Computer Security
Lecture -01-Course Introduction
Prof Amr Jadi
Course Information
• Lecturer: Prof. Amr Jadi
– Office: Room S242 (2rd Floor)
– Email:
– [Link]@[Link]
Course Evaluation
– Mid Term Exam : 25%
– Final Exam: 50%
– Quizzes, Discussions and Assignments,Taturial: 25%
What is Security?
• “The quality or state of being secure—to be free from danger”
• A successful organization should have multiple layers of
security in place:
– Physical security
– Personal security
– Operations security
– Web security
– Network security
– Information security
What is Information Security?
• Information security: a “well-informed sense of assurance that
the information risks and controls are in balance.” —Jim
Anderson, Inovant (2002)
What is Information Security?
• The protection of information and its critical elements,
including computer systems and hardware that use, store,
and transmit that information
• Necessary tools: policy, awareness, training, education,
technology
Security VS Usability
Basic Security Terminology
• The Threat Environment
– The threat environment consists of the types
of attackers and attacks that companies face
CIA Triad
Key Security Attributes
Alice
secure secure
Bob sender receiver
channel
Key Security Attributes
Confidentiality
Integrity
Availability
Authentication
Non Reputation
Confidentiality
• It ensures that information content cannot
be revealed by unauthorized entities.
• It is a Process of concealing information
on the network. Alice
• It prevents eavesdropping.
secure secure
Bob sender receiver
channel
Sam Snoop
Integrity
• It ensures data packets are unaltered
during transition from source to
destination.
• Attackers can violate data integrity
through insertion, substitution, deletion or
forging .
• Different ways of maintaining integrity.
Authentication
• It is a process that allows node to verify
the identity of the communicating node.
• Two types of authentications
Alice
1)Entity authentication
2)Data authentication
Packet
secure secure
Bob sender receiver
Packet Alice receive
Packet
Sam
Availability
• It ensuring that system resources and
services are available for use by
authorized users of the system.
• Intruders can deny services throughAlice
denial of services attacks
secure secure
Bob sender receiver
System resources Alice receive
& services Packet
Non Repudiation
• It ensures a entity in a dispute cannot
falsely deny its action.
• Non repudiation service prevents the
sender from denying sending a message
which he sent earlier Alice
• Receiver cannot claim to have received
the message falsely
secure secure
Bob sender receiver
channel
Alice falsely
claim to have
received packet
Basic Security Terminology
• Countermeasures
– Tools used to thwart attacks
– Also called safeguards, protections, and
controls
– Types of countermeasures
• Preventative
• Detective
• Corrective
2: Security Management
• Technology Is Concrete
– Can visualize devices and transmission lines
– Can understand device and software
operation
• Management Is Abstract
• Management Is More Important
– Security is a process, not a product (Bruce
Schneier)
3: Organizational Issues
• Chief Security Officer (CSO)
– Also called chief information security officer
(CISO)
• Where to Locate IT Security?
– Within IT
• Compatible technical skills
• CIO will be responsible for security
– Outside of IT
• Gives independence
– Hard to blow the whistle on IT and the CIO
• This is the most commonly advised choice
3: Organizational Issues
• Where to Locate IT Security?
– Hybrid
• Place planning, policy making, and auditing outside
of IT
The ISO/IEC 27000 Family
• Place operational ofsuch
aspects Security Standards
as firewall operation
• ISO/IEC 27000
within IT
– Family of IT security standards with several individual standards
– From the International Organization for Standardization (ISO) and the
International Electrotechnical Commission (IEC)
• ISO/IEC 27002
– Originally called ISO/IEC 17799
– Recommendations in 11 broad areas of security management
The ISO/IEC 27000 Family of Security
Standards
• ISO/IEC 27002: Eleven Broad Areas
Security policy Access control
Organization of information Information systems acquisition,
security development and maintenance
Asset management Information security incident
management
Human resources security Business continuity management
Physical and environmental Compliance
security
Communications and operations
management
4: a. Policies
• Policies
– Statements of what is to be done
– Provide clarity and direction
– Does not specify in detail how the policy is to
be implemented in specific circumstances
– Allows the best possible implementation at
any time
– Vary widely in length
4: a. Policies
• Tiers of Security Policies
– Brief corporate security policy to drive
everything
– Major policies
• E-mail
• Hiring and firing
• Personally identifiable information
– Acceptable use policy
• Summarizes key points of special importance for
users
• Typically, must be signed by users
– Policies for specific countermeasures
4: a. Policies
• Writing Policies
– For important policies, IT security cannot act
alone
– There should be policy-writing teams for each
policy
– For broad policies, teams must include IT
security, management in affected
departments, the legal department
– The team approach gives authority to policies
– It also prevents mistakes because of IT
security’s limited viewpoint
4: a. Policies for Access Control
• Individual and Role-Based Access
Control
– Individual access control: bases access rules
on individual accounts
– Role-based access control (RBAC)
• Bases access rules on organizational roles (e.g.,
buyer, member of a team, etc.)
• Assigns individual accounts to roles to give them
access to each role’s resources
• Human and Organizational Controls
– People and organizational forces may 5-24
4: a. Policies for Access Control
• Mandatory and Discretionary Access
Control
– Mandatory access control (MAC)
• No departmental or personal ability to alter
access control rules set by higher authorities
– Discretionary access control (DAC)
• Departmental or personal ability to alter access
control rules set by higher authorities
– MAC gives stronger security but is very
difficult to implement
• Military and National Security Organization
5-25
4: a. Policies for Access Control
• Multilevel Security
– Resources are rated by security level
• Public
• Sensitive but unclassified
• Secret
• Top secret
– People are given the same clearance
level
5-26