APPLICATIONS AND DATA
• Operating System Security • أمان نظام التشغيل
• Application Security أمن التطبيقات •
• Data security أمن البيانات •
عبدالرحمن القناد: االستاذ
Operating
System Security
✓ Security Principlesمبادئ األمن
✓ Account Securityأمان الحساب
✓ File System Securityأمن نظام الملفات
✓ Assessing Riskتقييم المخاطر
✓ Reducing Riskالحد من المخاطر
1:Security Principles
Security
Services
• Authentication
• Access control
• Data confidentiality
• Data integrity
• Nonrepudiation
Evaluation
Criteriaمعايير التقييم
• European Information Technology Security
Evaluation Criteria document BS 7799 وثيقة
معايير تقييم أمن تكنولوجيا المعلومات األوروبيةBS 7799
• Trusted Computer Systems Evaluation
Criteriaمعايير تقييم أنظمة الكمبيوتر الموثوق بها
• Common Criteriaمعايير مشتركة
Security Levels
• Low
• Medium
• High
Security
Mechanismsاآلليات األمنية
• Specificخاص
- Enciphermentالتشفير
- Digital signatureالتوقيع الرقمي
- Access controlالتحكم في الوصول
- Data integrityسلامة البيانات
- Authenticationالمصادقه
- Traffic paddingحشو حركة المرور
• Wideواسع
- Trusted functionalityوظائف موثوق بها
- Security labelsتسميات الأمان
- Audit trailsArabic translation مسارات التدقيق.
- Security recoveryاسترداد الأمان
Windows 2000
Security
• Exploits
• Windows 2000 registry
Windows 2000
Security Architecture
• Windows 2000 security components
- C2 certification
• Windows 2000 objects
• Security components
- SIDs
- Access tokens
- Security descriptors
- Access control lists and entities
• Security subsystem
Linux
Security
• Configuration problems
- Misconfigured authentication settings
- إعدادات المصادقة التي تم تكوينها بشكل خاطئ
- Unnecessary services
- خدمات غير ضرورية
- Default account policies
- سياسات الحساب االفتراضية
- Non-root user access to sensitive
commands وصول المستخدم غير الجذر إلى األوامر
الحساسة
-
Pluggable
Authentication Modules
قابل وحدات المصادقة
• Editing PAM(privileged access management)
files تحرير ملفاتPAM ()إدارة الوصول المميز
• PAM directoriesالدالئل
• PAM entry formatتنسيق اإلدخال
• Telnet access and the root account
• الوصول إلىTelnet والحساب الجذر
•
2: Account Security
Passwords
• Windows 2000 and strong passwords
- Enforcing strong passwords
- فرض كلمات مرور قوية
- Dictionary attacksهجمات القاموس
• Linux and strong passwords
- Shadow passwords
- كلمات مرور الظل
- The root account
- حساب الجذر
Verifying
System Stateالتحقق
حالة النظام
• Cross-referencing information on non-domain
controllers
• Built-in and external tools
• معلومات اإلحالة المرجعية على وحدات التحكم غير التابعة للمجال
• أدوات مدمجة وخارجية
• Renaming default accounts إعادة تسمية الحسابات
االفتراضية
• Windows 2000 account policies
• Password lockoutقفل كلمة المرور
•
Password
Aging in Linux
• Linux command optionsخيارات أوامر لينكس
•
• Timing out usersتوقيت المستخدمين
•
• Monitoring accountsمراقبة الحسابات
•
• System-wide event logging facility مرفق
تسجيل األحداث على نطاق المنظومة
•
3: File System
Security
Windows 2000
File System Security
• File-level permissions
• Standard 2000 permissions
• Drive partitioning
• Copying and moving files
Remote File
Access Control
• Remote access permissions
- Full Control
- Modify
- Read & Execute
- No Access
• Share permissions
Linux
File System Security
• Files
• File information
• Permissions
• The umask command
• The chmod command
• UIDs and GIDsمعرفات المستخدم ومؤشرات الجهوية
•
4: Assessing Riskتقييم المخاطر
Security
Threats
التهديدات العرضية •
التهديدات المتعمدة •
التهديدات السلبية •
التهديدات النشطة •
Types of
Attacks
• Spoofing/masqueradeالتنكر/االنتحال
• Replayاعاده
• Denial of serviceالحرمان من الخدمة
• Insider الدخيل
• Trapdoorتراب دور
• Trojan horsesحصنة طروادة
•
Windows 2000
Security Risks
• Default directoriesالدالئل االفتراضية
• Default accountsالحسابات االفتراضية
• Default shares and services األسهم والخدمات
االفتراضية
•
General UNIX
Security Vulnerabilities
الثغرات األمنية العامة فيUNIX
• Virusesفيروسات
• Buffer overflowsتجاوزات مخزن مؤقت
Keyloggers
• Invisible KeyLogger Stealth and Windows
20002000 غير مرئية كلوغر الشبح وويندوز
•
• Keylogging and securing the Linux search
path تسجيل المفاتيح وتأمين مسار بحثLinux
•
• Protecting yourself against keyloggers حماية
نفسك من كلوغرز
•
System Port Scanning
نظام المسح الضوئي للمنافذ
• Advanced security scanners
• الماسحات الضوئية األمنية المتقدمة
• WebTrends Security Analyzer
• محلل أمانWebTrends
UNIX
Security Risks
• The rlogin command
- Interactive sessions: Telnet vs. rlogin
• Network Information System (NIS)
• Network File System (NFS)
NIS
Security Concerns
• NIS security problems
- No authentication requirements
- Contacting server by broadcast
- Plain-text distribution
- Encryption and authentication
- Portmapper processes and
TCPWrappers
- The securenets file
• NIS+
NFS
Security Concerns
• Users, groups and NFS
• Secure RPC
• NFS security summary
5: Reducing Risk
:5الحد من المخاطر
Patches
and Fixesالتصحيحات واإلصالحات
• Microsoft service packs
• Red Hat Linux errata
Windows 2000
Registry Security
• Registry structure
- Subtrees and their uses
• Auditing the registry
• Setting registry permissions
Disabling and Removing
Services in Windows 2000
• Securing network connectivity
• تأمين االتصال بالشبكة
•
• Server Message Block
• كتلة رسائل الخادم
•
• Miscellaneous configuration changes
• تغييرات متنوعة في التكوين
•
Disabling and
Removing Services in UNIX
• Bastille
- The tarball format
- Downloading and installing Bastille
- Running Bastille in text mode
APPLICATION
SECURITY
Functionality Over Security
الوظائف عبر األمان
• Security must be included from the
beginningيجب تضمين األمان من البداية
• Strap-on security is an invitation to disaster األمن
على الحزام هو دعوة إلى كارثة
• M&M syndrome متالزمةM & M
- Developers and security engineers are
different fieldsالمطورون ومهندسو األمن هم مجاالت مختلفة
- Rush to marketاالندفاع إلى السوق
- Customarily ‘sell now, patch it later’
- " تصحيحه الحقا، عادة "بيع اآلن
- Reliance on perimeter protection
- االعتماد على حماية المحيط
Shifting from Reactive to
Proactive
التحول من رد الفعل إلى االستباقية
Software Version
+1
إصدار البرنامج 1+
Admins install
)patch(es Vulnerability
found
يقوم المسؤولون بتثبيت
التصحيح (التصحيحات) تم العثور على ثغرة
أمنية
Vendor patches Exploit released
تصحيحات البائعين استغالل االصدر
Secure Implementation
• How the software/OS is set up
- Features
- Configuration
- Security policies
- Group/user permissions
• Should default to uninstalled/no access
Database
• Where all the data goes
- Central location
• Behind multiple firewalls
• Access control, views, etc.
• Easy to backup
• Likely contains the most sensitive data
Database Types
• Hierarchical
• Network
• Relational
• Object Oriented
Database
Social sec # Name Address
111-22-3333 Tom Thompson 123b Whatever
St.
444-55-6666 Sue Slackley 8 Hill Road
Database (cont)
Record – collection of related data items
View – restricts data visibility
Schema – database structure
Data Dictionary – repository of data
relationships
Database – cross-referenced data collection
Index – fast way to search data
Incom Ag Social Sec #
Social sec # Name Address e e
111-22-3333 Tom 123b Whatever 12000 19 111-22-3333
Thompson 78000 56 444-55-6666
444-55-6666 Sue Slackley 8 Hill Road
Database issues
• Concurrency – changes overwritten making data
inaccurate.. التغييرات التي يتم استبدالها مما يجعل البيانات غير دقيقة- التزامن
- Fixed with locksثابت مع أقفال
• Semantic integrity – makes sure structure and semantic
rules enforced.. التأكد من تطبيق القواعد الهيكلية والداللية- النزاهة الداللية
• Referential integrity – all foreign keys reference existing
records تشير جميع المفاتيح الخارجية إلى السجالت الموجودة- التكامل المرجعي
• Entity integrity – tuples uniquely identified by primary key
values. مجموعات يتم تحديدها بشكل فريد من خالل القيم الرئيسية- تكامل الكيان
.األساسية
•
Database activities
• Rollback – transaction(s) cancelled, database switched to
an earlier version وتم تحويل قاعدة، ) تم إلغاء المعاملة (المعامالت- التراجع
البيانات إلى إصدار سابق
• Commit – completes a transaction, database updated
• يتم تحديث قاعدة البيانات، يكمل معاملة- االلتزام
• Savepoints – allow recovery in the event of a crash or
error السماح باالسترداد في حالة حدوث عطل أو خطأ- نقاط الحفظ
•
Database Security issues
• Aggregation – combining information to
glean unauthorized information
• الجمع بين المعلومات لجمع معلومات غير مصرح بها- التجميع
• Inference – deduction of information from
bits of information (result of aggregation)
(Pizza and CIA)
• خصم المعلومات من أجزاء من المعلومات (نتيجة- االستدالل
)التجميع) (بيتزا ووكالة المخابرات المركزية
•
Aggregation attack
prevention
منع هجمات التجميع
• التحكم في الوصول المعتمد على المحتوى -كلما كانت البيانات أكثر حساسية ،كلما قل عدد
األشخاص الذين يمكنهم الوصول إليها
• المعتمد على السياق -يحافظ على تتبع المحاوالت السابقة ،ويتأكد من أن الطلب "منطقي" AC
• قمع الخاليا – يخفي الخاليا الحساسة
• التقسيم -يقسم قاعدة البيانات
• الضوضاء واالضطراب -إدراج معلومات مزيفة
• الوصول إلى البيانات استنادا إلى اإلذن DAC / MACطرق عرض قاعدة البيانات -يقيد
(األذونات)
• DACتعدد المتماثالت -مثل الضوضاء واالضطراب ،يتم استبدال البيانات المختلفة فقط بناء على
MAC.
• وجهة الشحن""
•
Other Database Stuff
• معالجة المعامالت عبر اإلنترنت -التسامح مع األخطاء OLTP – ،
األداء العالي ،الموزعة
• أكثر عرضة للهجوم
• الجمع بين قواعد البيانات المتباينة في – Data Warehousing
قاعدة واحدة كبيرة للتحليل
• التنبؤ باألعمال
• تتجه
• استخراج البيانات -ابحث عن الجمعيات/االرتباطات
• البيانات الوصفية -العثور على عالقات غير مرئية في البيانات
•
System
Development
Security & Development
• Security plan created at the start of the
project
• Look at security integration at each stage
of the lifecycle
• Systems development lifecycle
Project
initiation
Disposal
بدء المشروع
Functional design
analysis and
Operational planning
maintenance
تحليل التصميم الوظيفي
الصيانة التشغيلية والتخطيط
Installation and System design
implementation specifications
التثبيت والتنفيذ مواصفات تصميم النظام
Software
development
تطوير البرمجيات
Project Initiation
• Conceptual definition of the project
• Are there existing products?
• User needs
• Basic security objectives (C.I.A.)
• Risk management –
- The design itself should have security
integrated
• Risk analysis – identify risks and
consequences
Functional Design Analysis
and Planning
• Functional baseline – what the product is
expected to do/ features
• Test plan created
• Security requirements
• Security controls to be implemented
• Identify other weaknesses and minimize
• Create the design document
- Make sure to share it with the customer
- no surprises
System design specifications
• Requirements
نموذج المعلومات -النوع وكيفية معالجة المعلومات -
النموذج الوظيفي -المهام التي يقوم بها التطبيق- .
النموذج السلوكي -حاالت التطبيق أثناء وبعد االنتقاالت- .
• هياكل البيانات والمكونات الهيكلية
• وظائف النظام مقسمة إلى مزيد من التفاصيل
• قابلية التشغيل البيني والنمطية
• ،سالمة النظامIPC .التحكم في الوصول ،الحقوق واألذونات ،
•
Software Development
• إدراج المبرمجين والمطورين هنا
• الترميز اآلمن
• التحقق من أطوال اإلدخال
• السماح بأنواع البيانات المناسبة فقط -تعقيم المدخالت
• منع القنوات السرية
• تصحيح األخطاء ،مراجعات التعليمات البرمجية
• وثيقة ،وثيقة ،وثيقة
• اختبار الوحدة -يتم اختبار كل "قطعة" من التعليمات البرمجية
• الفصل بين الواجبات -يقوم أشخاص مختلفون بإجراء اختبار المدخالت
والتحقق من الصحة
• إزالة أي خطافات صيانة /أبواب خلفية
Installation/Implementation
• How to use and operate the application
• Protection configured
• Functionality and performance testing
• Document configuration
• Certification process
• Accreditation – formal acceptance by
management.
Operational
الصيانة التشغيليةMaintenance
• إدراج معلومات النظام في البيئة
• إجراء اختبارات دورية للثغرات األمنية.
• إعادة التصديق /االعتماد بعد أي تغييرات /تحديثات رئيسية.
•
تصريف Disposal
• أرشفة البيانات وتدميرها وترحيلها
• الكتابة فوق الوسائط المدمرة ماديا
• يمكن أن يكون التخلص صعبا
ترحيل البيانات /تغيير تنسيق البيانات -
إلغاء تثبيت البرنامج بالكامل -
Security Testing
• البرامج التي تم فحصها تحت هجوم محاكاة
• يبحث عن نقاط الضعفLooks for vulnerabilities
التحقق من الحدود -
تنسيق البيانات -
معالجة األخطاء -
إعدادات التكوين -
االختبار اليدوي واآللي -
الهندسة االجتماعية -
-
Software Escrow
برنامج الضمان
• 3rd party keeps a copy of the source
code3 يحتفظ الطرفrd بنسخة من شفرة المصدر
• Code is released to client in certain
situations يتم إصدار التعليمات البرمجية للعميل في مواقف
معينة
•
Languages
• Machine code
• Assembly language
• High level language
• Very high-level language
• Natural language
Languages (cont)
• Interpreters – translate one command at a
time - perl بيرل- ترجمة أمر واحد في كل مرة
• Compilers – translate sections at a time -
C - ترجمة األقسام في وقت واحدC
• Assemblers – translate from assembly to
machine code ترجمة من التجميع إلى رمز- المجمعون
الماكينة
Web Security
Attacks on web security
• Vandalismالتخريب
• Financial fraudاالحتيال المالي
• Privileged/Admin accessالمسؤول/الوصول المميز
• Theft of Transaction information سرقة معلومات
المعامالت
• Theft of IP (via internal network) سرقةIP ( عبر
)الشبكة الداخلية
• DoS attack هجومDoS
Defenses for web attacks
• Web application firewalls (Deep packet
inspection) جدران حماية تطبيقات الويب (الفحص العميق
)للحزم
• Quality assurance process/security review
• المراجعة األمنية/عملية ضمان الجودة
• Authentication and access control المصادقة
والتحكم في الوصول
• SYN Proxy
Information Gathering
جمع المعلومات
• Google search
• Cached web site
• Error messages on the web site
• Configuration, include files (incorrect
permissions)
- This happened to wordpress just last
week!
Administrative interface
• Allows remote configuration and
management
• Not a good idea to enable
• If you must, make it Out Of Band
Authentication & Access
Control
• Username and Password most common
- Over a secure channel
• Account lockouts
Configuration Management
• Get it working now, secure it later
• Transferring ‘test’ to ‘production’
• Installing an application/service
- Default usernames/passwords
- Online documentation
- Example pages/databases/files
• Often a ‘kick me’ sign found with
Google searches
- Configuration issues (open by default)
Bypassing web controls
• Path or directory traversal
• Unicode/URL/Hex encoding
• Cross site scripting (XSS)
- [Link]
• Session hijacking/injection
- [Link]
• Server side vs. client side input validation
Web based code
• Java – bytecode, machine code, sandbox
• ActiveX – no sandbox, user allows,
‘authenticode’
• Javascript/VBS
• Flash, Silverlight
Malicious code التعليمات البرمجية
الضارة
• Virus – user action required
- Meme virus
• Worms – self reproductionالتكاثر الذاتي
• Botnets, bots, bot herder
• Logic bombs
• Trojan horses – RATs (BO, Sub7)
• Spam (Bayesian filtering)
Antivirus
• Layered approach
- Client PCs
- Servers
- E-mail servers
- Proxys
• Virus walls
Patch management
• A constant process
• Test
• Deploy (phased?)
• Verify deployment
• Roll back or Validate and report
DATA SECURITY
It’s your Data – Are you sure it’s Safe?
Never Sacrifice Security | Keep your Data Safe
ال تضحي أبدا باألمن | حافظ على أمان بياناتك
(Data) ماذا تعرف عن البيانات؟
• Data is information that has been stored in the form
of Digitalization. البيانات هي المعلومات التي تم تخزينها في شكل
رقمنة
• Data Security is the practice of keeping data
protected from unauthorized access. أمن البيانات هو
ممارسة الحفاظ على البيانات محمية من الوصول غير المصرح به
• Data Security is also known as System Data
Security, Information Security or Computer
Security. يعرف أمن البيانات أيضا باسم أمن بيانات النظام أو أمن
.المعلومات أو أمن الكمبيوتر
•
PRINCIPLES OF DATA PROTECTION
Types of Data Security and
importance
• Network Layer Security
• IPSec Protocol
• Email Security
يحمي برنامج أمان البيانات الكمبيوتر /الشبكة من التهديدات عبر
اإلنترنت عند االتصال باإلنترنت .قد يحمي برنامج أمان البيانات أيضا
مناطق أخرى مثل البرامج أو نظام التشغيل لتطبيق بأكمله .هدفها هو
التعرف على القواعد واإلجراءات الواجب تطبيقها ضد الضربات على
.أمن اإلنترنت