-
28
pages
-
English
-
Documents
Description
Introduction t oTrustedBSD A udit + OpenBSMWayne Salamon(wsalamon@freebsd.org)Robert Watson(rwatson@freebsd.org)Introduction• What is T rustedB SD?• What is e vent a uditing?• CC + C AP P e valuation requirements• The BSM a udit fo rmat• Kernel c omponents• MAC -Aud it in tegration• User space components• Status a nd Av ailabilityTrustedBSD P roject● Trusted system e xtensions to FreeB SD– A nnounced A pril, 2 000● Security Infrastructure– OpenPA M– UFS2, E xtended A ttributes (EA s)– Kernel a ccess control c entralization● Security Fun ctionality– A ccess Control L ists (A CLs)– Extensible kernel a ccess control (MA C Framework)– Mandatory Access Control (MA C)– Event Auditing, OpenB SMWhat is event auditing?● Non-bypassable a udit lo g describing security relevant e vents● Security-relevant e vents– Co ntrolled operations– A uthentication related even ts– Security management events● Ap propriate fo r ma ny us es– Post-mortem– Intrusion de tection– Monitoring● Typically, variable g ranularity: selectionCommon C riteria and A udit● Aud it is ma ndated by common O S security evaluations a nd standards– CC – Common Criteria– CAP P – Common Access P rotection P rofile– EA L – E valuation Assurance Level– A va riety o f other m ore s pecific requirements● CAP P id entifies fun ctional requirements– A udit w ill p rovide c omprehensive lo gging of security ev ents defined to b e relevant to CA PP– Typically security even ts ...
-
Publié par
-
Langue
English