Cryptography - Lecture 23 - Trusted Computer Systems

This lesson introduces the idea of trusted computer systems which are evaluated against a standard. It then discusses risk assessment.

Objectives

  • understand the idea of trusted computer systems
  • understand the need for evaluation of systems
  • understand the concept of risk assessment
  • be able to do a simple yellow book or DSD risk analysis
  • Preliminary Reading

    Stallings, "Cryptography and Network Security", Ch 16.2 pp527-532

    Lecture Content

    Trusted Computer Systems

    1. Trusted Computer Systems
    2. Information System Security
    3. Issues with Trusted Computer Systems
    4. Evaluation Concepts and Relationships
    5. Evaluation Concepts and Relationships
    6. Trusted Computing Base
    7. Types of Secure Computing Systems
    8. Dedicated (Single-Level) Systems
    9. System-High
    10. Compartmented
    11. Multi-Level Systems
    12. Evaluation Process
    13. Security Evaluation Stages
    14. Apprroaching Security Evaluation Tasks
      Defining Security Requirements
      • use system specification
      • use standards/criteria
      • use experience
      Risk Assessment
      • based on standards/criteria
      • based on experience
      Theoretical Evaluation
      • of functionality required
      • to assurance level needed
      Practical Testing
      • of code checking both normal/erroneaous usage
      Examination of the Source Code
      • for potential bugs
      Penetration
      • attempting to hack system using knowledge of it

    Risk Assessment

    1. Risk Assessment
    2. Risk Assessment - Yellow Book
    3. Risk Rating Level Table
    4. Recommended Systems
    5. Risk Analysis - DSD Gateway Certification Guide
    6. Process
    7. Asset Identification
    8. Threat & Threat Likelihood Estimation
    9. Harm Estimation
    10. Risk Assessment
    11. Required Risk & Countermeasure Rating

    Summary

    1. Summary

    Exercises

    1. Exercises

    Additional References

    For additional information, see:
  • DSD Infosec - http://www.dsd.gov.au/infosec/
  • D Gollman, "Computer Security", Wiley 1999, Ch 9 pp144-161

  • [Back to CCS3 Lectures]
    Lawrie.Brown@adfa.edu.au / 8 Feb 2001