05.
Implementation
Prof. Manel Medina
[Link]/in/manelmedina/
Twitter: @Medina_Manel
[Link]
Calendar
Subjects
- Starting: risk, treats & policy
- Architectures: Trusted Cloud Initiative (TCI) by CSA
- Passive sec.: net mngmt, acc ctl, encrypt, dlp, user
devices
- Active: ids, Vulnerability management, SIEM
- Application security: OWASP, code protection
- Web services & Microservcs: Requirements, risk &
impact, new architectures
- Methodology: NIST, BSIMM
CyberSecurity Principles (CATIA)
(DICTA)
• Availability
• -Continuity / Contingency
• Integrity
• Confidentiality
• Traceability / Auditability
• Traceability of the operations
• -Not repudiation of the originator of the operations
• Authentication
• -ID
• -Authorization
OSA (Open Security Architecture) design principles
TCI Sec. Architecture by CSA
Security by Design
TCI Sec. Architecture by CSA
1. Cybersecurity
Governance
Threat Vulnerability Managmt
Security Intelligence Report
Service Oriented Architecture
2. Passive Security
Passive protection
1. Network security management
• Segregation
• Communications
2. Server & Service protection
3. Encryption
• Key protection
4. Authorisation and access control
• Authentication
• Privileged access
5. Anti-Malware
6. Remote access & wireless
2.1. Network Security: Segregation
• Security Domain identification
• Same trustworthiness level
• Equivalent security needs
• Equivalent risk scenarios
• Communications:
• Network Access control
• Abnormal behaviour detection
• Firewall
• intrusion prevention systems (IPSs)
• Unified threat management (UTM)
2.2. Web Application Firewall
• WAF protects a Web application by controlling its input
and output and the access to and from the application.
Running as an appliance, server plug-in or cloud-based
service, a WAF inspects every HTML, HTTPS, SOAP and
XML-RPC data packet. Through customizable inspection,
it is able to prevent attacks such as XSS, SQL injection,
session hijacking and buffer overflows, which network
firewalls and intrusion detection systems are often not
capable of doing. A WAF is also able to detect and
prevent new unknown attacks by watching for
unfamiliar patterns in the traffic data.
• Application Security Testing (AST), distributed denial of
service (DDoS) protection appliances, Web fraud
detection and database security solutions.
2.3 VPN
3. Data Protection
3.1 Data Protection: Access Mngmt.
• DLP: Data Leak / Data Loss Prevention
• Right Management:
• IRM: Information Right management
• RMS: Right Management Services
• Profiles/ Roles/ Policies/ Compatibility/ …
• Information encryption
• In Transit
• In Origen
• Open issues:
• Key encrypt. algorithms
& Enterprise Key mngment
• Role/ Rights/ Access
• Integration in Cloud
• BYOK: BYO Key
3.2 Data Protection: Encryption
• Classification of Information
• Policy and Processes:
• Classification Guidelines
• Information tagging & handling
• Asset handling
• Encryption:
• Cryptographic controls usage policy: network traffic,
files, storage, application live data, database,
authentication & authorisation elements
• Key Management: user key, master key, key providers,
derivated keys, secure deletion
3.3 BYOD
4. Identity management
and Access control rights
4.1 Authentication - One Time Password
• Combination of three • One-time password.
factors • Requires a Flow
• Something that I am: Implementation
• Paw print
• Error handling
• Retina scanner
• Voice pattern
• Writing cadence
• Something I own
• Phone
• Token
• Card
• Something I know
• Pin
• Password
5. End-point security
6. Active Protection
• IDS
• Vulnerability Management
• SIEM: log management, event correlation, Intelligence
OSA (Open Security Architecture) design principles
7. Application and
Development Security
- Mobile security App
Security Development Lifecycle
Security Development Lifecycle
8. Web Services Security
WS Risks
• Message modification (integrity)
• Lack of confidentiality
• Fake message
• Man in the Middle
• Identity spoofing
• Message re-use (full or part)
• DoS
C
o
n
c
l
u
si
o
n
References
• [Link]
8-global-study-application-security
• [Link]
application-security-top-health-care-apps-in-
critical-condition
• [Link]
security/