0% found this document useful (0 votes)
15 views77 pages

Lecture 6

يتناول المستند موضوعات أمن نظام التشغيل وأمن التطبيقات وأمن البيانات. يتضمن مبادئ أمن نظام التشغيل وأمن الحسابات وأمن نظام الملفات. كما يناقش تقييم المخاطر والحد منها.

Uploaded by

Osamah Al-hazmi
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
15 views77 pages

Lecture 6

يتناول المستند موضوعات أمن نظام التشغيل وأمن التطبيقات وأمن البيانات. يتضمن مبادئ أمن نظام التشغيل وأمن الحسابات وأمن نظام الملفات. كما يناقش تقييم المخاطر والحد منها.

Uploaded by

Osamah Al-hazmi
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

APPLICATIONS AND DATA

• Operating System Security ‫• أمان نظام التشغيل‬


• Application Security ‫أمن التطبيقات‬ •
• Data security ‫أمن البيانات‬ •

‫ عبدالرحمن القناد‬: ‫االستاذ‬


Operating
System Security

✓ Security Principles‫مبادئ األمن‬


✓ Account Security‫أمان الحساب‬
✓ File System Security‫أمن نظام الملفات‬
✓ Assessing Risk‫تقييم المخاطر‬
✓ Reducing Risk‫الحد من المخاطر‬
1:Security Principles
Security
Services

• Authentication
• Access control
• Data confidentiality
• Data integrity
• Nonrepudiation
Evaluation
Criteria‫معايير التقييم‬

• European Information Technology Security


Evaluation Criteria document BS 7799 ‫وثيقة‬
‫معايير تقييم أمن تكنولوجيا المعلومات األوروبية‬BS 7799
• Trusted Computer Systems Evaluation
Criteria‫معايير تقييم أنظمة الكمبيوتر الموثوق بها‬
• Common Criteria‫معايير مشتركة‬
Security Levels

• Low
• Medium
• High
Security
Mechanisms‫اآلليات األمنية‬
• Specific‫خاص‬
- Encipherment‫التشفير‬
- Digital signature‫التوقيع الرقمي‬
- Access control‫التحكم في الوصول‬
- Data integrity‫سلامة البيانات‬
- Authentication‫المصادقه‬
- Traffic padding‫حشو حركة المرور‬
• Wide‫واسع‬
- Trusted functionality‫وظائف موثوق بها‬
- Security labels‫تسميات الأمان‬
- Audit trailsArabic translation‫ مسارات التدقيق‬.
- Security recovery‫استرداد الأمان‬
Windows 2000
Security

• Exploits
• Windows 2000 registry
Windows 2000
Security Architecture

• Windows 2000 security components


- C2 certification
• Windows 2000 objects
• Security components
- SIDs
- Access tokens
- Security descriptors
- Access control lists and entities
• Security subsystem
Linux
Security

• Configuration problems
- Misconfigured authentication settings
- ‫إعدادات المصادقة التي تم تكوينها بشكل خاطئ‬
- Unnecessary services
- ‫خدمات غير ضرورية‬
- Default account policies
- ‫سياسات الحساب االفتراضية‬
- Non-root user access to sensitive
commands ‫وصول المستخدم غير الجذر إلى األوامر‬
‫الحساسة‬
-
Pluggable
Authentication Modules
‫قابل وحدات المصادقة‬
• Editing PAM(privileged access management)
files ‫تحرير ملفات‬PAM ()‫إدارة الوصول المميز‬
• PAM directories‫الدالئل‬
• PAM entry format‫تنسيق اإلدخال‬
• Telnet access and the root account
• ‫الوصول إلى‬Telnet ‫والحساب الجذر‬

2: Account Security
Passwords

• Windows 2000 and strong passwords


- Enforcing strong passwords
- ‫فرض كلمات مرور قوية‬
- Dictionary attacks‫هجمات القاموس‬
• Linux and strong passwords
- Shadow passwords
- ‫كلمات مرور الظل‬
- The root account
- ‫حساب الجذر‬
Verifying
System State‫التحقق‬
‫حالة النظام‬
• Cross-referencing information on non-domain
controllers
• Built-in and external tools
• ‫معلومات اإلحالة المرجعية على وحدات التحكم غير التابعة للمجال‬
• ‫أدوات مدمجة وخارجية‬
• Renaming default accounts ‫إعادة تسمية الحسابات‬
‫االفتراضية‬
• Windows 2000 account policies
• Password lockout‫قفل كلمة المرور‬

Password
Aging in Linux

• Linux command options‫خيارات أوامر لينكس‬



• Timing out users‫توقيت المستخدمين‬

• Monitoring accounts‫مراقبة الحسابات‬

• System-wide event logging facility ‫مرفق‬
‫تسجيل األحداث على نطاق المنظومة‬

3: File System
Security
Windows 2000
File System Security

• File-level permissions
• Standard 2000 permissions
• Drive partitioning
• Copying and moving files
Remote File
Access Control

• Remote access permissions


- Full Control
- Modify
- Read & Execute
- No Access
• Share permissions
Linux
File System Security

• Files
• File information
• Permissions
• The umask command
• The chmod command
• UIDs and GIDs‫معرفات المستخدم ومؤشرات الجهوية‬

4: Assessing Risk‫تقييم المخاطر‬
‫‪Security‬‬
‫‪Threats‬‬

‫التهديدات العرضية‬ ‫•‬


‫التهديدات المتعمدة‬ ‫•‬
‫التهديدات السلبية‬ ‫•‬
‫التهديدات النشطة‬ ‫•‬
Types of
Attacks

• Spoofing/masquerade‫التنكر‬/‫االنتحال‬
• Replay‫اعاده‬
• Denial of service‫الحرمان من الخدمة‬
• Insider ‫الدخيل‬
• Trapdoor‫تراب دور‬
• Trojan horses‫حصنة طروادة‬

Windows 2000
Security Risks

• Default directories‫الدالئل االفتراضية‬


• Default accounts‫الحسابات االفتراضية‬
• Default shares and services ‫األسهم والخدمات‬
‫االفتراضية‬

General UNIX
Security Vulnerabilities
‫الثغرات األمنية العامة في‬UNIX

• Viruses‫فيروسات‬
• Buffer overflows‫تجاوزات مخزن مؤقت‬
Keyloggers

• Invisible KeyLogger Stealth and Windows


20002000 ‫غير مرئية كلوغر الشبح وويندوز‬

• Keylogging and securing the Linux search
path ‫تسجيل المفاتيح وتأمين مسار بحث‬Linux

• Protecting yourself against keyloggers ‫حماية‬
‫نفسك من كلوغرز‬

System Port Scanning
‫نظام المسح الضوئي للمنافذ‬

• Advanced security scanners


• ‫الماسحات الضوئية األمنية المتقدمة‬
• WebTrends Security Analyzer
• ‫محلل أمان‬WebTrends
UNIX
Security Risks

• The rlogin command


- Interactive sessions: Telnet vs. rlogin
• Network Information System (NIS)
• Network File System (NFS)
NIS
Security Concerns

• NIS security problems


- No authentication requirements
- Contacting server by broadcast
- Plain-text distribution
- Encryption and authentication
- Portmapper processes and
TCPWrappers
- The securenets file
• NIS+
NFS
Security Concerns

• Users, groups and NFS


• Secure RPC
• NFS security summary
‫‪5: Reducing Risk‬‬
‫‪ :5‬الحد من المخاطر‬
Patches
and Fixes‫التصحيحات واإلصالحات‬

• Microsoft service packs


• Red Hat Linux errata
Windows 2000
Registry Security

• Registry structure
- Subtrees and their uses
• Auditing the registry
• Setting registry permissions
Disabling and Removing
Services in Windows 2000

• Securing network connectivity


• ‫تأمين االتصال بالشبكة‬

• Server Message Block
• ‫كتلة رسائل الخادم‬

• Miscellaneous configuration changes
• ‫تغييرات متنوعة في التكوين‬

Disabling and
Removing Services in UNIX

• Bastille

- The tarball format


- Downloading and installing Bastille
- Running Bastille in text mode
APPLICATION
SECURITY
Functionality Over Security
‫الوظائف عبر األمان‬

• Security must be included from the


beginning‫يجب تضمين األمان من البداية‬
• Strap-on security is an invitation to disaster ‫األمن‬
‫على الحزام هو دعوة إلى كارثة‬
• M&M syndrome ‫متالزمة‬M & M
- Developers and security engineers are
different fields‫المطورون ومهندسو األمن هم مجاالت مختلفة‬
- Rush to market‫االندفاع إلى السوق‬
- Customarily ‘sell now, patch it later’
- "‫ تصحيحه الحقا‬، ‫عادة "بيع اآلن‬
- Reliance on perimeter protection
- ‫االعتماد على حماية المحيط‬
‫‪Shifting from Reactive to‬‬
‫‪Proactive‬‬
‫التحول من رد الفعل إلى االستباقية‬
‫‪Software Version‬‬
‫‪+1‬‬
‫إصدار البرنامج ‪1+‬‬

‫‪Admins install‬‬
‫)‪patch(es‬‬ ‫‪Vulnerability‬‬
‫‪found‬‬
‫يقوم المسؤولون بتثبيت‬
‫التصحيح (التصحيحات)‬ ‫تم العثور على ثغرة‬
‫أمنية‬

‫‪Vendor patches‬‬ ‫‪Exploit released‬‬


‫تصحيحات البائعين‬ ‫استغالل االصدر‬
Secure Implementation

• How the software/OS is set up


- Features
- Configuration
- Security policies
- Group/user permissions

• Should default to uninstalled/no access


Database

• Where all the data goes


- Central location
• Behind multiple firewalls
• Access control, views, etc.
• Easy to backup
• Likely contains the most sensitive data
Database Types

• Hierarchical
• Network
• Relational
• Object Oriented
Database

Social sec # Name Address


111-22-3333 Tom Thompson 123b Whatever
St.
444-55-6666 Sue Slackley 8 Hill Road
Database (cont)
 Record – collection of related data items
 View – restricts data visibility
 Schema – database structure
 Data Dictionary – repository of data
relationships
 Database – cross-referenced data collection
 Index – fast way to search data
Incom Ag Social Sec #
Social sec # Name Address e e
111-22-3333 Tom 123b Whatever 12000 19 111-22-3333
Thompson 78000 56 444-55-6666
444-55-6666 Sue Slackley 8 Hill Road
Database issues

• Concurrency – changes overwritten making data


inaccurate..‫ التغييرات التي يتم استبدالها مما يجعل البيانات غير دقيقة‬- ‫التزامن‬
- Fixed with locks‫ثابت مع أقفال‬
• Semantic integrity – makes sure structure and semantic
rules enforced..‫ التأكد من تطبيق القواعد الهيكلية والداللية‬- ‫النزاهة الداللية‬
• Referential integrity – all foreign keys reference existing
records‫ تشير جميع المفاتيح الخارجية إلى السجالت الموجودة‬- ‫التكامل المرجعي‬
• Entity integrity – tuples uniquely identified by primary key
values. ‫ مجموعات يتم تحديدها بشكل فريد من خالل القيم الرئيسية‬- ‫تكامل الكيان‬
.‫األساسية‬

Database activities

• Rollback – transaction(s) cancelled, database switched to


an earlier version ‫ وتم تحويل قاعدة‬، )‫ تم إلغاء المعاملة (المعامالت‬- ‫التراجع‬
‫البيانات إلى إصدار سابق‬
• Commit – completes a transaction, database updated
• ‫ يتم تحديث قاعدة البيانات‬، ‫ يكمل معاملة‬- ‫االلتزام‬
• Savepoints – allow recovery in the event of a crash or
error‫ السماح باالسترداد في حالة حدوث عطل أو خطأ‬- ‫نقاط الحفظ‬

Database Security issues

• Aggregation – combining information to


glean unauthorized information
• ‫ الجمع بين المعلومات لجمع معلومات غير مصرح بها‬- ‫التجميع‬
• Inference – deduction of information from
bits of information (result of aggregation)
(Pizza and CIA)
• ‫ خصم المعلومات من أجزاء من المعلومات (نتيجة‬- ‫االستدالل‬
)‫التجميع) (بيتزا ووكالة المخابرات المركزية‬

‫‪Aggregation attack‬‬
‫‪prevention‬‬
‫منع هجمات التجميع‬
‫•‬ ‫التحكم في الوصول المعتمد على المحتوى ‪ -‬كلما كانت البيانات أكثر حساسية ‪ ،‬كلما قل عدد‬
‫األشخاص الذين يمكنهم الوصول إليها‬
‫•‬ ‫المعتمد على السياق ‪ -‬يحافظ على تتبع المحاوالت السابقة ‪ ،‬ويتأكد من أن الطلب "منطقي" ‪AC‬‬
‫•‬ ‫قمع الخاليا – يخفي الخاليا الحساسة‬
‫•‬ ‫التقسيم ‪ -‬يقسم قاعدة البيانات‬
‫•‬ ‫الضوضاء واالضطراب ‪ -‬إدراج معلومات مزيفة‬
‫•‬ ‫الوصول إلى البيانات استنادا إلى اإلذن ‪DAC / MAC‬طرق عرض قاعدة البيانات ‪ -‬يقيد‬
‫(األذونات)‬
‫•‬ ‫‪DAC‬تعدد المتماثالت ‪ -‬مثل الضوضاء واالضطراب ‪ ،‬يتم استبدال البيانات المختلفة فقط بناء على‬
‫‪MAC.‬‬
‫•‬ ‫وجهة الشحن""‬
‫•‬
‫‪Other Database Stuff‬‬

‫•‬ ‫معالجة المعامالت عبر اإلنترنت ‪ -‬التسامح مع األخطاء ‪OLTP – ،‬‬


‫األداء العالي ‪ ،‬الموزعة‬
‫•‬ ‫أكثر عرضة للهجوم‬
‫•‬ ‫الجمع بين قواعد البيانات المتباينة في – ‪Data Warehousing‬‬
‫قاعدة واحدة كبيرة للتحليل‬
‫•‬ ‫التنبؤ باألعمال‬
‫•‬ ‫تتجه‬
‫•‬ ‫استخراج البيانات ‪ -‬ابحث عن الجمعيات‪/‬االرتباطات‬
‫•‬ ‫البيانات الوصفية ‪ -‬العثور على عالقات غير مرئية في البيانات‬
‫•‬
System
Development
Security & Development

• Security plan created at the start of the


project
• Look at security integration at each stage
of the lifecycle
• Systems development lifecycle
Project
initiation
Disposal
‫بدء المشروع‬

Functional design
analysis and
Operational planning
maintenance
‫تحليل التصميم الوظيفي‬
‫الصيانة التشغيلية‬ ‫والتخطيط‬

Installation and System design


implementation specifications
‫التثبيت والتنفيذ‬ ‫مواصفات تصميم النظام‬

Software
development
‫تطوير البرمجيات‬
Project Initiation

• Conceptual definition of the project


• Are there existing products?
• User needs
• Basic security objectives (C.I.A.)
• Risk management –
- The design itself should have security
integrated
• Risk analysis – identify risks and
consequences
Functional Design Analysis
and Planning
• Functional baseline – what the product is
expected to do/ features
• Test plan created
• Security requirements
• Security controls to be implemented
• Identify other weaknesses and minimize
• Create the design document
- Make sure to share it with the customer
- no surprises
‫‪System design specifications‬‬

‫•‬ ‫‪Requirements‬‬
‫نموذج المعلومات ‪ -‬النوع وكيفية معالجة المعلومات ‪-‬‬
‫النموذج الوظيفي ‪ -‬المهام التي يقوم بها التطبيق‪- .‬‬
‫النموذج السلوكي ‪ -‬حاالت التطبيق أثناء وبعد االنتقاالت‪- .‬‬
‫•‬ ‫هياكل البيانات والمكونات الهيكلية‬
‫•‬ ‫وظائف النظام مقسمة إلى مزيد من التفاصيل‬
‫•‬ ‫قابلية التشغيل البيني والنمطية‬
‫•‬ ‫‪ ،‬سالمة النظام‪IPC .‬التحكم في الوصول ‪ ،‬الحقوق واألذونات ‪،‬‬
‫•‬
‫‪Software Development‬‬

‫•‬ ‫إدراج المبرمجين والمطورين هنا‬


‫•‬ ‫الترميز اآلمن‬
‫•‬ ‫التحقق من أطوال اإلدخال‬
‫•‬ ‫السماح بأنواع البيانات المناسبة فقط ‪ -‬تعقيم المدخالت‬
‫•‬ ‫منع القنوات السرية‬
‫•‬ ‫تصحيح األخطاء ‪ ،‬مراجعات التعليمات البرمجية‬
‫•‬ ‫وثيقة‪ ،‬وثيقة‪ ،‬وثيقة‬
‫•‬ ‫اختبار الوحدة ‪ -‬يتم اختبار كل "قطعة" من التعليمات البرمجية‬
‫•‬ ‫الفصل بين الواجبات ‪ -‬يقوم أشخاص مختلفون بإجراء اختبار المدخالت‬
‫والتحقق من الصحة‬
‫•‬ ‫إزالة أي خطافات صيانة ‪ /‬أبواب خلفية‬
Installation/Implementation

• How to use and operate the application


• Protection configured
• Functionality and performance testing
• Document configuration
• Certification process
• Accreditation – formal acceptance by
management.
‫‪Operational‬‬
‫الصيانة التشغيلية‪Maintenance‬‬

‫•‬ ‫إدراج معلومات النظام في البيئة‬


‫•‬ ‫إجراء اختبارات دورية للثغرات األمنية‪.‬‬
‫•‬ ‫إعادة التصديق ‪ /‬االعتماد بعد أي تغييرات ‪ /‬تحديثات رئيسية‪.‬‬
‫•‬
‫تصريف ‪Disposal‬‬

‫•‬ ‫أرشفة البيانات وتدميرها وترحيلها‬


‫•‬ ‫الكتابة فوق الوسائط المدمرة ماديا‬
‫•‬ ‫يمكن أن يكون التخلص صعبا‬
‫ترحيل البيانات ‪ /‬تغيير تنسيق البيانات ‪-‬‬
‫إلغاء تثبيت البرنامج بالكامل ‪-‬‬
‫‪Security Testing‬‬

‫•‬ ‫البرامج التي تم فحصها تحت هجوم محاكاة‬


‫•‬ ‫يبحث عن نقاط الضعف‪Looks for vulnerabilities‬‬
‫التحقق من الحدود ‪-‬‬
‫تنسيق البيانات ‪-‬‬
‫معالجة األخطاء ‪-‬‬
‫إعدادات التكوين ‪-‬‬
‫االختبار اليدوي واآللي ‪-‬‬
‫الهندسة االجتماعية ‪-‬‬
‫‪-‬‬
Software Escrow
‫برنامج الضمان‬

• 3rd party keeps a copy of the source


code3 ‫يحتفظ الطرف‬rd ‫بنسخة من شفرة المصدر‬
• Code is released to client in certain
situations ‫يتم إصدار التعليمات البرمجية للعميل في مواقف‬
‫معينة‬

Languages

• Machine code
• Assembly language
• High level language
• Very high-level language
• Natural language
Languages (cont)

• Interpreters – translate one command at a


time - perl‫ بيرل‬- ‫ترجمة أمر واحد في كل مرة‬
• Compilers – translate sections at a time -
C - ‫ترجمة األقسام في وقت واحد‬C
• Assemblers – translate from assembly to
machine code ‫ ترجمة من التجميع إلى رمز‬- ‫المجمعون‬
‫الماكينة‬
Web Security
Attacks on web security

• Vandalism‫التخريب‬
• Financial fraud‫االحتيال المالي‬
• Privileged/Admin access‫المسؤول‬/‫الوصول المميز‬
• Theft of Transaction information ‫سرقة معلومات‬
‫المعامالت‬
• Theft of IP (via internal network) ‫ سرقة‬IP ( ‫عبر‬
)‫الشبكة الداخلية‬
• DoS attack ‫هجوم‬DoS
Defenses for web attacks

• Web application firewalls (Deep packet


inspection) ‫جدران حماية تطبيقات الويب (الفحص العميق‬
)‫للحزم‬
• Quality assurance process/security review
• ‫المراجعة األمنية‬/‫عملية ضمان الجودة‬
• Authentication and access control ‫المصادقة‬
‫والتحكم في الوصول‬
• SYN Proxy
Information Gathering
‫جمع المعلومات‬

• Google search
• Cached web site
• Error messages on the web site
• Configuration, include files (incorrect
permissions)
- This happened to wordpress just last
week!
Administrative interface

• Allows remote configuration and


management
• Not a good idea to enable
• If you must, make it Out Of Band
Authentication & Access
Control

• Username and Password most common


- Over a secure channel
• Account lockouts
Configuration Management

• Get it working now, secure it later


• Transferring ‘test’ to ‘production’
• Installing an application/service
- Default usernames/passwords
- Online documentation
- Example pages/databases/files
• Often a ‘kick me’ sign found with
Google searches
- Configuration issues (open by default)
Bypassing web controls

• Path or directory traversal


• Unicode/URL/Hex encoding
• Cross site scripting (XSS)
- [Link]
• Session hijacking/injection
- [Link]
• Server side vs. client side input validation
Web based code

• Java – bytecode, machine code, sandbox


• ActiveX – no sandbox, user allows,
‘authenticode’
• Javascript/VBS
• Flash, Silverlight
Malicious code ‫التعليمات البرمجية‬
‫الضارة‬

• Virus – user action required


- Meme virus
• Worms – self reproduction‫التكاثر الذاتي‬
• Botnets, bots, bot herder
• Logic bombs
• Trojan horses – RATs (BO, Sub7)
• Spam (Bayesian filtering)
Antivirus

• Layered approach
- Client PCs
- Servers
- E-mail servers
- Proxys

• Virus walls
Patch management

• A constant process
• Test
• Deploy (phased?)
• Verify deployment
• Roll back or Validate and report
DATA SECURITY

It’s your Data – Are you sure it’s Safe?


Never Sacrifice Security | Keep your Data Safe

‫ال تضحي أبدا باألمن | حافظ على أمان بياناتك‬


(Data) ‫ماذا تعرف عن البيانات؟‬

• Data is information that has been stored in the form


of Digitalization. ‫البيانات هي المعلومات التي تم تخزينها في شكل‬
‫رقمنة‬
• Data Security is the practice of keeping data
protected from unauthorized access. ‫أمن البيانات هو‬
‫ممارسة الحفاظ على البيانات محمية من الوصول غير المصرح به‬
• Data Security is also known as System Data
Security, Information Security or Computer
Security. ‫يعرف أمن البيانات أيضا باسم أمن بيانات النظام أو أمن‬
.‫المعلومات أو أمن الكمبيوتر‬

PRINCIPLES OF DATA PROTECTION
‫‪Types of Data Security and‬‬
‫‪importance‬‬

‫•‬ ‫‪Network Layer Security‬‬


‫•‬ ‫‪IPSec Protocol‬‬
‫•‬ ‫‪Email Security‬‬

‫يحمي برنامج أمان البيانات الكمبيوتر ‪ /‬الشبكة من التهديدات عبر‬


‫اإلنترنت عند االتصال باإلنترنت‪ .‬قد يحمي برنامج أمان البيانات أيضا‬
‫مناطق أخرى مثل البرامج أو نظام التشغيل لتطبيق بأكمله‪ .‬هدفها هو‬
‫التعرف على القواعد واإلجراءات الواجب تطبيقها ضد الضربات على‬
‫‪.‬أمن اإلنترنت‬

You might also like