Добавил:
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:

Information protection in digital communication systems. Textbook

.pdf
Скачиваний:
0
Добавлен:
07.09.2026
Размер:
2 Мб
Скачать
271
A separate feature inherent in high-end systems is the correlation analysis of information.
The description of controlled objects and the storage of relevant information is the most important component of active audit tools, giving them extensibility and customization properties. This component is primarily subject to technological requirements.
Monitors as organizing shells for managers of active auditing tools must have two groups of properties:
ensure protection of the processes that make up the manager from
malicious influences;
• ensure high availability of these processes.
The first group is served by the FPT_SEP (domain separation) family.
The second group of properties can be provided by technical solutions such as middleware, cluster configurations, etc.
In terms of security, it is advisable to follow the requirements of FPT_FLS.1 (impossibility of transition to an unsafe state in the event of a failure or failure), as well as FPT_RCV.2, FPT_RCV.3, FPT_RCV.4 (reliable recovery in automatic mode, without data loss, accurate to the function security).
The security of monitor interfaces (with other monitors, sensors, security administrator) can be ensured by the components FPT_ITI.1, FPT_ITI.2 (detection and correction of modification of exported data), FPT_ITC.1 (confidentiality of exported data), FPT_ITA.1 (availability of exported data).
The security administrators workplace should provide standard capabilities for management tools: a graphical interface, the ability to configure the visualization method and level of detail, and select displayed events. Specific to active audit tools is the ability to obtain explanations from analyzers and solvers regarding detected suspicious activity. Such explanations help to choose an adequate way to respond.
A function package (FP) is a reusable collection of functional components combined to achieve specific security goals.
272
Protection profiles (PP), corresponding to security classes, are built on the basis of the basic PP and the corresponding FP combinations. You can capture profiles for the following types of active auditing tools:
class 5 protection of one information service with tracking of a
fixed set of characteristics and threshold analysis (basic PP);
class 4 protection of a single-host configuration with an arbitrary set of information services, monitoring of network traffic, system and application events, threshold and simple signature analysis in real time;
class 3 protection of a local network segment from multi-stage attacks while maintaining the remaining assumptions of class 4;
class 2 protection of an arbitrary configuration with identification of atypical behavior while maintaining the remaining assumptions of class 3;
• class 1 — imposition of all requirements with the ability to ensure a given ratio between errors of the first and second kind.
7.2. METHODS AND TOOLS OF AUDITING SECURITY OF INFORMATION SYSTEMS
7.2.1. Basic concepts and definitions
Active audit and its place among other security services
The formula “protect, detect, respond” is classic. Only a layered,
active defense containing a variety of elements gives a chance to successfully repel threats.
The purpose of active auditing is to detect and respond. Suspicious activity of IS components is subject to detection from users (internal and external) to software systems and hardware devices.
Suspicious activity can be divided into:
• malicious;
• abnormal (atypical).
Malicious activity is either an attack aimed at gaining unauthorized privileges, or actions performed under existing privileges (possibly obtained illegally) but violating security policy. Lets call the latter abuse of power.
273
Atypical activity may not directly violate security policy, but, as a rule, it is a consequence of either incorrect (or deliberately modified) operation of hardware or programs, or the actions of attackers masquerading as legitimate users.
Active auditing complements traditional security mechanisms such as identification/authentication and access control. This addition is necessary for two reasons. Firstly, existing access control tools are not capable of implementing all security policy requirements if the latter are more complex than allowing/prohibiting atomic operations with resources. A developed security policy can impose restrictions on the total amount of information read, deny access to resource B if there was previously access to resource A, etc. Secondly, the security measures themselves have errors and weaknesses, therefore, in addition to building fences, we have to take care of catching those who were able to climb over these fences.
Developed active audit systems carry a double load, forming both the first and last lines of defense (Fig. 7.2). The first line is designed to detect attacks and promptly stop them. At the last stage, symptoms of current or previously occurring security policy violations are identified, and measures are taken to suppress violations and minimize damage.
At both the first and last stages, in addition to active auditing, there are other security services. The first line includes security scanners, which help identify and eliminate security weaknesses. As a final step, integrity monitoring can be used to detect symptoms of disruption. Sometimes they are included in the repertoire of active audit systems; we, however, will not do this, considering integrity control to be a separate service.
There are other connections between security services. Thus, active auditing can rely on traditional logging mechanisms. In turn, after identifying a violation, it is often necessary to review previously accumulated registration information, assess the damage, understand why the violation became possible, and plan measures to prevent a recurrence of the incident. At the same time, a reliable restoration of the original configuration is carried out, that is, not changed by the intruder.
274
Нарушения, последствия которых не ликвидированы,
с возможностью повторения в будущем
Злоумышленник
Атаки
Система выявления и
пресечения атак
Система выявления и
устранения слабостей
Невыявленные атаки
Идентификация и
Аутентификация
Разграничения
доступа
Успешные атаки
Выявление любой
вредной активности
Контроль
целостности
Нарушения, оставшиеся невыявленными
Пресечение
нарушений
Оценка ущерба
Восстановление
Меры по недопущению
повторения нарушений
Рабочая станция
Защитные рубежи,
на которых
рассполагаются
компоненты
систем активного
аудита
Fig. 7.2. Protective lines monitored by active audit systems
Types of audit. Types of audit can be classified by means, namely:
• active audit;
• authorized audit.
Active audit is a check directly of a computer information network through software products. Active audit allows you to constantly check the internal network of an enterprise.
An authorized audit is a check of the security of an enterprise’s
information assets at all levels of protection (legislative, administrative, procedural and software). Such verification is carried out by specially accredited audit services.
The impact of a security audit on the development of a company
Most of those responsible for ensuring information security asked the
question: “How to assess the level of security of the corporate information
system of our enterprise in order to manage it as a whole and determine the prospects for its development?”
275
The pace of development of modern information technologies is significantly faster than the pace of development of the advisory and regulatory framework of governing documents operating in Russia.
Therefore, the question “how to assess the security level of a corporate
information system” necessarily entails the following: in accordance with
what criteria to assess the effectiveness of protection, how to assess and reassess the information risks of an enterprise? As a result, in addition to the requirements, recommendations and guidance documents of the State Technical Commission of Russia and FAPSI, it is necessary to adapt to our conditions and apply methods of international standards (ISO 17799, 9001, 15408, BSI, etc.), as well as use methods of quantitative risk analysis in conjunction with assessments economic efficiency of investments in ensuring the security and protection of information.
Such work methods for analyzing information security risks, designing and maintaining security systems should allow:
make a quantitative assessment of the current level of security, set acceptable levels of risks, develop an action plan to ensure the required level of security at the organizational, managerial, technological and technical levels using modern methods and tools;
calculate and economically justify to management or shareholders the amount of necessary investments in security based on risk analysis technologies, correlate security costs with potential damage and the likelihood of its occurrence;
identify and prioritize blocking the most dangerous vulnerabilities before launching attacks on vulnerable resources;
determine functional relationships and areas of responsibility in the interaction of departments and persons to ensure the information security of the enterprise, create the necessary package of organizational and administrative documentation;
develop and coordinate with the organization’s services and supervisory authorities a project for the implementation of the necessary security systems, taking into account the current level and trends in the development of information technology;
276
ensure the maintenance of the implemented protection complex in accordance with the changing operating conditions of the organization, regular modifications of organizational and administrative documentation, modification of technological processes and modernization of technical means of protection.
New opportunities for company development. The implementation of the above activities opens up new broad opportunities for officials at various levels:
1) allows managers of organizations and enterprises to ensure the formation of a unified policy and concept of enterprise security; calculate, agree on and justify the necessary costs for protecting the enterprise; objectively and independently assess the current level of information security of the enterprise; ensure the required level of safety and generally increase the economic efficiency of the enterprise; effectively create and use security profiles for a specific enterprise based on repeatedly tested and adapted qualitative and quantitative methods for assessing the information security of enterprises;
2) heads of automation and information security services of the enterprise to receive a prompt and objective qualitative and quantitative assessment of the state of information security of the enterprise at all main levels of consideration of security issues: organizational, managerial, technological and technical; develop and justify the necessary organizational measures (composition and structure of the information security service, regulations on trade secrets, a package of job descriptions and instructions for action in emergency situations); helps to draw up an economic justification for the necessary investments in information protection, to reasonably select certain hardware and software means of information protection within the framework of a unified security concept in accordance with the requirements of the orders and guidance documents of the State Technical Commission of Russia, FAPSI, as well as international standards ISO 17799, 9001, 15408, BSI; adapt and use in their work the proposed quantitative indicators for assessing information
277
security, methods for assessing and managing security with reference to the economic component of the enterprise’s efficiency;
3) system, network administrators and enterprise security
administrators to objectively assess the security of all the main
components and services of the enterprise’s corporate information system,
the technical condition of hardware and software information security tools (firewalls, routers, hosts, servers, corporate databases and applications); successfully apply in practice the recommendations obtained during the analytical study to neutralize and localize identified vulnerabilities at the hardware and software level;
4) employees and workers of enterprises and organizations to
determine the main functional relationships and, most importantly, areas of responsibility, including financial, for the proper use of information resources and the state of the enterprise’s security policy.
7.2.2. Main stages of the audit
A comprehensive information security audit includes the following
types of work:
1) inspection of the facility construction of an information model of the customer’s AS;
2) inventory of resources ranking the companys resources by importance;
3) building a private threat model classifying threats according to the degree of danger and likelihood;
4) building a model of the intruder;
5) assessment of potential damage from a security breach risk assessment using the three-factor analysis technique;
6) assessment of the existing security system for compliance with the requirements of security standards: departmental, state, international;
7) identification of vulnerabilities and channels of information leakage;
278
8) development and evaluation of proposals for the use of countermeasures;
9) design of a set of protective equipment;
10) development of organizational measures a package of organizational and administrative documentation;
11) assessment of residual risks.
Practical steps for an authorized security audit
How to implement the above possibilities in practice? According to experts, this becomes possible during the next practical steps of a security audit.
1. Comprehensive analysis of the enterprises IS and IS subsystem at the methodological, organizational, managerial, technological and technical levels. Risk analysis.
1.1. Research and assessment of the information security state of the corporate information system and the enterprise information security subsystem.
Comprehensive assessment of compliance of the standard requirements of the RD State Technical Commission of the Russian Federation with the enterprise information security system.
Comprehensive assessment of compliance of standard requirements of international ISO standards with the enterprise information security system.
Comprehensive assessment of compliance of the customer’s special requirements with the enterprise information security system.
1.2. Work based on risk analysis.
Risk analysis. Level of risk management based on qualitative risk assessments.
Risk analysis. Level of risk management based on quantitative risk assessments.
1.3. Instrumental research.
279
1.3.1. Instrumental examination of elements of the infrastructure of a computer network and corporate information system for the presence of vulnerabilities.
1.3.2. Instrumental study of the security of enterprise access points on the Internet.
1.4. Analysis of the enterprises document flow.
2. Development of comprehensive recommendations on methodological, organizational, managerial, technological, general technical and hardware and software support for the enterprise information security regime.
2.1. Development of a concept for ensuring enterprise information security.
2.2. Development of a corporate policy for ensuring enterprise information security at the organizational, managerial, legal, technological and technical levels.
2.3. Development of a protection plan for the customer’s enterprise.
2.4. Additional work on the analysis and creation of methodological, organizational, managerial, technological, infrastructural and technical support for the information security regime of the customer’s enterprise.
3. Organizational and technological analysis of enterprise IS.
3.1. Assessment of the organizational and managerial level of security.
Assessment of compliance with the standard requirements of the governing documents of the Russian Federation for the enterprise information security system in the field of organizational and technological standards.
Analysis of the document flow of an enterprise in the “confidential” category for compliance with the requirements of the information security concept, the provision on trade secrets, and other internal requirements of the enterprise to ensure the confidentiality of information.
Additional work on research and assessment of the information security of the facility.
280
3.2. Development of recommendations for organizational, managerial,
technological, and general technical support of the enterprise’s information
security regime.
Development of elements of a concept for ensuring enterprise information security.
Development of elements of corporate policy for ensuring enterprise information security at the organizational, managerial, legal and technological levels.
4. Expertise of solutions and projects.
Examination of automation solutions and projects for compliance with information security requirements using the expert-documentary method.
Examination of information security subsystem projects for compliance with security requirements using the expert-documentary method.
5. Work on analyzing document flow and supplying standard sets of organizational and administrative documentation.
Analysis of the document flow of an enterprise in the “confidential” category for compliance with the requirements of the information security concept, the provision on trade secrets, and other internal requirements of the enterprise to ensure the confidentiality of information.
Supply of a set of standard organizational and administrative documentation in accordance with the recommendations of the enterprise’s
corporate information security policy at the organizational, managerial and legal levels.
6. Work that supports the practical implementation of the protection plan.
Development of a technical project for the modernization of CIS security equipment installed at the customer, based on the results of a comprehensive analytical study of the corporate network.
Development of a decision support system at the customer’s enterprise to ensure enterprise information security based on CASE systems, etc.
• Preparing the enterprise for certification.