![Chapter-01PPT課件_第1頁](http://file2.renrendoc.com/fileroot_temp3/2021-10/22/adfe30d6-def2-4c1d-9928-c46919dafbef/adfe30d6-def2-4c1d-9928-c46919dafbef1.gif)
![Chapter-01PPT課件_第2頁](http://file2.renrendoc.com/fileroot_temp3/2021-10/22/adfe30d6-def2-4c1d-9928-c46919dafbef/adfe30d6-def2-4c1d-9928-c46919dafbef2.gif)
![Chapter-01PPT課件_第3頁](http://file2.renrendoc.com/fileroot_temp3/2021-10/22/adfe30d6-def2-4c1d-9928-c46919dafbef/adfe30d6-def2-4c1d-9928-c46919dafbef3.gif)
![Chapter-01PPT課件_第4頁](http://file2.renrendoc.com/fileroot_temp3/2021-10/22/adfe30d6-def2-4c1d-9928-c46919dafbef/adfe30d6-def2-4c1d-9928-c46919dafbef4.gif)
![Chapter-01PPT課件_第5頁](http://file2.renrendoc.com/fileroot_temp3/2021-10/22/adfe30d6-def2-4c1d-9928-c46919dafbef/adfe30d6-def2-4c1d-9928-c46919dafbef5.gif)
版權說明:本文檔由用戶提供并上傳,收益歸屬內容提供方,若內容存在侵權,請進行舉報或認領
文檔簡介
1、The art of war teaches us to rely not on the likelihood of the enemys not coming, but on our own readiness to receive him; not on the chance of his not attacking, but rather on the fact that we have made our position unassailable. The Art of War, Sun Tzu第1頁/共22頁The combination of space, time, and st
2、rength that must be considered as the basic elements of this theory of defense makes this a fairly complicated matter. Consequently, it is not easy to find a fixed point of departure. On War, Carl Von Clausewitz第2頁/共22頁Computer Security the protection afforded to an automated information system in o
3、rder to attain the applicable objectives of preserving the integrity, availability and confidentiality of information system resources (includes hardware, software, firmware, information/data, and telecommunications)第3頁/共22頁Key Security Concepts第4頁/共22頁Levels of Impact can define 3 levels of impact
4、from a security breach Low Moderate High第5頁/共22頁Examples of Security Requirements confidentiality student grades integrity patient information availability authentication service第6頁/共22頁Computer Security Challenges第7頁/共22頁OSI Security Architecture ITU-T X.800 “Security Architecture for OSI” defines
5、a systematic way of defining and providing security requirements for us it provides a useful, if abstract, overview of concepts we will studyM acintosh P IC Tim age form atis not supported第8頁/共22頁Aspects of Security consider 3 aspects of information security: security attack security mechanism secur
6、ity service note termsthreat a potential for violation of securityattack an assault on system security, a deliberate attempt to evade security services第9頁/共22頁Passive Attacks第10頁/共22頁Active Attacks第11頁/共22頁Security Service enhance security of data processing systems and information transfers of an o
7、rganization intended to counter security attacks using one or more security mechanisms often replicates functions normally associated with physical documents which, for example, have signatures, dates; need protection from disclosure, tampering, or destruction; be notarized or witnessed; be recorded
8、 or licensed第12頁/共22頁Security Services X.800:“a service provided by a protocol layer of communicating open systems, which ensures adequate security of the systems or of data transfers” RFC 2828:“a processing or communication service provided by a system to give a specific kind of protection to syste
9、m resources”第13頁/共22頁Security Services (X.800) Authentication - assurance that communicating entity is the one claimed have both peer-entity & data origin authentication Access Control - prevention of the unauthorized use of a resource Data Confidentiality protection of data from unauthorized disclo
10、sure Data Integrity - assurance that data received is as sent by an authorized entity Non-Repudiation - protection against denial by one of the parties in a communication Availability resource accessible/usable第14頁/共22頁Security Mechanism feature designed to detect, prevent, or recover from a securit
11、y attack no single mechanism that will support all services required however one particular element underlies many of the security mechanisms in use: cryptographic techniques hence our focus on this topic第15頁/共22頁Security Mechanisms (X.800)specific security mechanisms: encipherment, digital signatur
12、es, access controls, data integrity, authentication exchange, traffic padding, routing control, notarizationpervasive security mechanisms: trusted functionality, security labels, event detection, security audit trails, security recovery第16頁/共22頁Model for Network Security第17頁/共22頁Model for Network Se
13、curityusing this model requires us to: ldesign a suitable algorithm for the security transformation lgenerate the secret information (keys) used by the algorithm ldevelop methods to distribute and share the secret information 1.specify a protocol enabling the principals to use the transformation and
14、 secret information for a security service 第18頁/共22頁Model for Network Access Security第19頁/共22頁Model for Network Access Securityusing this model requires us to: lselect appropriate gatekeeper functions to identify users 1.implement security controls to ensure only authorised users access designated information or resources 第20頁/共22頁Summary topic
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯(lián)系上傳者。文件的所有權益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網頁內容里面會有圖紙預覽,若沒有圖紙預覽就沒有圖紙。
- 4. 未經權益所有人同意不得將文件中的內容挪作商業(yè)或盈利用途。
- 5. 人人文庫網僅提供信息存儲空間,僅對用戶上傳內容的表現方式做保護處理,對用戶上傳分享的文檔內容本身不做任何修改或編輯,并不能對任何下載內容負責。
- 6. 下載文件中如有侵權或不適當內容,請與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準確性、安全性和完整性, 同時也不承擔用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。
最新文檔
- 農村殘疾申請書
- 2025年企業(yè)兼職講師市場營銷合作協(xié)議
- 2025年紫水晶玉墜行業(yè)深度研究分析報告
- 2025年度智慧城市建設項目建筑工程三方協(xié)議合同范本
- 2025年度國際貿易實務磋商及合同簽訂爭議解決合同
- 2025年度健康養(yǎng)老產業(yè)借款分紅合同書
- 2025年度跨境電商貨運保險服務合同
- 2025年度半導體產業(yè)貸款擔保合同
- 2025年度大型體育賽事組織服務合同
- 2025年度果園農產品出口貿易代理合同
- 學校保潔服務投標方案(技術標)
- 青島中國(山東)自由貿易試驗區(qū)青島片區(qū)(青島前灣綜合保稅區(qū))管理委員會選聘35人筆試歷年參考題庫附帶答案詳解
- 《社區(qū)工作者培訓課件 新浪版》
- 教育信息化背景下的學術研究趨勢
- 人教版小學數學(2024)一年級下冊第五單元100以內的筆算加、減法綜合素養(yǎng)測評 B卷(含答案)
- 2024年度體育賽事贊助合同:運動員代言與贊助權益2篇
- 智研咨詢發(fā)布:2024年中國新疫苗行業(yè)市場現狀、發(fā)展概況、未來前景分析報告
- 2025屆西藏林芝一中高三第二次診斷性檢測英語試卷含解析
- 中國傳統(tǒng)文化非遺文化中國剪紙介紹2
- 藥企銷售總經理競聘
- 開封市第一屆職業(yè)技能大賽健康照護項目技術文件(國賽)
評論
0/150
提交評論