CAPP-Compliant Security Event Audit System for Mac OS X and FreeBSD
|
|
|
- Noel Grant
- 10 years ago
- Views:
Transcription
1 CAPP-Compliant Security Event Audit System for Mac OS X and FreeBSD Robert N. M. Watson Security Research Computer Laboratory University of Cambridge March 23, 2006
2 Introduction Background Common Criteria, CAPP, evaluation What is security event audit? Audit design and implementation considerations Differences between UNIX and Mac OS X FreeBSD port OpenBSM 23 Mar
3 Organizations Apple Computer, Inc. Tight hardware/software integration, single vendo McAfee Research, McAfee, Inc., Computer security research and engineering SAIC Primarily DoD customers, but some commercial Many things, but among them, evaluation lab TrustedBSD Project Trusted operating system extensions for FreeBSD 23 Mar
4 Trusted Operating Systems Notions originated in security research and development during 1950's 1970's Trustworthy and security systems for US military Later, scope expands Two focuses Specific security feature sets Assurance 1980's 1990's Orange book 1990's 2000's NIAP and Common Criteria (CC) 23 Mar
5 Role of Evaluations Security evaluations controversial Does the evaluation address real security needs? Is the goal more paper or a better product? Do we know more after an evaluation? Security evaluations are, however, a reality Cannot sell to US DoD (and others) without evaluation Inclusion of many necessary security features has been driven by evaluation requirements 23 Mar
6 Common Criteria ISO standard and model for security evaluation CC defines vocabulary and processes Protection Profiles define functional requirements Evaluation Assurance Level (EAL) defines assurance target Two widely used protection profiles for operating systems CAPP, LSPP Other protection profiles for other sorts of products 23 Mar
7 NCSC Orange Book-Derived Protection Profiles Derived from Orange Book C2 Common Access Protection Profile (CAPP) Multiple authenticated users Separation of administrative role Discretionary access control Security event auditing Minimal coverage of network concepts Derived from Orange Book B1 Labelled Security Protection Profile (LSPP) CAPP + Mandatory Access Control (MAC) Role-Based Access Control (RBAC) Multi-Level Security (MLS) Enhanced security event auditing Typically shipped with labelled networking 23 Mar
8 Assurance Assurance arguments critical to evaluation Documentation of goals Documentation of assumptions Documentation of system design Argument system implementation matches design Documentation of process Assurance is measured in paper For lower EAL, measurements < 1 yardmetre For higher EAL, measurements > 1 yardmetre 23 Mar
9 Common Criteria Evaluation Five easy steps 1 Select a protection profile, assurance level 2 Write a security target, evaluation evidence 3 Add features implementing missed requirements 4 Write a very large cheque 5 Work with evaluation lab through testing cycle Shortcuts Evaluate to a cut down protection profile (PR) Contract evaluation lab to write your evidence 23 Mar
10 UNIX and CAPP Most commercial UNIX systems meet CAPP requirements with minor configuration tweaks Three common extensions required: Enhanced discretionary access control ACLs Security event audit Authentication and password policy enforcement Of these, audit is the most difficult (expensive) to add to a UNIX system 23 Mar
11 What is Security Event Audit? Log of security-relevant events Secure Reliable Fine-grained Configurable A variety of uses including Post-mortem analysis Intrusion detection Live system monitoring, debugging 23 Mar
12 Common Criteria and Audit CAPP defines functional requirements Audit will provide comprehensive logging of security events defined in CAPP and security target Reliability and robustness requirements key LSPP extends audit to include MAC labelling and decision information 23 Mar
13 CAPP Requirements (excerpt) CAPP Requirements Table CAPP Category Requirement Description FAU_GEN.1 Audit Data Generation The TSF shall be able to generate an audit record of the auditable events listed in column Event of Table 1 (Auditable Events). This includes all auditable events for the basic level of audit, except FIA_UID.1's user identity during failures FAU_GEN.1 Audit Data Generation FAU_GEN.2 User Identity Association FAU_SAR.1 Audit Review FAU_SAR.1 Audit Review FAU_SAR.2 Restricted Audit Review The TSF shall record within each audit record at least the following information: (a) Data and time of the event, type of the event, subject identity, and the outcome (success or failure) of the event; (b) additional information specified in Table 1. The TSF shall be able to associate each auditable event with the identity of the user that caused the event. The TSF shall provide authorized administrators with the capabiity to read all audit information from the audit records. The TSF shall provide the audit records in a manner suitable for the user to interpret the information. The TSF shall prohibit all users read access to the audit records, excet those users that have been granted explicit read-access. 23 Mar
14 Audit Basics Audit records describe individual events Attributable (to an authenticated user) Non-attributable (no authenticated user) Selected (configured to be audited) Most audit events fall into three classes Access control Authentication Security management Audit log files are called trails 23 Mar
15 Audit Log Security Audit must be non-bypassable Right to add records to trail must be controlled Setting and viewing the audit configuration must be controlled Audit review must be controlled, assignable UNIX syslog has none of these properties! 23 Mar
16 Audit Reliability Reliability is key to audit implementation If an event is auditable, selected, and occurs, then it must be audited If an event is auditable, selected, but cannot be audited, it must not occur Ability to fail-stop system for predictable loss Upper bound on loss in the event of unexpected failure (i.e., power loss) UNIX syslog can't do this either 23 Mar
17 Mapping CAPP Audit into UNIX CAPP does not impose a specific OS structure Does require a Trusted Code Base (TCB) UNIX structure is layered Operating system kernel (TCB) Operating system user space (TCB) Other operating system user space (user) All audit events sourced in TCB Authentication events mostly user space Access control events mostly kernel space 23 Mar
18 Auditable Events in UNIX Access control System calls checking for super user privilege System calls with file system access control checks Including path name lookup! Login access control decisions Authentication, Account Management Password changes, successful authentication, failed authentication, user administration Audit related events 23 Mar
19 Mapping CAPP Audit into UNIX Typical design choices Audit event stream managed by kernel Most records generated by system calls Other records submitted by system applications using system call; privilege required UNIX DAC permissions protect audit log Helper daemon manages audit configuration, possibly writes audit stream Process state extended with pre-selection masks and audit user ID 23 Mar
20 Audit and FreeBSD FreeBSD is in every sense, a classic UNIX All UNIX design choices on previous slide apply Will tell you more in a few minutes 23 Mar
21 Audit and Mac OS X Mac OS X is based on a UNIX kernel Most UNIX audit design choices apply Kernel also offers Mach IPC Mac OS X user space relies on extensive IPC UNIX processes cross boundaries with setuid Mac OS X uses IPC to privileged daemons Extend Mach message trailers with audit fields Allows privileged daemons to attribute audit events to current subject 23 Mar
22 Audit and Mac OS X (cont) Mac OS X process tree not traditional UNIX UNIX process tree descends from single parent In Mac OS X, user applications launched by a single privileged process (window server) Modification to approach that assumes all audit properties can be set at login and then inherited Application launch services had to learn about audit 23 Mar
23 Modifications to FreeBSD, Mac OS X Kernels System call entry pre-selects, allocates record System call arguments, return values System call exit commits record Audit record queue implementation Audit event trigger mechanism Conversion from internal record to BSM Audit system calls Mach message trailer audit fields (Mac OS X) 23 Mar
24 Modifications to FreeBSD, Mac OS X User Space Audit library Audit trail viewer, reduction tool /etc/security audit configuration / databases Audit daemon to manage trails, triggers Set audit context at user login Application launch support for audit (Mac OS X) Audit in management tools, daemons 23 Mar
25 Sample Audit Control Flow access() Audit permission argument Audit result, preselect, commit to record queue, wake up worker access() returns login uthread login kthread audit_worker kthread Audit preselect, possibly assign record to thread, possibly wait for queue space Audit pathname argument Dequeue audit record Convert record to BSM Commit to disk 23 Mar
26 BSM APIs and File Formats Sun's Basic Security Module (BSM) de facto industry standard File formats APIs Token-oriented audit trail format (almost TLV) Audit configuration and databases Construct, parse, process audit record streams Manage audit state, pre-selection model Compatibility with many existing libraries and tools for free 23 Mar
27 BSM Audit Record Format Record header 0 or more variable argument tokens... (paths, ports,...) Subject token Return token header,129,1,aue_open_r,0,tue Feb 21 00:12: , msec argument,2,0,flags path,/lib/libc.so.6 attribute,444,root,wheel, , , subject,-1,root,wheel,root,wheel,319,0,0, return,success,6 trailer,129 header,108,1,aue_close,0,tue Feb 21 00:12: , msec argument,2,0x6,fd attribute,444,root,wheel, , , subject,-1,root,wheel,root,wheel,319,0,0, return,success,0 trailer,108 Trailer token 23 Mar
28 Thinking About Audit Reliability Correspondence between auditable events and audit records tricky Audit record production is a queue split over several system components Must bound end-to-end queue size based on available storage resources Must bound end-to-end queue size based on maximum permissible loss "Fail-stop" must commit remaining records gracefully before stopping 23 Mar
29 Audit Queuing User processes Kernel Stable store Perthread queue Audit subsystem queue File system, Buffer cache 23 Mar
30 Audit Selection Potential for audit record volume huge Terabytes/hour on busy, fully audited system Two key points for audit record selection Audit pre-selection to limit audit records created Audit post-selection, or reduction, to eliminate undesired records after creation Mac OS X and FreeBSD support both models Administrator can apply filters to users at login time Administrator can use tools to reduce trails later 23 Mar
31 Audit Configuration: Pre-Selection Over 350 event types Most of them meaningless individually Each event assigned to one or more classes Class masks assigned to users 0:AUE_NULL:indir system call:no 1:AUE_EXIT:exit(2):pc 2:AUE_FORK:fork(2):pc 3:AUE_OPEN:open(2) - attr only:fa 4:AUE_CREAT:creat(2):fc 5:AUE_LINK:link(2):fc 6:AUE_UNLINK:unlink(2):fd 7:AUE_EXEC:exec(2):pc,ex 8:AUE_CHDIR:chdir(2):pc... 0x :no:invalid class 0x :fr:file read 0x :fw:file write 0x :fa:file attribute access 0x :fm:file attribute modify 0x :fc:file create 0x :fd:file delete 0x :cl:file close 0x :pc:process 0x :nt:network... root:lo:no audit:lo:no test:all:no www:fr,nt,ip:no Mar
32 FreeBSD Port FreeBSD Operating System BSD-licensed 4.4BSDlite2 derivative OS Widely used in high-end embedded, networking, ISP, server spaces. One of the source code bases for Mac OS X More classic UNIX operating system Common code base makes it an easy target Currently present in FreeBSD 7.x development tree, will be merged as of 6.2 release 23 Mar
33 Changes Made Porting to FreeBSD Endian-independent implementation Also now important on Mac OS X Discard Mac OS X mach trailer support Add 64-bit token support Also now important on Mac OS X Significant clean-up, debugging, documentation Largely different user space integration Introduce audit pipes 23 Mar
34 Audit Pipes Historically, audit for post-mortem analysis Today, for intrusion detection / monitoring Audit pipes provide live record feed Audit subsystem queue File system, Buffer cache Audit pipe queue(s) process Lossy queue process Discrete audit records Independent streams 23 Mar
35 OpenBSM BSD-licensed BSM library, tools, docs Portable across many platforms Implements Sun BSM with some extensions Foundation for FreeBSD, future Mac OS X use 23 Mar
36 Conclusion Security event auditing is critical to successful security evaluation Some argue audit is a critical security feature Complex reliability requirements Complex security requirements Open source common to FreeBSD, Mac OS X API/file format compatibility with Solaris 23 Mar
FreeBSD Developer Summit TrustedBSD: Audit + priv(9)
FreeBSD Developer Summit TrustedBSD: Audit + priv(9) Robert Watson FreeBSD Project Computer Laboratory University of Cambridge TrustedBSD Audit Quick audit tutorial Adding audit support to new kernel features
Practical Security Event Auditing with FreeBSD
Practical Security Event Auditing with FreeBSD Christian Brüffer [email protected] NYCBSDCon New York City, USA November 14, 2010 Outline 1. What / What for / Why 2. Format 3. Configuration and Operation
Certification Report
Certification Report EAL 4+ Evaluation of Solaris 10 Release 11/06 Trusted Extensions Issued by: Communications Security Establishment Canada Certification Body Canadian Common Criteria Evaluation and
Common Criteria Evaluation Challenges for SELinux. Doc Shankar IBM Linux Technology Center [email protected]
Common Criteria Evaluation Challenges for SELinux Doc Shankar IBM Linux Technology Center [email protected] Agenda Common Criteria Roadmap/Achievements CAPP/LSPP Overview EAL4 Overview Open Sourcing
Access Control Lists in Linux & Windows
Access Control Lists in Linux & Windows Vasudevan Nagendra & Yaohui Chen Categorization: Access Control Mechanisms Discretionary Access Control (DAC): Owner of object specifies who can access object (files/directories)
System Assurance C H A P T E R 12
C H A P T E R 12 System Assurance 169 The aim of system assurance is to verify that a system enforces a desired set of security goals. For example, we would like to know that a new operating system that
Computer Security: Principles and Practice
Computer Security: Principles and Practice Chapter 24 Windows and Windows Vista Security First Edition by William Stallings and Lawrie Brown Lecture slides by Lawrie Brown Windows and Windows Vista Security
NSA Security-Enhanced Linux (SELinux)
NSA Security-Enhanced Linux (SELinux) http://www.nsa.gov/selinux Stephen Smalley [email protected] Information Assurance Research Group National Security Agency Information Assurance Research Group 1
Windows Security. CSE497b - Spring 2007 Introduction Computer and Network Security Professor Jaeger. www.cse.psu.edu/~tjaeger/cse497b-s07/
Windows Security CSE497b - Spring 2007 Introduction Computer and Network Security Professor Jaeger www.cse.psu.edu/~tjaeger/cse497b-s07/ Windows Security 0 to full speed No protection system in early versions
Audit Trail Administration
Audit Trail Administration 0890431-030 August 2003 Copyright 2003 by Concurrent Computer Corporation. All rights reserved. This publication or any part thereof is intended for use with Concurrent Computer
CS 377: Operating Systems. Outline. A review of what you ve learned, and how it applies to a real operating system. Lecture 25 - Linux Case Study
CS 377: Operating Systems Lecture 25 - Linux Case Study Guest Lecturer: Tim Wood Outline Linux History Design Principles System Overview Process Scheduling Memory Management File Systems A review of what
Using an Open Source Framework to Catch the Bad Guy. Norman Mark St. Laurent Senior Solutions Architect, Red Hat 06.28.12
Using an Open Source Framework to Catch the Bad Guy Norman Mark St. Laurent Senior Solutions Architect, Red Hat 06.28.12 Agenda Audit Log Management Infrastructure Establishing Policies and Procedures
Features. The Samhain HIDS. Overview of available features. Rainer Wichmann
Overview of available features November 1, 2011 POSIX (e.g. Linux, *BSD, Solaris 2.x, AIX 5.x, HP-UX 11, and Mac OS X. Windows 2000 / WindowsXP with POSIX emulation (e.g. Cygwin). Please note that this
Information Security Measures and Monitoring System at BARC. - R.S.Mundada Computer Division B.A.R.C., Mumbai-85
Information Security Measures and Monitoring System at BARC - R.S.Mundada Computer Division B.A.R.C., Mumbai-85 Information Security Approach Secure Network Design, Layered approach, with SPF and Application
Secure to the Core: The Next Generation Secure Operating System from CyberGuard
Secure to the Core: The Next Generation Secure Operating System from CyberGuard Paul A. Henry MCP+I, MCSE, CCSA, CCSE, CFSA, CFSO, CISSP, CISM, CISA Senior Vice President CyberGuard Corp A CyberGuard Corporation
Snare System Version 6.3.4 Release Notes
Snare System Version 6.3.4 Release Notes is pleased to announce the release of Snare Server Version 6.3.4. Snare Server Version 6.3.4 New Features The behaviour of the Snare Server reflector has been modified
Security Enhanced Linux and the Path Forward
Security Enhanced Linux and the Path Forward April 2006 Justin Nemmers Engineer, Red Hat Agenda System security in an insecure world Red Hat Enterprise Linux Security Features An overview of Discretionary
Example of Standard API
16 Example of Standard API System Call Implementation Typically, a number associated with each system call System call interface maintains a table indexed according to these numbers The system call interface
Mandatory Access Control
CIS/CSE 643: Computer Security (Syracuse University) MAC: 1 1 Why need MAC DAC: Discretionary Access Control Mandatory Access Control Definition: An individual user can set an access control mechanism
Advanced Systems Security: Retrofitting Commercial Systems
Systems and Internet Infrastructure Security Network and Security Research Center Department of Computer Science and Engineering Pennsylvania State University, University Park PA Advanced Systems Security:
Using Likewise Enterprise to Boost Compliance with Sarbanes-Oxley
Likewise Enterprise Using Likewise Enterprise to Boost Compliance with Sarbanes-Oxley IMPROVE SOX COMPLIANCE WITH CENTRALIZED ACCESS CONTROL AND AUTHENTICATION With Likewise Enterprise, you get one user,
Access Control. ITS335: IT Security. Sirindhorn International Institute of Technology Thammasat University ITS335. Access Control.
ITS335: IT Security Sirindhorn International Institute of Technology Thammasat University Prepared by Steven Gordon on 10 October 2013 its335y13s2l04, Steve/Courses/2013/s2/its335/lectures/access.tex,
National Information Assurance Partnership. Common Criteria Evaluation and Validation Scheme Validation Report
National Information Assurance Partnership Common Criteria Evaluation and Validation Scheme Validation Report TM HP Network Node Management Advanced Edition Software V7.51 with patch PHSS_35278 Report
Snare System Version 6.3.6 Release Notes
Snare System Version 6.3.6 Release Notes is pleased to announce the release of Snare Server Version 6.3.6. Snare Server Version 6.3.6 New Features Added objective and user documentation to the email header,
IronMail Secure Email Gateway Software Version 4.0.0 Security Target April 27, 2006 Document No. CipherTrust E2-IM4.0.0
IronMail Secure Email Gateway Software Version 4.0.0 Security Target April 27, 2006 Document No. CipherTrust E2-IM4.0.0 CipherTrust 4800 North Point Parkway Suite 400 Alpharetta, GA 30022 Phone: 678-969-9399
User's Manual. Intego Remote Management Console User's Manual Page 1
User's Manual Intego Remote Management Console User's Manual Page 1 Intego Remote Management Console for Macintosh 2007 Intego, Inc. All Rights Reserved Intego, Inc. www.intego.com This manual was written
Knowledge Base Articles
Knowledge Base Articles 2005 Jalasoft Corp. All rights reserved. TITLE: How to configure and use the Jalasoft Xian Syslog Server. REVISION: Revision : B001-SLR01 Date : 11/30/05 DESCRIPTION: Jalasoft has
Auditing NFS Events. Efstratios Karatzas [email protected]
Auditing NFS Events Efstratios Karatzas [email protected] FreeBSD Developer Summit Karlsruhe Institute of Technology Karlsruhe, Germany October 8, 2010 Audit's Limitations TrustedBSD's Audit implementation
Monitor Print Popup for Mac. Product Manual. www.monitorbm.com
Monitor Print Popup for Mac Product Manual www.monitorbm.com Monitor Print Popup for Mac Product Manual Copyright 2013 Monitor Business Machines Ltd The software contains proprietary information of Monitor
TEL2821/IS2150: INTRODUCTION TO SECURITY Lab: Operating Systems and Access Control
TEL2821/IS2150: INTRODUCTION TO SECURITY Lab: Operating Systems and Access Control Version 3.4, Last Edited 9/10/2011 Students Name: Date of Experiment: Read the following guidelines before working in
Secure computing: SELinux
Secure computing: SELinux Michael Wikberg Helsinki University of Technology [email protected] Abstract Using mandatory access control greatly increases the security of an operating system. SELinux,
Constructing Trusted Code Base XIV
Constructing Trusted Code Base XIV Certification Aleksy Schubert & Jacek Chrząszcz Today s news (on tvn24bis.pl) (June 6th on BBC) security vulnerability CVE-2014-0224 was discovered by Masashi Kikuchi
How To Fix A Snare Server On A Linux Server On An Ubuntu 4.5.2 (Amd64) (Amd86) (For Ubuntu) (Orchestra) (Uniden) (Powerpoint) (Networking
Snare System Version 6.3.5 Release Notes is pleased to announce the release of Snare Server Version 6.3.5. Snare Server Version 6.3.5 Bug Fixes: The Agent configuration retrieval functionality within the
Computer Security. Evaluation Methodology CIS 5370. Value of Independent Analysis. Evaluating Systems Chapter 21
Computer Security CIS 5370 Evaluating Systems Chapter 21 1 Evaluation Methodology 1. Set of security functionality requirements 2. Set of assurance a requirements e e 3. Methodology to determine if the
The System Monitor Handbook. Chris Schlaeger John Tapsell Chris Schlaeger Tobias Koenig
Chris Schlaeger John Tapsell Chris Schlaeger Tobias Koenig 2 Contents 1 Introduction 6 2 Using System Monitor 7 2.1 Getting started........................................ 7 2.2 Process Table.........................................
How To Test Your Web Site On Wapt On A Pc Or Mac Or Mac (Or Mac) On A Mac Or Ipad Or Ipa (Or Ipa) On Pc Or Ipam (Or Pc Or Pc) On An Ip
Load testing with WAPT: Quick Start Guide This document describes step by step how to create a simple typical test for a web application, execute it and interpret the results. A brief insight is provided
RSA Authentication Manager
McAfee Enterprise Security Manager Data Source Configuration Guide Data Source: RSA Authentication Manager February 26, 2015 RSA Authentication Manager Page 1 of 9 Important Note: The information contained
Red Hat Enterprise Linux 3 (running on specified Dell and Hewlett-Packard hardware) Security Target
Red Hat Enterprise Linux 3 (running on specified Dell and Hewlett-Packard hardware) Security Target Version 1.7 January 2004 Document Control DOCUMENT TITLE Red Hat Enterprise Linux 3 Security Target Version
Nixu SNS Security White Paper May 2007 Version 1.2
1 Nixu SNS Security White Paper May 2007 Version 1.2 Nixu Software Limited Nixu Group 2 Contents 1 Security Design Principles... 3 1.1 Defense in Depth... 4 1.2 Principle of Least Privilege... 4 1.3 Principle
Performance Monitor. Intellicus Web-based Reporting Suite Version 4.5. Enterprise Professional Smart Developer Smart Viewer
Performance Monitor Intellicus Web-based Reporting Suite Version 4.5 Enterprise Professional Smart Developer Smart Viewer Intellicus Technologies [email protected] www.intellicus.com Copyright 2009 Intellicus
Barracuda Networks Web Application Firewall
McAfee Enterprise Security Manager Data Source Configuration Guide Data Source: Barracuda Networks Web Application Firewall January 30, 2015 Barracuda Networks Web Application Firewall Page 1 of 10 Important
CS 392/CS 681 - Computer Security. Module 17 Auditing
CS 392/CS 681 - Computer Security Module 17 Auditing Auditing Audit Independent review and examination of records and activities to assess the adequacy of system controls, to ensure compliance with established
Computer Security DD2395 http://www.csc.kth.se/utbildning/kth/kurser/dd2395/dasakh10/
Computer Security DD2395 http://www.csc.kth.se/utbildning/kth/kurser/dd2395/dasakh10/ Fall 2010 Sonja Buchegger [email protected] Lecture 13, Dec. 6, 2010 Auditing Security Audit an independent review and examination
CRM Migration Manager 3.1.1 for Microsoft Dynamics CRM. User Guide
CRM Migration Manager 3.1.1 for Microsoft Dynamics CRM User Guide Revision D Issued July 2014 Table of Contents About CRM Migration Manager... 4 System Requirements... 5 Operating Systems... 5 Dynamics
Best Practices, Procedures and Methods for Access Control Management. Michael Haythorn
Best Practices, Procedures and Methods for Access Control Management Michael Haythorn July 13, 2013 Table of Contents Abstract... 2 What is Access?... 3 Access Control... 3 Identification... 3 Authentication...
Operating System Protection Profile. Common Criteria Protection Profile BSI-CC-PP-0067 Version 2.0
Common Criteria Protection Profile BSI-CC-PP-0067 Version 2.0 Bundesamt für Sicherheit in der Informationstechnik Postfach 20 03 63 53133 Bonn Tel.: +49 22899 9582-111 E-Mail: [email protected]
IHS USER SECURITY AUDIT
RESOURCE AND PATIENT MANAGEMENT SYSTEM IHS USER SECURITY AUDIT (BUSA) Version 1.0 Office of Information Technology Division of Information Technology Albuquerque, New Mexico Table of Contents 1.0 Release
EMC ApplicationXtender Server
EMC ApplicationXtender Server 6.0 Monitoring Guide P/N 300 008 232 A01 EMC Corporation Corporate Headquarters: Hopkinton, MA 01748 9103 1 508 435 1000 www.emc.com Copyright 1994 2009 EMC Corporation. All
Trusted RUBIX TM. Version 6. Multilevel Security in Trusted RUBIX White Paper. Revision 2 RELATIONAL DATABASE MANAGEMENT SYSTEM TEL +1-202-412-0152
Trusted RUBIX TM Version 6 Multilevel Security in Trusted RUBIX White Paper Revision 2 RELATIONAL DATABASE MANAGEMENT SYSTEM Infosystems Technology, Inc. 4 Professional Dr - Suite 118 Gaithersburg, MD
CIS 551 / TCOM 401 Computer and Network Security
CIS 551 / TCOM 401 Computer and Network Security Spring 2007 Lecture 3 1/18/07 CIS/TCOM 551 1 Announcements Email project groups to Jeff (vaughan2 AT seas.upenn.edu) by Jan. 25 Start your projects early!
Administration Guide. WatchDox Server. Version 4.8.0
Administration Guide WatchDox Server Version 4.8.0 Published: 2015-11-01 SWD-20151101091846278 Contents Introduction... 7 Getting started... 11 Signing in to WatchDox... 11 Signing in with username and
What is Auditing? Auditing. Problems. Uses. Audit System Structure. Logger. Reading: Chapter 24. Logging. Slides by M. Bishop are used.
Reading: Chapter 24 Auditing Slides by M. Bishop are used What is Auditing? Logging» Recording events or statistics to provide information about system use and performance Auditing» Analysis of log records
Part III. Access Control Fundamentals
Part III Access Control Fundamentals Sadeghi, Cubaleska @RUB, 2008-2009 Course Operating System Security Access Control Fundamentals 105 / 148 10 3.1 Authentication and Access Control 11 Examples for DAC
Configuring CQ Security
Configuring CQ Security About Me CQ Architect for Inside Solutions http://inside-solutions.ch CQ Blog: http://cqblog.inside-solutions.ch Customer Projects with Adobe CQ Training Material on Adobe CQ Agenda
IBM AIX 7 for POWER V7.1 Technology level 7100-00-03 with optional IBM Virtual I/O Server V2.2 Security Target with BSI OSPP Compliance.
IBM AIX 7 for POWER V7.1 Technology level 7100-00-03 with optional IBM Virtual I/O Server V2.2 Security Target Version: Status: Last Update: 1.8 Release 2012-08-15 Trademarks IBM and the IBM logo are trademarks
White Paper Levels of Linux Operating System Security
White Paper Levels of Linux Operating System Security Owl Approach to the Hardening of Linux Abstract Cross Domain Solutions produced by Owl Computing Technologies, Inc., running on Security Enhanced (SE)
SELinux. Security Enhanced Linux
SELinux Security Enhanced Linux Introduction and brief overview. Copyright 2005 by Paweł J. Sawicki http://www.pawel-sawicki.com/ Agenda DAC Discretionary Access Control ACL Access Control Lists MAC Mandatory
How to use the VMware Workstation / Player to create an ISaGRAF (Ver. 3.55) development environment?
Author Janice Hong Version 1.0.0 Date Mar. 2014 Page 1/56 How to use the VMware Workstation / Player to create an ISaGRAF (Ver. 3.55) development environment? Application Note The 32-bit operating system
Contents III: Contents II: Contents: Rule Set Based Access Control (RSBAC) 4.2 Model Specifics 5.2 AUTH
Rule Set Based Access Control (RSBAC) Linux Kernel Security Extension Tutorial Amon Ott Contents: 1 Motivation: Why We Need Better Security in the Linux Kernel 2 Overview of RSBAC 3 How
CEN 559 Selected Topics in Computer Engineering. Dr. Mostafa H. Dahshan KSU CCIS [email protected]
CEN 559 Selected Topics in Computer Engineering Dr. Mostafa H. Dahshan KSU CCIS [email protected] Access Control Access Control Which principals have access to which resources files they can read
Low Assurance Security Target for a Cisco VoIP Telephony System
Low Assurance Security Target for a Cisco VoIP Telephony System Security Target Version 1.6 March 14, 2005 Document Control Preparation Action Name Date Prepared by: Rob Hunter of TNO-ITSEF BV on behalf
Load testing with. WAPT Cloud. Quick Start Guide
Load testing with WAPT Cloud Quick Start Guide This document describes step by step how to create a simple typical test for a web application, execute it and interpret the results. 2007-2015 SoftLogica
Introduction. Connection security
SECURITY AND AUDITABILITY WITH SAGE ERP X3 Introduction An ERP contains usually a huge set of data concerning all the activities of a company or a group a company. As some of them are sensitive information
Intrusion Detection using the Linux Audit Framework. Stephen Quinney <[email protected]> School of Informatics University of Edinburgh
Intrusion Detection using the Linux Audit Framework Stephen Quinney School of Informatics University of Edinburgh the only secure computer is one that s unplugged... Two Distinct
A Simple Implementation and Performance Evaluation Extended-Role Based Access Control
A Simple Implementation and Performance Evaluation Extended-Role Based Access Control Wook Shin and Hong Kook Kim Dept. of Information and Communications, Gwangju Institute of Science and Technology, 1
RBAC and HIPAA Security
Chief Executive, HIPAA Academy RBAC and HIPAA Security Uday O. Ali Pabrai, CHSS, SCNA Session Objective Challenges HIPAA Requirements Seven Steps to HIPAA Security Access Control RBAC Information Access
IDENTITIES, ACCESS TOKENS, AND THE ISILON ONEFS USER MAPPING SERVICE
White Paper IDENTITIES, ACCESS TOKENS, AND THE ISILON ONEFS USER MAPPING SERVICE Abstract The OneFS user mapping service combines a user s identities from different directory services into a single access
Linux Kernel Architecture
Linux Kernel Architecture Amir Hossein Payberah [email protected] Contents What is Kernel? Kernel Architecture Overview User Space Kernel Space Kernel Functional Overview File System Process Management
TeamViewer 9 Manual Management Console
TeamViewer 9 Manual Management Console Rev 9.2-07/2014 TeamViewer GmbH Jahnstraße 30 D-73037 Göppingen www.teamviewer.com Table of Contents 1 About the TeamViewer Management Console... 4 1.1 About the
SNAP: Secure Network Access Partnering
SNAP: Secure Network Access Partnering (and Partnering for Secure Network Access ) Dynamic Coalition Formation at its best (sigmund@best). Inherent Security. HA. High-Performance. Server/Storage Virtualization.
Mobile Billing System Security Target
Mobile Billing System Security Target Common Criteria: EAL1 Version 1.2 25 MAY 11 Document management Document identification Document ID Document title Product version IDV_EAL1_ASE IDOTTV Mobile Billing
Virtual Fragmentation Reassembly
Virtual Fragmentation Reassembly Currently, the Cisco IOS Firewall specifically context-based access control (CBAC) and the intrusion detection system (IDS) cannot identify the contents of the IP fragments
Server Management Tools (ASMT)
1 Auspex Server Management Tools (ASMT) Introduction This module presents the Auspex Server Management Tools, or ASMT. This is a graphical interface which allows you to perform most NetServer system administration
CSE543 - Introduction to Computer and Network Security. Module: Reference Monitor
CSE543 - Introduction to Computer and Network Security Module: Reference Monitor Professor Trent Jaeger 1 Living with Vulnerabilities So, software is potentially vulnerable In a variety of ways So, how
EMC ApplicationXtender Server
EMC ApplicationXtender Server 6.5 Monitoring Guide P/N 300-010-560 A01 EMC Corporation Corporate Headquarters: Hopkinton, MA 01748-9103 1-508-435-1000 www.emc.com Copyright 1994-2010 EMC Corporation. All
NetSpective Logon Agent Guide for NetAuditor
NetSpective Logon Agent Guide for NetAuditor The NetSpective Logon Agent The NetSpective Logon Agent is a simple application that runs on client machines on your network to inform NetSpective (and/or NetAuditor)
Common Criteria. Introduction 2014-02-24. Magnus Ahlbin. Emilie Barse 2014-02-25. Emilie Barse Magnus Ahlbin
Common Criteria Introduction 2014-02-24 Emilie Barse Magnus Ahlbin 1 Magnus Ahlbin Head of EC/ITSEF Information and Security Combitech AB SE-351 80 Växjö Sweden [email protected] www.combitech.se
Release Notes: J-Web Application Package Release 15.1A1 for Juniper Networks EX Series Ethernet Switches
Release Notes: J-Web Application Package Release 15.1A1 for Juniper Networks EX Series Ethernet Switches Release 15.1A1 4 June 2015 Revision 1 Contents Release Notes: J-Web Application Package Release
Red Hat Enterprise Linux Version 5.6 Security Target for CAPP Compliance on DELL 11 th Generation PowerEdge Servers
Red Hat Enterprise Linux Version 5.6 Security Target for CAPP Compliance on DELL 11 th Generation PowerEdge Servers Version: 2.02.02.0 Last Update: 2012-08-21 atsec is a trademark of atsec GmbH Dell and
FREQUENTLY ASKED QUESTIONS
FREQUENTLY ASKED QUESTIONS Secure Bytes, October 2011 This document is confidential and for the use of a Secure Bytes client only. The information contained herein is the property of Secure Bytes and may
SecureDoc Disk Encryption Cryptographic Engine
SecureDoc Disk Encryption Cryptographic Engine FIPS 140-2 Non-Proprietary Security Policy Abstract: This document specifies Security Policy enforced by SecureDoc Cryptographic Engine compliant with the
SECURITY TARGET FOR CENTRIFY SUITE VERSION 2013.2
SECURITY TARGET FOR CENTRIFY SUITE VERSION 2013.2 Document No. 1769-000-D0007 Version: v0.89, 12 September 2013 Prepared for: Centrify Corporation 785 N. Mary Avenue, Suite 200 Sunnyvale, California USA,
BM482E Introduction to Computer Security
BM482E Introduction to Computer Security Lecture 7 Database and Operating System Security Mehmet Demirci 1 Summary of Lecture 6 User Authentication Passwords Password storage Password selection Token-based
Oracle Solaris Security: Mitigate Risk by Isolating Users, Applications, and Data
Oracle Solaris Security: Mitigate Risk by Isolating Users, Applications, and Data Will Fiveash presenter, Darren Moffat author Staff Engineer Solaris Kerberos Development Safe Harbor Statement The following
Active Directory Integration for Greentree
App Number: 010044 Active Directory Integration for Greentree Last Updated 14 th February 2013 Powered by: AppsForGreentree.com 2013 1 Table of Contents Features... 3 Options... 3 Important Notes... 3
Xcalibur. Foundation. Administrator Guide. Software Version 3.0
Xcalibur Foundation Administrator Guide Software Version 3.0 XCALI-97520 Revision A May 2013 2013 Thermo Fisher Scientific Inc. All rights reserved. LCquan, Watson LIMS, and Web Access are trademarks,
Creating Home Directories for Windows and Macintosh Computers
ExtremeZ-IP Active Directory Integrated Home Directories Configuration! 1 Active Directory Integrated Home Directories Overview This document explains how to configure home directories in Active Directory
Tracking Network Changes Using Change Audit
CHAPTER 14 Change Audit tracks and reports changes made in the network. Change Audit allows other RME applications to log change information to a central repository. Device Configuration, Inventory, and
