节点文献
CC功能要求映射于系统安全措施的方法研究
A Study on the Mapping Relationship of the Functional Requirements of CC and System Security Measures
【作者】 宋成勇;
【导师】 方勇;
【作者基本信息】 四川大学 , 通信与信息系统, 2005, 硕士
【摘要】 全球信息化已成为人类社会发展的大趋势,信息技术的研究和应用日新月异。与此同时,信息系统的安全问题也逐步得到社会的重视,加强信息安全技术的研究和应用成为一个长期而持久的课题。由于互连网络具有开放性、联结形式多样性、技术复杂性等特征以及通信协议的安全缺陷,致使信息系统的安全问题变得尤为复杂。无论是局域网还是在广域网中,对于信息系统而言,都存在着自然的和人为的等诸多因素的潜在威胁。加强网络上各种资源的安全保护是非常必要的,信息安全技术已成为信息技术发展过程中一个迫切需要解决的问题。 信息系统安全问题既具有涉及全网络的整体性,又具有涉及各种技术、管理等多层面的复杂性,关键问题是制定统一的安全策略和整体方案,培养充足的技术骨干,并加强安全管理,这样才能提高信息系统的安全保障能力。因此,必须针对各种不同的威胁和系统本身的脆弱性,多层次、多方位地、系统化地制定信息系统的安全措施,这样才能确保信息系统运行安全和信息的机密性、完整性和可用性。保障信息系统安全的措施很多,但并不仅仅是拼凑几个安全措施或者将所有的信息安全措施都用上就能保证信息系统的安全性。基于成本与效率的考虑,一个信息系统只要根据完善的安全策略配备了基本的信息安全措施,就可以保证信息系统的安全性。信息系统风险评估为我们判断信息系统的安全性能提供了可靠的依据。 本文结合作者参与的项目开发过程,对《信息技术安全性评估准则》(即CC)的安全功能要求与安全措施进行了研究,通过对各种安全措施的分析和归纳,研究并总结性提出了安全措施在本质上与CC安全功能要求的映射关系,为评估安全措施的有效性提供依据,为信息系统的安全体系结构设计到安全功能需求,再到具体安全措施建立联系的桥梁。
【Abstract】 The global informationization has already become the main trend of human social development, and the research and application of information technology has been changing with each passing day . Meanwhile, the security problem of the information system was paid attention to likewise step by step, and the more research and applications of information security have already become a long-term and lasting subject. Because the internet networks have such characteristics as opening, variety of connection form, complexity of security technology, and security defect of communication protocol, etc., the security problem of the information system have become particularly complicated. No matter in the WAN, or in the LAN, there are a great deal of potential threats in information system from nature and human being. It’s necessary to strengthen the security protection to different resources. The information security protection technology has already become an urgent problem of the information technology, which need be resolved.The security problem of information system has the overallness that is concerned with whole network, and has the complexity that is concerned with the multilayer fields such as various technology and management. It’s the key of the problem making unified security policy and entire scheme, training adequate technical mainstay, strengthening the security management .The ability of information system security assurance can be raised in this way .Therefore we must make the safeguards multi-levelly, multi-directionally, systematizedly against the vulnerability of system itself and various different threats to ensure safely running of information system and confidentiality, integrity and availability of information . There are many safeguards to assurance information system security, but it’s not enough to assurance security of informationsystem to patch up some safeguards or apply all safeguards. Based on the consideration of cost and efficiency, if an information system has allocated basic safeguards according to perfect security policy, security performance of information system can be ensured. The security evaluation of information systematic has offered practical basis for us to judge the security performance of information system. Based on the consideration of cost and efficiency, if an information system has allocated basic safeguards according to perfect security policy, security performance of information system can be ensured. Risk evaluation of information system has offered reliable basis for us to judge the security performance of information system.Combining the project development that author participate in, this dissertation research safeguards and security functional requirements of " Common Criteria for Information Technology Security Evaluation", namely CC, and research and bring forward the relationship of safeguards and security functional requirements of CC essentially by analysing and concluding various safeguards, to offer basis on evaluating the validity of safeguards.This dissertation starts with the structure of security system, and has discussed the relationship of security service and security mechanism. Beacause security mechanism is the foundation of realizing security service, there must be effective security mechanism, and there would be reliable security service probably. Then this dissertation has analysed the security functional requirement components of CC, and has researched the relation of security mechanism and security functional requirements. This dissertation analyse security function requirements that is corresponding to security mechanism, to which we choose the safeguards according . The security function requirements is function and purpose that the security mechanism of an information technology should achieve. This dissertation has still summarized nowaday general security technology mechanism. Only according to security demand of information system, select appropriate security mechanism and security production, and allocate to systematic proper location and layer of information system, then the purpose of control information system risk can be realized . This dissertation brings forward elementary relationship of security functional requirements of CC and safeguards.
【Key words】 open systems; CC; security measures; risk evaluation; security functional requirements;
- 【网络出版投稿人】 四川大学 【网络出版年期】2006年 02期
- 【分类号】TP309
- 【被引频次】1
- 【下载频次】83