Intro To Access Controls

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Favorites, Groups & Events

    Intro To Access Controls - Presentation Transcript

    1. Overview of Access controls Sundar N suntracks@gmail.com
    2. Access
      • A specific interaction between a subject and object resulting information flow from one to another .
      R FW R X Mail
      • Trusted computer security evaluation criteria (TCSEC) is a DOD standard 5200.28
      • It defined a standard for manufacturers and set a metrics for degree of measurement for security.
        • MAC (Mandatory access control): defined for multilevel security access generally used for military applications.
        • DAC (Discretionary access control): defined for single level access generally deployed for non military applications.
    3. MAC
      • Mandatory access control
      • Is defined in the security policy of an organization and enforced by an admin
      • Has a multilevel security level access in terms of hierarchy
      • Generally used for confidential or classified information.
      • Define the appropriate Read and write access separately to the information depending on the levels of security for each user.
      • It is more of a micromanagement
      • It is a centrally administered access.
    4. DAC
      • Discretionary access control
      • Information owner defines the access to data and type of access to it for the users.
      • It is more of a hands off approach
      • Mostly depends on the discretion of the information owner.
      • Access can be passed on from one individual to another
    5. Models
      • RBAC (Role based access controls)
      • It is non discretionary
      • Defined as per role
        • Duties
        • Responsibilities
        • Qualifications
        • Has flexibility of DAC but not as hard policies as MAC
    6. Access control administration methods
      • Centralized
      X Admin S1 S2
    7. Access control administration methods
      • Decentralized
      X S1 S2
    8. Security models
      • BELL LAPADULA (1970)
      • BIBA (1977)
      • Clark Wilson (1987)
    9. BELL LAPADULA
      • Maintain the property of the confidentiality
      • Maintain the simple security rule.
      • Do not downgrade the security levels.
      TS S C P
    10. BIBA
      • Maintain the integrity of the information
      • Follow the rules against each of the security on the information levels.
      • Maintain the property of the information
    11. Clark Wilson
      • Introduction of a middle man in the transaction from subject to the object
      • Limit the capabilities for the subject
      • Have well formed transactions to prevent manipulations .
    12. Authentication Methods
      • Username/Passwords
      • Tokens (HW/SW)
      • Biometrics (Retina/fingerprints/voice)
    13. Access Attacks
      • Protocol Analysis
      • Dos attacks (Smurf/Syn Flood/DDos)
      • Spoofing
    14. Appendix
      • Preventive access control
      • Deterrent access control
      • Detective access control
      • Corrective access control
      • Recovery access control
      • Compensation access control
      • Directive access control
      • Administrative access controls
      • Logical/technical access controls
      • Physical access controls

    + harinathpvharinathpv, 12 months ago

    custom

    550 views, 0 favs, 0 embeds more stats

    Presentation on Introduction to Access Controls by more

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 550
      • 550 on SlideShare
      • 0 from embeds
    • Comments 0
    • Favorites 0
    • Downloads 21
    Most viewed embeds

    more

    All embeds

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories