1.1 Information Security of a Modern State
9
VPN module, ensuring the protection of the traffic transmitted between sections of
the network.
The development of firewalls was completely different from the development of
antivirus software. If the latter evolved from personal protection to the protection of
entire networks, the former—the other way around. For a long time, no one could
even think that a firewall was able to protect something else besides the corporate
perimeter (which is why it was called a network firewall), but with an increase in
the number of personal computers connected to the World Wide Web, the task of
protecting individual nodes gave rise to the technology of personal firewall, actively
developing at the moment. Some manufacturers have gone even further by offering
consumers application firewalls that protect not the networks or personal computers,
but the programs running on them (for instance, web server software). Prominent
representatives of this class of security tools are Check Point Firewall-1 NG with
Application Intelligence and Cisco PIX Firewall (corporate firewalls), RealSecure
Desktop Protector and Check Point SecureClient (personal firewalls), and Sanctum
AppShield (application firewalls). Russian developers offered their solutions:
Elvis + (Zastava), Jet Infosystems (Z-2 and Angara), Informzaschita (Continent-K).
1.1.5.3 Authorization and Access Control
Perimeter defense is important, but we also need to think about internal security, since
according to statistics, from 51 to 83% of all computer incidents in companies occur
through the fault of their employees, i.e., no firewalls will help. Therefore, there is
a need for authorization and access control systems, determining the exact resource
one can access, as well as the time of access. These systems are based on classical
access control models (Bell–LaPadula model, Clark–Wilson model, etc.), developed
in the 1970s—1980s and originally used in the US Department of Defense, where
the Internet was created to order.
One of the areas of protection technology of this class is authentication, matching
the user-entered password and name with the information stored in the security
database. When the input and reference data match, access to the relevant resources
is permitted. It should be noted that, apart from the password, other unique elements
possessed by the user can serve as authentication information. All these elements
can be divided into categories based on the following three principles: “Something
you know,” (classical password schemes) “something you have,” (a Touch Memory
tablet, a smart card, an eToken keychain, a proximity contact card or a SecurlD onetime password card can be a unique element) and “something you are” (a unique
element is your fingerprint, hand geometry, handwriting, voice, or retina).
1.1.5.4 Intrusion Detection and Prevention Systems
Even despite the presence of firewalls and antiviruses on the corporate network
perimeter, protective barriers are still attacked and penetrated. Such attacks are
Précédent

- 31/839

Suivant