- C. Ding - COMP4631 - L02
1
Introduction to Computer Security Cunsheng Ding HKUST, Hong Kong, - - PowerPoint PPT Presentation
Introduction to Computer Security Cunsheng Ding HKUST, Hong Kong, CHINA cding@cs.ust.hk C. Ding - COMP4631 - L02 1 Outline of this Lecture A brief introduction to computer security A theoretical framework of computer security
1
2
3
4
5
6
7
8
9
10
11
12
Users Hackers Terrorists Criminals Issue Motivated Groups Foreign Intelligence || || || \/ Destroy Disrupt Modify Disclose
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
– ID + Password: Students and professors have different access rights
29
30
Application Software User (subject) Hardware Resource (object)
31
1) the format and content of data items
(authorized access)
32
33
H/W OS H.W. OS kernel OS Services Applications The Onion model of protection mechanisms
34
H/W OS H.W. OS kernel OS Services Applications
35
36
37
– If it is put at the application layer, then it is usually more complex (it can provide a higher level of security). – If it is put in the center, it is simpler and generic, but may not provide a higher level of security.
– “IPSec” can provide security for many types of data, including email data, and is thus generic. But “PGP” can provide the “sender nonrepudiation” security service.
38
39
40
41
42
43
44
45
46
47