-
36
pages
-
English
-
Documents
Description
CAPP-Compliant Security Event Audit System for Mac OS X and Fr eeBSDRobert N . M. WatsonSecurity ResearchComputer LaboratoryUniversity of CambridgeMarch 23 , 2006Introduction● Background● Common Criteria, CAP P, evaluation● What is security event audit?● Audit design and implementation considerations● Differences between UN IX and Mac OS X● F reeBSD port● OpenBS M23 Mar 2006 2Or ganizations● Apple Computer, Inc.– Tight hardware/software integration, single vendo● McAfee Research, McAfee, Inc.,– Computer security research and engineering● Primarily DoD customers, but some commercial● SAIC– Many things, but among them, evaluation lab● TrustedBSD Project– Trusted operating system extensions for F reeBSD23 Mar 2006 3Trusted Operating Systems● N otions originated in security research and development during 19 50's – 19 70's– Trustworthy and security systems for US military– Later, scope expands● Two focuses– Specific security feature sets– Assurance● 19 80's–19 9 0's “O range book”● 19 9 0's–2000's N IAP and Common Criteria (CC)23 Mar 2006 4Role of Evaluations● Security evaluations controversial– Does the evaluation address real security needs?– Is the goal more paper or a better product?– Do we know more after an evaluation?● Security evaluations are, however, a reality– Cannot sell to US DoD (and others) without evaluation– Inclusion of many necessary security features has been driven by evaluation requirements23 Mar 2006 ...
-
Publié par
-
Langue
English