Damiani | Open Source Systems Security Certification | E-Book | www.sack.de
E-Book

E-Book, Englisch, 204 Seiten

Damiani Open Source Systems Security Certification


1. Auflage 2008
ISBN: 978-0-387-77324-7
Verlag: Springer-Verlag
Format: PDF
Kopierschutz: Adobe DRM (»Systemvoraussetzungen)

E-Book, Englisch, 204 Seiten

ISBN: 978-0-387-77324-7
Verlag: Springer-Verlag
Format: PDF
Kopierschutz: Adobe DRM (»Systemvoraussetzungen)



Open Source Systems Security Certification discusses Security Certification Standards and establishes the need to certify open source tools and applications. This includes the international standard for the certification of IT products (software, firmware and hardware) Common Criteria (ISO/IEC 15408) (CC 2006), a certification officially adopted by the governments of 18 nations.

Without security certification, open source tools and applications are neither secure nor trustworthy. Open Source Systems Security Certification addresses and analyzes the urgency of security certification for security-sensible markets, such as telecommunications, government and the military, through provided case studies.

This volume is designed for professionals and companies trying to implement an Open Source Systems (OSS) aware IT governance strategy, and SMEs looking to attract new markets traditionally held by proprietary products or to reduce costs. This book is also suitable for researchers and advanced-level students.



Damiani Open Source Systems Security Certification jetzt bestellen!

Autoren/Hrsg.


Weitere Infos & Material


1;Foreword;6
2;Acknowledgements;10
3;Contents;11
4;Acronyms;15
5;Introduction;18
5.1;1.1 Context and motivation;18
5.2;1.2 Software certification;21
5.2.1;1.2.1 Certification vs. standardization;22
5.2.2;1.2.2 Certification authorities;22
5.3;1.3 Software security certification;23
5.3.1;1.3.1 The state of the art;25
5.3.2;1.3.2 Changing scenarios;26
5.4;1.4 Certifying Open source;26
5.5;1.5 Conclusions;29
5.6;References;29
6;Basic Notions on Access Control;31
6.1;2.1 Introduction;31
6.2;2.2 Access Control;33
6.2.1;2.2.1 Discretionary Access Control;34
6.2.2;2.2.2 Mandatory Access Control;35
6.2.3;2.2.3 Role Based Access Control;40
6.3;2.3 Conclusions;40
6.4;References;41
7;Test based security certifications;42
7.1;3.1 Basic Notions on Software Testing;42
7.1.1;3.1.1 Types of Software Testing;45
7.1.2;3.1.2 Automation of Test Activities;49
7.1.3;3.1.3 Fault Terminology;49
7.1.4;3.1.4 Test Coverage;51
7.2;3.2 Test-based Security Certification;52
7.2.1;3.2.1 The Trusted Computer System Evaluation Criteria ( TCSEC) standard;54
7.2.2;3.2.2 CTCPEC;61
7.2.3;3.2.3 ITSEC;61
7.3;3.3 The Common Criteria : A General Model for Test- based Certification;62
7.3.1;3.3.1 CC components;63
7.4;3.4 Conclusions;74
7.5;References;75
8;Formal methods for software verification;77
8.1;4.1 Introduction;77
8.2;4.2 Formal methods for software verification;79
8.2.1;4.2.1 Model Checking;79
8.2.2;4.2.2 Static Analysis;83
8.2.3;4.2.3 Untrusted code;87
8.2.4;4.2.4 Security by contract;88
8.3;4.3 Formal Methods for Error Detection in OS C-based Software;89
8.3.1;4.3.1 Static Analysis for C code verification;90
8.3.2;4.3.2 Model Checking for large-scale C-based Software verification;95
8.3.3;4.3.3 Symbolic approximation for large-scale OS software verification;97
8.4;4.4 Conclusion;100
8.5;References;100
9;OSS security certification;103
9.1;5.1 Open source software (OSS);103
9.1.1;5.1.1 Open Source Licenses;104
9.1.2;5.1.2 Specificities of Open Source Development;107
9.2;5.2 OSS security;111
9.3;5.3 OSS certification;113
9.3.1;5.3.1 State of the art;114
9.4;5.4 Security driven OSS development;118
9.5;5.5 Security driven OSS development: A case study on Single Sign- On;119
9.5.1;5.5.1 Single Sign-On: Basic Concepts;119
9.5.2;5.5.2 A ST-based definition of trust models and requirements for SSO solutions;121
9.5.3;5.5.3 Requirements;130
9.5.4;5.5.4 A case study: CAS++;132
9.6;5.6 Conclusions;135
9.7;References;136
10;Case Study 1: Linux certification;139
10.1;6.1 The Controlled Access Protection Profile and the SLES8 Security Target;139
10.1.1;6.1.1 SLES8 Overview;140
10.1.2;6.1.2 Target of Evaluation (TOE);141
10.1.3;6.1.3 Security environment;142
10.1.4;6.1.4 Security objectives;143
10.1.5;6.1.5 Security requirements;144
10.2;6.2 Evaluation process;146
10.2.1;6.2.1 Producing the Evidence;147
10.3;6.3 The Linux Test Project;148
10.3.1;6.3.1 Writing a LTP test case;149
10.4;6.4 Evaluation Tests;155
10.4.1;6.4.1 Running the LTP test suite;155
10.4.2;6.4.2 Test suite mapping;156
10.4.3;6.4.3 Automatic Test Selection Example Based on SLES8 Security Functions;160
10.5;6.5 Evaluation Results;162
10.6;6.6 Horizontal and Vertical reuse of SLES8 evaluation ;163
10.6.1;6.6.1 Across distribution extension;163
10.6.2;6.6.2 SLES8 certification within a composite product;165
10.7;6.7 Conclusions;167
10.8;References;167
11;Case Study 2: ICSA and CCHIT Certifications;169
11.1;7.1 Introduction;169
11.2;7.2 ICSA Dynamic Certification Framework;171
11.3;7.3 A closer look to ICSA certification;172
11.3.1;7.3.1 Certification process;172
11.4;7.4 A case study: the ICSA certification of the Endian firewall;173
11.5;7.5 Endian Test Plan ;175
11.5.1;7.5.1 Hardware configuration;175
11.5.2;7.5.2 Software configuration;175
11.5.3;7.5.3 Features to test;175
11.5.4;7.5.4 Testing tools;177
11.6;7.6 Testing ;178
11.6.1;7.6.1 Configuration;178
11.6.2;7.6.2 Logging;179
11.6.3;7.6.3 Administration;180
11.6.4;7.6.4 Security testing;180
11.7;7.7 The CCHIT certification;182
11.7.1;7.7.1 The CCHIT certification process;184
11.8;7.8 Conclusions;184
11.9;References;185
12;The role of virtual testing labs;186
12.1;8.1 Introduction;186
12.2;8.2 An Overview of Virtualization Internals;189
12.2.1;8.2.1 Virtualization Environments;190
12.2.2;8.2.2 Comparing technologies;192
12.3;8.3 Virtual Testing Labs;193
12.3.1;8.3.1 The Open Virtual Testing Lab;193
12.3.2;8.3.2 Xen Overview;194
12.3.3;8.3.3 OVL key aspects;194
12.3.4;8.3.4 Hardware and Software Requirements;195
12.3.5;8.3.5 OVL Administration Interface;197
12.4;8.4 Using OVL to perform LTP tests;197
12.5;8.5 Conclusions;199
12.6;References;199
13;Long-term OSS security certifications: An Outlook;200
13.1;9.1 Introduction;200
13.2;9.2 Long-term Certifications;202
13.2.1;9.2.1 Long-lived systems;202
13.2.2;9.2.2 Long-term certificates;203
13.3;9.3 On-demand certificate checking;205
13.4;9.4 The certificate composition problem;207
13.5;9.5 Conclusions;208
13.6;References;209
14;An example of a grep-based search/match phase;211
15;Index;212



Ihre Fragen, Wünsche oder Anmerkungen
Vorname*
Nachname*
Ihre E-Mail-Adresse*
Kundennr.
Ihre Nachricht*
Lediglich mit * gekennzeichnete Felder sind Pflichtfelder.
Wenn Sie die im Kontaktformular eingegebenen Daten durch Klick auf den nachfolgenden Button übersenden, erklären Sie sich damit einverstanden, dass wir Ihr Angaben für die Beantwortung Ihrer Anfrage verwenden. Selbstverständlich werden Ihre Daten vertraulich behandelt und nicht an Dritte weitergegeben. Sie können der Verwendung Ihrer Daten jederzeit widersprechen. Das Datenhandling bei Sack Fachmedien erklären wir Ihnen in unserer Datenschutzerklärung.