tools provided by CE or AS. By standard means we mean the totality of software, firmware and hardware of the CE or AS.
Section 3 of “Concept” formulates the basic principles of protection from unauthorized access to information:
3.1. Protection of electronic equipment and AS is based on the provisions and requirements of existing laws, standards and regulatory and methodological documents on protection from unauthorized access to information.
3.2. CE protection is provided by a complex of software and hardware.
3.3. Protection of the AS is ensured by a complex of software and hardware tools and organizational measures that support them.
3.4. AS protection must be ensured at all technological stages of information processing and in all operating modes, including during repair and maintenance work.
3.5. Software and hardware protection measures should not significantly degrade the main functional characteristics of the AS (reliability, performance, ability to change the AS configuration).
3.6. An integral part of the protection work is the assessment of the effectiveness of protective equipment, carried out using a methodology that takes into account the entire set of technical characteristics of the object being assessed, including technical solutions and the practical implementation of protective equipment.
3.7. AS protection should include monitoring the effectiveness of means of protection against unauthorized access. This control can be either periodic or initiated as necessary by the user of the AS or regulatory authorities.
As the main means of protection against unauthorized access to
information, Section 6 of the “Concept” considers the access control system (ACS) of subjects to access objects:
6.1. Ensuring the protection of CE and AS is carried out by:
176
ACS of subjects to access objects;
• providing funds for the ACS.
6.2. The main functions of the ACS are:
implementation of restricting access rules (RAR) of subjects and their processes to data;
implementation of RAR of subjects and their processes to devices for creating hard copies;
• isolation of process programs performed in the interests of the subject
from other subjects;
data flow management to prevent data from being written to inappropriately typed media;
implementation of rules for data exchange between subjects for AS and CE, built on network principles.
6.3. Providing means for RAR perform the following functions:
identification and recognition (authentication) of subjects and maintaining the binding of the subject to the process performed for the subject;
registration of the actions of the subject and its process; providing opportunities to exclude and include new subjects and access objects, as well as changing the powers of subjects;
reaction to unauthorized access attempts, for example, alarms, blocking, recovery after unauthorized access;
• testing;
cleaning RAM and work areas on magnetic media after the user has
finished working with protected data;
accounting of output printed and graphic forms and hard copies in the AS;
• monitoring the integrity of the software and information part of both
the RAR and the means that support it.
6.4. Resources associated with both the RAR and the means that support it are included in access objects.
177
6.5. Methods for implementing the RAR depend on the specific features of the CE and AS. The following protection methods and any combinations thereof can be used:
distributed RAR and RAR localized in the software and hardware complex (protection core);
RAR within the operating system, DBMS or application programs;
RAR in means of implementing network interactions or at the
application level;
use of cryptographic transformations or direct access control methods;
• software and (or) technical implementation of the RAR.
In general, the development of the Guidelines of the State Technical Commission of Russia was a consequence of the rapidly developing process of introducing new information technologies. The documents quickly filled the legal vacuum in the field of information security standards in the country and at a certain stage made it possible to solve the urgent problem of ensuring information security. Since the development of documents of this kind for Russia represents a fairly new area of activity, they can be considered as the first stage in the formation of domestic standards in the field of information security.
The development of these documents was greatly influenced by the
“Orange Book” of the US Department of Defense, which was expressed in
its focus on systems for military and special applications, in the use of a single universal scale of security degree and in ignoring the issues of value and lifetime of information.
The disadvantages of the documents, in addition to the lack of requirements for protection against threats to operability, include a focus only on counteracting unauthorized access and the lack of requirements for the adequacy of the implementation of the security policy. Actually,
“security policy” is interpreted in these documents solely as maintaining a
178
regime of secrecy and the absence of unauthorized access. Because of this, protection means are focused on countering only external threats, and no requirements are imposed on the structure of the system itself and its functioning.
From the point of view of the developers of these governing documents, the main and almost the only task of security tools is to provide protection against unauthorized access to information. While they still pay some attention to the means of monitoring and ensuring the integrity of information, maintaining the operability of information processing systems (as a measure of protection against threats to operability) is not mentioned at all. A certain bias towards maintaining secrecy is explained by the fact that these documents were developed with the expectation of use in existing information systems of the Ministry of Defense and intelligence services of Russia, as well as the insufficiently high level of technology of these systems.
Documents of the State Technical Commission of Russia
on the model of the violator in the AS
The model of the intruder is defined in Section 4 of the main Guiding
Document of the State Technical Commission of Russia “Concept for the
protection of computer equipment and automated systems from unauthorized access to information” [2].
This document considers a violator to be an entity that has access to work with standard AS and CE equipment as part of the AS.
Violators are classified according to the level of capabilities provided to them by standard AS and CE equipment. There are four levels of these capabilities. The classification is hierarchical, i.e., each subsequent level includes the functionality of the previous one.
The first level determines the lowest level of dialogue capabilities in the AS launching tasks (programs) from a fixed set that implement pre­defined information processing functions.
179
The second level is determined by the ability to create and launch your own programs with new information processing functions.
The third level is determined by the ability to control the functioning of the AS, i.e., the impact on the basic software of the system and on the composition and configuration of its equipment.
The fourth level is determined by the entire scope of capabilities of persons carrying out the design, implementation and repair of AS technical equipment, up to the inclusion of their own technical means with new information processing functions in the CE.
It is emphasized that at his level the violator is a highly qualified specialist, knows everything about the AS and, in particular, about the system and its means of protection.
Security classification of CE.
AS protection classification
Guiding documents of the State Technical Commission of Russia “Guiding document. Computer facilities. Protection against unauthorized access to information. Indicators of security from unauthorized access to information [2] and Guidance document. Automated systems. Protection against unauthorized access to information. Classification of automated
systems and requirements for information protection” [2] determine the
main security indicators by class of computer equipment (Table 6.1) and requirements for security classes of automated systems (Table 6.2).
The seventh class is assigned to computer equipment that was subject to requirements for protection from unauthorized access to information, but when assessed, the security of the tool turned out to be below the level of the requirements of the sixth class.
180
Table 6.1
Distribution of security indicators by classes of computer equipment
Indicator name
Security class
6 5 4 3 2 1 Discretionary access control principle
+ + + = + = Mandatory principle of access control
– – + = =
=
Clearing memory
+ + + =
=
Module isolation
– – + = + = Document marking
– – + = =
=
Protection of input and output to distant storage media
– – + = =
=
User to device mapping
– – + = = = Identification and authentication
+ = + = = = Design Guarantees
– + + + + + Registration
– + + + = = User interaction with trusted computing base
– – – + = = Reliable recovery
– – – + = = Integrity of the trusted computing base
– + + + = = Modification control
– – – – + = Distribution control
– – – – + = Architecture guarantees
– – – – – + Testing
+ + + + + = User guide
+ = = = = = Guide to trusted computing base
+ + = + + = Test documentation
+ + + + + = Design (project) documentation
+ + + + +
+
Designations:
“–” — there are no requirements for this class;
“+” — new or additional requirements;
“=” — the requirements coincide with the requirements for CE of the previous
class.