Добавил:
ivanov666
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз:
Предмет:
Файл:Information protection in digital communication systems. Textbook
.pdf
271
A separate feature inherent in high-end systems is the correlation
analysis of information.
The description of controlled objects and the storage of relevant
information is the most important component of active audit tools, giving
them extensibility and customization properties. This component is
primarily subject to technological requirements.
Monitors as organizing shells for managers of active auditing tools
must have two groups of properties:
• ensure protection of the processes that make up the manager from
malicious influences;
• ensure high availability of these processes.
The first group is served by the FPT_SEP (domain separation) family.
The second group of properties can be provided by technical solutions
such as middleware, cluster configurations, etc.
In terms of security, it is advisable to follow the requirements of
FPT_FLS.1 (impossibility of transition to an unsafe state in the event of a
failure or failure), as well as FPT_RCV.2, FPT_RCV.3, FPT_RCV.4
(reliable recovery in automatic mode, without data loss, accurate to the
function security).
The security of monitor interfaces (with other monitors, sensors,
security administrator) can be ensured by the components FPT_ITI.1,
FPT_ITI.2 (detection and correction of modification of exported data),
FPT_ITC.1 (confidentiality of exported data), FPT_ITA.1 (availability of
exported data).
The security administrator’s workplace should provide standard
capabilities for management tools: a graphical interface, the ability to
configure the visualization method and level of detail, and select displayed
events. Specific to active audit tools is the ability to obtain explanations
from analyzers and solvers regarding detected suspicious activity. Such
explanations help to choose an adequate way to respond.
A function package (FP) is a reusable collection of functional
components combined to achieve specific security goals.

272
Protection profiles (PP), corresponding to security classes, are built on
the basis of the basic PP and the corresponding FP combinations. You can
capture profiles for the following types of active auditing tools:
• class 5 — protection of one information service with tracking of a
fixed set of characteristics and threshold analysis (basic PP);
• class 4 — protection of a single-host configuration with an arbitrary
set of information services, monitoring of network traffic, system and
application events, threshold and simple signature analysis in real time;
• class 3 — protection of a local network segment from multi-stage
attacks while maintaining the remaining assumptions of class 4;
• class 2 — protection of an arbitrary configuration with identification
of atypical behavior while maintaining the remaining assumptions of class 3;
• class 1 — imposition of all requirements with the ability to ensure a
given ratio between errors of the first and second kind.
7.2. METHODS AND TOOLS OF AUDITING SECURITY
OF INFORMATION SYSTEMS
7.2.1. Basic concepts and definitions
Active audit and its place among other security services
The formula “protect, detect, respond” is classic. Only a layered,
active defense containing a variety of elements gives a chance to
successfully repel threats.
The purpose of active auditing is to detect and respond. Suspicious
activity of IS components is subject to detection — from users (internal and
external) to software systems and hardware devices.
Suspicious activity can be divided into:
• malicious;
• abnormal (atypical).
Malicious activity is either an attack aimed at gaining unauthorized
privileges, or actions performed under existing privileges (possibly obtained
illegally) but violating security policy. Let’s call the latter abuse of power.

273
Atypical activity may not directly violate security policy, but, as a rule,
it is a consequence of either incorrect (or deliberately modified) operation
of hardware or programs, or the actions of attackers masquerading as
legitimate users.
Active auditing complements traditional security mechanisms such as
identification/authentication and access control. This addition is necessary
for two reasons. Firstly, existing access control tools are not capable of
implementing all security policy requirements if the latter are more complex
than allowing/prohibiting atomic operations with resources. A developed
security policy can impose restrictions on the total amount of information
read, deny access to resource B if there was previously access to resource
A, etc. Secondly, the security measures themselves have errors and
weaknesses, therefore, in addition to building fences, we have to take care
of catching those who were able to climb over these fences.
Developed active audit systems carry a double load, forming both the
first and last lines of defense (Fig. 7.2). The first line is designed to detect
attacks and promptly stop them. At the last stage, symptoms of current or
previously occurring security policy violations are identified, and measures
are taken to suppress violations and minimize damage.
At both the first and last stages, in addition to active auditing, there are
other security services. The first line includes security scanners, which help
identify and eliminate security weaknesses. As a final step, integrity
monitoring can be used to detect symptoms of disruption. Sometimes they
are included in the repertoire of active audit systems; we, however, will not
do this, considering integrity control to be a separate service.
There are other connections between security services. Thus, active
auditing can rely on traditional logging mechanisms. In turn, after
identifying a violation, it is often necessary to review previously
accumulated registration information, assess the damage, understand why
the violation became possible, and plan measures to prevent a recurrence of
the incident. At the same time, a reliable restoration of the original
configuration is carried out, that is, not changed by the intruder.

274
Нарушения, последствия которых не ликвидированы,
с возможностью повторения в будущем
Злоумышленник
Атаки
Система выявления и
пресечения атак
Система выявления и
устранения слабостей
Невыявленные атаки
Идентификация и
Аутентификация
Разграничения
доступа
Успешные атаки
Выявление любой
вредной активности
Контроль
целостности
Нарушения, оставшиеся невыявленными
Пресечение
нарушений
Оценка ущерба
Восстановление
Меры по недопущению
повторения нарушений
Рабочая станция
Защитные рубежи,
на которых
рассполагаются
компоненты
систем активного
аудита
Fig. 7.2. Protective lines monitored by active audit systems
Types of audit. Types of audit can be classified by means, namely:
• active audit;
• authorized audit.
Active audit is a check directly of a computer information network
through software products. Active audit allows you to constantly check the
internal network of an enterprise.
An authorized audit is a check of the security of an enterprise’s
information assets at all levels of protection (legislative, administrative,
procedural and software). Such verification is carried out by specially
accredited audit services.
The impact of a security audit on the development of a company
Most of those responsible for ensuring information security asked the
question: “How to assess the level of security of the corporate information
system of our enterprise in order to manage it as a whole and determine the
prospects for its development?”

275
The pace of development of modern information technologies is
significantly faster than the pace of development of the advisory and
regulatory framework of governing documents operating in Russia.
Therefore, the question “how to assess the security level of a corporate
information system” necessarily entails the following: in accordance with
what criteria to assess the effectiveness of protection, how to assess and
reassess the information risks of an enterprise? As a result, in addition to the
requirements, recommendations and guidance documents of the State
Technical Commission of Russia and FAPSI, it is necessary to adapt to our
conditions and apply methods of international standards (ISO 17799, 9001,
15408, BSI, etc.), as well as use methods of quantitative risk analysis in
conjunction with assessments economic efficiency of investments in
ensuring the security and protection of information.
Such work methods for analyzing information security risks,
designing and maintaining security systems should allow:
• make a quantitative assessment of the current level of security, set
acceptable levels of risks, develop an action plan to ensure the required level
of security at the organizational, managerial, technological and technical
levels using modern methods and tools;
• calculate and economically justify to management or shareholders
the amount of necessary investments in security based on risk analysis
technologies, correlate security costs with potential damage and the
likelihood of its occurrence;
• identify and prioritize blocking the most dangerous vulnerabilities
before launching attacks on vulnerable resources;
• determine functional relationships and areas of responsibility in the
interaction of departments and persons to ensure the information security of
the enterprise, create the necessary package of organizational and
administrative documentation;
• develop and coordinate with the organization’s services and
supervisory authorities a project for the implementation of the necessary
security systems, taking into account the current level and trends in the
development of information technology;

276
• ensure the maintenance of the implemented protection complex in
accordance with the changing operating conditions of the organization,
regular modifications of organizational and administrative documentation,
modification of technological processes and modernization of technical
means of protection.
New opportunities for company development. The implementation of
the above activities opens up new broad opportunities for officials at various
levels:
1) allows managers of organizations and enterprises to ensure the
formation of a unified policy and concept of enterprise security; calculate,
agree on and justify the necessary costs for protecting the enterprise;
objectively and independently assess the current level of information
security of the enterprise; ensure the required level of safety and generally
increase the economic efficiency of the enterprise; effectively create and use
security profiles for a specific enterprise based on repeatedly tested and
adapted qualitative and quantitative methods for assessing the information
security of enterprises;
2) heads of automation and information security services of the
enterprise — to receive a prompt and objective qualitative and quantitative
assessment of the state of information security of the enterprise at all main
levels of consideration of security issues: organizational, managerial,
technological and technical; develop and justify the necessary
organizational measures (composition and structure of the information
security service, regulations on trade secrets, a package of job descriptions
and instructions for action in emergency situations); helps to draw up an
economic justification for the necessary investments in information
protection, to reasonably select certain hardware and software means of
information protection within the framework of a unified security concept
in accordance with the requirements of the orders and guidance documents
of the State Technical Commission of Russia, FAPSI, as well as
international standards ISO 17799, 9001, 15408, BSI; adapt and use in their
work the proposed quantitative indicators for assessing information

277
security, methods for assessing and managing security with reference to the
economic component of the enterprise’s efficiency;
3) system, network administrators and enterprise security
administrators — to objectively assess the security of all the main
components and services of the enterprise’s corporate information system,
the technical condition of hardware and software information security tools
(firewalls, routers, hosts, servers, corporate databases and applications);
successfully apply in practice the recommendations obtained during the
analytical study to neutralize and localize identified vulnerabilities at the
hardware and software level;
4) employees and workers of enterprises and organizations — to
determine the main functional relationships and, most importantly, areas of
responsibility, including financial, for the proper use of information
resources and the state of the enterprise’s security policy.
7.2.2. Main stages of the audit
A comprehensive information security audit includes the following
types of work:
1) inspection of the facility — construction of an information model
of the customer’s AS;
2) inventory of resources — ranking the company’s resources by
importance;
3) building a private threat model — classifying threats according to
the degree of danger and likelihood;
4) building a model of the intruder;
5) assessment of potential damage from a security breach — risk
assessment using the three-factor analysis technique;
6) assessment of the existing security system for compliance with the
requirements of security standards: departmental, state, international;
7) identification of vulnerabilities and channels of information
leakage;

278
8) development and evaluation of proposals for the use of
countermeasures;
9) design of a set of protective equipment;
10) development of organizational measures — a package of
organizational and administrative documentation;
11) assessment of residual risks.
Practical steps for an authorized security audit
How to implement the above possibilities in practice? According to
experts, this becomes possible during the next practical steps of a security
audit.
1. Comprehensive analysis of the enterprise’s IS and IS subsystem at
the methodological, organizational, managerial, technological and technical
levels. Risk analysis.
1.1. Research and assessment of the information security state of the
corporate information system and the enterprise information security
subsystem.
• Comprehensive assessment of compliance of the standard
requirements of the RD State Technical Commission of the Russian
Federation with the enterprise information security system.
• Comprehensive assessment of compliance of standard requirements
of international ISO standards with the enterprise information security
system.
• Comprehensive assessment of compliance of the customer’s special
requirements with the enterprise information security system.
1.2. Work based on risk analysis.
• Risk analysis. Level of risk management based on qualitative risk
assessments.
• Risk analysis. Level of risk management based on quantitative risk
assessments.
1.3. Instrumental research.

279
1.3.1. Instrumental examination of elements of the infrastructure of a
computer network and corporate information system for the presence of
vulnerabilities.
1.3.2. Instrumental study of the security of enterprise access points on
the Internet.
1.4. Analysis of the enterprise’s document flow.
2. Development of comprehensive recommendations on
methodological, organizational, managerial, technological, general
technical and hardware and software support for the enterprise information
security regime.
2.1. Development of a concept for ensuring enterprise information
security.
2.2. Development of a corporate policy for ensuring enterprise
information security at the organizational, managerial, legal, technological
and technical levels.
2.3. Development of a protection plan for the customer’s enterprise.
2.4. Additional work on the analysis and creation of methodological,
organizational, managerial, technological, infrastructural and technical
support for the information security regime of the customer’s enterprise.
3. Organizational and technological analysis of enterprise IS.
3.1. Assessment of the organizational and managerial level of security.
• Assessment of compliance with the standard requirements of the
governing documents of the Russian Federation for the enterprise
information security system in the field of organizational and technological
standards.
• Analysis of the document flow of an enterprise in the “confidential”
category for compliance with the requirements of the information security
concept, the provision on trade secrets, and other internal requirements of
the enterprise to ensure the confidentiality of information.
• Additional work on research and assessment of the information
security of the facility.

280
3.2. Development of recommendations for organizational, managerial,
technological, and general technical support of the enterprise’s information
security regime.
• Development of elements of a concept for ensuring enterprise
information security.
• Development of elements of corporate policy for ensuring enterprise
information security at the organizational, managerial, legal and
technological levels.
4. Expertise of solutions and projects.
• Examination of automation solutions and projects for compliance
with information security requirements using the expert-documentary
method.
• Examination of information security subsystem projects for
compliance with security requirements using the expert-documentary
method.
5. Work on analyzing document flow and supplying standard sets of
organizational and administrative documentation.
• Analysis of the document flow of an enterprise in the “confidential”
category for compliance with the requirements of the information security
concept, the provision on trade secrets, and other internal requirements of
the enterprise to ensure the confidentiality of information.
• Supply of a set of standard organizational and administrative
documentation in accordance with the recommendations of the enterprise’s
corporate information security policy at the organizational, managerial and
legal levels.
6. Work that supports the practical implementation of the protection
plan.
• Development of a technical project for the modernization of CIS
security equipment installed at the customer, based on the results of a
comprehensive analytical study of the corporate network.
• Development of a decision support system at the customer’s
enterprise to ensure enterprise information security based on CASE
systems, etc.
• Preparing the enterprise for certification.
Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]
