book Page i Tuesday, September 28, 2004 1:46 PM Introduction to Computer Security Bishop.book Page ii Tuesday, September 28, 2004 1:46 PM Bishop.book Page iii Tuesday, September 28, 2004 1:46 PM Introduction to Computer Security Matt Bishop Boston • San Francisco • New York • Toronto • Montreal London • Munich • Paris • Madrid Capetown • Sydney • Tokyo • Singapore • Mexico City Bishop.book Page iv Tuesday, September 28, 2004 2:34 PM Many of the designations used by manufacturers and sellers to distinguish their products are claimed as trade- marks. Where those designations appear in this book, and Addison-Wesley was aware of a trademark claim, the designations have been printed with initial capital letters or in all capitals. The author and publisher have taken care in the preparation of this book, but make no expressed or implied warranty of any kind and assume no responsibility for errors or omissions. No liability is assumed for inciden- tal or consequential damages in connection with or arising out of the use of the information or programs con- tained herein.
The publisher offers discounts on this book when ordered in quantity for bulk purchases and special sales. For more information, please contact: U. Corporate and Government Sales (800) 382-3419 corpsales@pearsontechgroup.com For sales outside of the U., please contact: International Sales international@pearsoned.com Visit Addison-Wesley on the Web: www.com Library of Congress Cataloging-in-Publication Data Bishop, Matt (Matthew A.) Introduction to computer security / Matt Bishop. Includes bibliographical references and index.
ISBN 0-321-24744-2 (hardcover : alk.8—dc22 2004019195 Copyright © 2005 by Pearson Education, Inc. All rights reserved. No part of this publication may be reproduced, stored in a retrieval system, or transmitted, in any form, or by any means, electronic, mechanical, photocopying, recording, or otherwise, without the prior consent of the publisher. Printed in the United States of America.
Published simultaneously in Canada. Chapters 17 and 18 Copyright 2005 by Elisabeth C. Published by Pearson Education, Inc. For information on obtaining permission for use of material from this work, please submit a written request to: Pearson Education, Inc.
Rights and Contracts Department 75 Arlington Street, Suite 300 Boston, MA 02116 Fax: (617) 848-7047 ISBN: 0-321-24744-2 Text printed on recycled paper 1 2 3 4 5 6 7 8 9 10—CRS—0807060504 First printing, October 2004 Bishop.book Page v Tuesday, September 28, 2004 1:46 PM Bishop.book Page vi Tuesday, September 28, 2004 1:46 PM To my dear Holly; our children Heidi, Steven, David, and Caroline; our grandson Skyler; our son-in-law Mike; and our friends Seaview, Tinker Belle, Stripe, Baby Windsor, Fuzzy, Scout, Fur, Puff, and the rest of the menagerie.book Page vii Tuesday, September 28, 2004 1:46 PM Contents Preface. xxix Differences Between this Book and Computer Security: Art and Science .xxx Special Acknowledgment. xxxi Chapter 1 An Overview of Computer Security.1 The Basic Components .3 Policy and Mechanism.1 Goals of Security .4 Assumptions and Trust .1 Cost-Benefit Analysis.3 Laws and Customs .8 Tying It All Together.book Page viii Tuesday, September 28, 2004 1:46 PM viii Contents Chapter 2 Access Control Matrix .2 Access Control Matrix Model .3 Protection State Transitions. 35 Chapter 3 Foundational Results .1 The General Question.
44 Chapter 4 Security Policies .2 Types of Security Policies .3 The Role of Trust .4 Types of Access Control.5 Example: Academic Computer Security Policy .1 General University Policy .2 Electronic Mail Policy.1 The Electronic Mail Policy Summary .2 The Full Policy .3 Implementation at UC Davis. 59 Chapter 5 Confidentiality Policies.1 Goals of Confidentiality Policies .2 The Bell-LaPadula Model.2 Example: The Data General B2 UNIX System .1 Assigning MAC Labels .2 Using MAC Labels .book Page ix Tuesday, September 28, 2004 1:46 PM Contents ix Chapter 6 Integrity Policies .2 Biba Integrity Model .3 Clark-Wilson Integrity Model .2 Comparison with the Requirements .3 Comparison with Other Models .82 Chapter 7 Hybrid Policies .1 Chinese Wall Model .1 Bell-LaPadula and Chinese Wall Models .2 Clark-Wilson and Chinese Wall Models .2 Clinical Information Systems Security Policy.1 Bell-LaPadula and Clark-Wilson Models .3 Originator Controlled Access Control .4 Role-Based Access Control .95 Chapter 8 Basic Cryptography.1 What Is Cryptography? .2 One-Time Pad .3 Data Encryption Standard .4 Other Classical Ciphers .3 Public Key Cryptography .book Page x Tuesday, September 28, 2004 1:46 PM x Contents Chapter 9 Key Management .1 Session and Interchange Keys .1 Classical Cryptographic Key Exchange and Authentication.3 Public Key Cryptographic Key Exchange and Authentication .3 Cryptographic Key Infrastructures .1 Certificate Signature Chains .509: Certification Signature Chains .2 PGP Certificate Signature Chains .4 Storing and Revoking Keys .2 Public Key Signatures. 142 Chapter 10 Cipher Techniques .1 Precomputing the Possible Messages .2 Stream and Block Ciphers .1 Synchronous Stream Ciphers .2 Self-Synchronous Stream Ciphers.3 Networks and Cryptography.1 Secure Electronic Mail: PEM .book Page xi Tuesday, September 28, 2004 1:46 PM Contents xi 10.2 Security at the Network Layer: IPsec.2 Authentication Header Protocol .3 Encapsulating Security Payload Protocol .1 Attacking a Password System .2 Countering Password Guessing .1 Random Selection of Passwords .2 Pronounceable and Other Computer-Generated Passwords .3 User Selection of Passwords .4 Reusable Passwords and Dictionary Attacks .5 Guessing Through Authentication Functions .2 One-Time Passwords .3 Hardware-Supported Challenge-Response Procedures .4 Challenge-Response and Dictionary Attacks .book Page xii Tuesday, September 28, 2004 1:46 PM xii Contents Chapter 12 Design Principles.1 Principle of Least Privilege .2 Principle of Fail-Safe Defaults .3 Principle of Economy of Mechanism .4 Principle of Complete Mediation .5 Principle of Open Design .6 Principle of Separation of Privilege .7 Principle of Least Common Mechanism .8 Principle of Psychological Acceptability. 208 Chapter 13 Representing Identity .1 What Is Identity?.2 Files and Objects.4 Groups and Roles .5 Naming and Certificates .1 The Meaning of the Identity .6 Identity on the Web .1 Static and Dynamic Identifiers .2 Security Issues with the Domain Name Service .2 State and Cookies .3 Anonymity on the Web .1 Anonymity for Better or Worse.
234 Chapter 14 Access Control Mechanisms .1 Access Control Lists .1 Abbreviations of Access Control Lists .2 Creation and Maintenance of Access Control Lists .1 Which Subjects Can Modify an Object’s ACL? .2 Do the ACLs Apply to a Privileged User? .3 Does the ACL Support Groups and Wildcards? .book Page xiii Tuesday, September 28, 2004 1:46 PM Contents xiii 14.5 ACLs and Default Permissions .3 Revocation of Rights .4 Example: Windows NT Access Control Lists .1 Implementation of Capabilities .2 Copying and Amplifying Capabilities .3 Revocation of Rights .4 Limits of Capabilities .5 Comparison with Access Control Lists .3 Locks and Keys .4 Ring-Based Access Control.5 Propagated Access Control Lists .259 Chapter 15 Information Flow .1 Basics and Background .1 Information Flow Models and Mechanisms.2 Compiler-Based Mechanisms .3 Exceptions and Infinite Loops .3 Execution-Based Mechanisms.1 Fenton’s Data Mark Machine.4 Example Information Flow Controls .1 Security Pipeline Interface .2 Secure Network Server Mail Guard .book Page xiv Tuesday, September 28, 2004 1:46 PM xiv Contents Chapter 16 Confinement Problem.1 The Confinement Problem .1 Detection of Covert Channels .2 Mitigation of Covert Channels. 307 Chapter 17 Introduction to Assurance .1 Assurance and Trust .1 The Need for Assurance .2 The Role of Requirements in Assurance .3 Assurance Throughout the Life Cycle.2 Building Secure and Trusted Systems .4 Fielded Product Life .2 The Waterfall Life Cycle Model .1 Requirements Definition and Analysis .2 System and Software Design .3 Implementation and Unit Testing .4 Integration and System Testing.5 Operation and Maintenance .3 Other Models of Software Development.4 System Assembly from Reusable Components .3 Building Security In or Adding Security Later.book Page xv Tuesday, September 28, 2004 1:46 PM Contents xv Chapter 18 Evaluating Systems .1 Goals of Formal Evaluation.1 Deciding to Evaluate .2 Historical Perspective of Evaluation Methodologies .1 TCSEC Functional Requirements .2 TCSEC Assurance Requirements.2 The TCSEC Evaluation Classes .3 The TCSEC Evaluation Process.2 FIPS 140-2 Security Levels .4 The Common Criteria: 1998–Present .1 Overview of the Methodology .3 CC Security Functional Requirements .5 Evaluation Assurance Levels .8 Future of the Common Criteria .2 Assurance Class AMA and Family ALC_FLR .3 Products Versus Systems .4 Protection Profiles and Security Targets.5 Assurance Class AVA.5 SSE-CMM: 1997–Present .1 The SSE-CMM Model .2 Using the SSE-CMM .book Page xvi Tuesday, September 28, 2004 1:46 PM xvi Contents Chapter 19 Malicious Logic .1 Boot Sector Infectors .5 Other Forms of Malicious Logic .1 Rabbits and Bacteria .1 Malicious Logic Acting as Both Data and Instructions.2 Malicious Logic Assuming the Identity of a User.1 Information Flow Metrics .2 Reducing the Rights .3 Malicious Logic Crossing Protection Domain Boundaries by Sharing .4 Malicious Logic Altering Files .5 Malicious Logic Performing Actions Beyond Specification .1 Proof-Carrying Code .6 Malicious Logic Altering Statistical Characteristics .7 The Notion of Trust. 386 Chapter 20 Vulnerability Analysis .2 Layering of Tests.3 Methodology at Each Layer .4 Flaw Hypothesis Methodology .book Page xvii Tuesday, September 28, 2004 1:46 PM Contents xvii 20.1 Information Gathering and Flaw Hypothesis .5 Example: Penetration of the Michigan Terminal System .6 Example: Compromise of a Burroughs System .7 Example: Penetration of a Corporate Computer System .8 Example: Penetrating a UNIX System .9 Example: Penetrating a Windows NT System .1 Two Security Flaws .1 The RISOS Study .1 The Flaw Classes .2 Protection Analysis Model .1 The Flaw Classes .3 The NRL Taxonomy .1 The Flaw Classes .1 The Flaw Classes .5 Comparison and Analysis.1 The xterm Log File Flaw .2 The fingerd Buffer Overflow Flaw.2 Anatomy of an Auditing System .3 Designing an Auditing System .book Page xviii Tuesday, September 28, 2004 1:46 PM xviii Contents 21.4 Application and System Logging .1 Auditing to Detect Violations of a Known Policy.1 State-Based Auditing.2 Transition-Based Auditing .2 Auditing to Detect Known Violations of a Policy.6 Examples: Auditing File Systems.1 Audit Analysis of the NFS Version 2 Protocol .2 The Logging and Auditing File System (LAFS). 451 Chapter 22 Intrusion Detection .2 Basic Intrusion Detection .1 Host-Based Information Gathering .2 Network-Based Information Gathering .5 Organization of Intrusion Detection Systems.1 Monitoring Network Traffic for Intrusions: NSM .2 Combining Host and Network Monitoring: DIDS .3 Autonomous Agents: AAFID .book Page xix Tuesday, September 28, 2004 1:46 PM Contents xix 22.3 Follow-Up Phase .485 Chapter 23 Network Security .1 Firewalls and Proxies .2 Analysis of the Network Infrastructure .1 Outer Firewall Configuration .2 Inner Firewall Configuration .3 In the DMZ .1 DMZ Mail Server .2 DMZ WWW Server.3 DMZ DNS Server .4 DMZ Log Server .4 In the Internal Network .5 General Comment on Assurance .4 Availability and Network Flooding .2 TCP State and Memory Allocations.513 Chapter 24 System Security .1 The Web Server System in the DMZ .2 The Development System .book Page xx Tuesday, September 28, 2004 1:46 PM xx Contents 24.1 The Web Server System in the DMZ .2 The Development System .1 The Web Server System in the DMZ .2 The Development System .1 The Web Server System in the DMZ .2 Development Network System .1 The Web Server System in the DMZ .2 The Development System .1 The Web Server System in the DMZ .2 The Development System .1 The Web Server System in the DMZ .2 The Development System.
551 Chapter 25 User Security .2 The Login Procedure .3 Leaving the System .3 Files and Devices .1 File Permissions on Creation .book Page xxi Tuesday, September 28, 2004 1:46 PM Contents xxi 25.3 Monitors and Window Systems .1 Copying and Moving Files .2 Accidentally Overwriting Files .3 Encryption, Cryptographic Keys, and Passwords .4 Start-up Settings .1 Automated Electronic Mail Processing .2 Failure to Check Certificates .3 Sending Unexpected Content .577 Chapter 26 Program Security.2 Requirements and Policy .1 Group 1: Unauthorized Users Accessing Role Accounts.2 Group 2: Authorized Users Accessing Role Accounts.2 High-Level Design .2 Access to Roles and Commands .3 Storage of the Access Control Data.4 Refinement and Implementation .1 First-Level Refinement.2 Second-Level Refinement .2 The Access Control Record .book Page xxii Tuesday, September 28, 2004 1:46 PM xxii Contents 26.3 Error Handling in the Reading and Matching Routines.5 Common Security-Related Programming Problems .1 Improper Choice of Initial Protection Domain .