Outline for March 31, 2005
Reading: §1
Discussion
A famous computer scientist once said that the only way to make a computer system secure was to put it in a box, fill the box with concrete, and drop it in the bottom of the deepest part of the ocean.
-
Under what conditions is he right?
-
Under what conditions is he wrong?
Outline
-
Basic components of computer security
-
Confidentiality
-
Integrity
-
Availability
-
Classes of threats
-
Disclosure
-
Deception
-
Disruption
-
Usurpation
-
Policy vs. mechanism
-
Policy
-
Mechanism
-
Goals of security
-
Prevention
-
Detection
-
Recovery
-
Trust and Assumptions
-
Types of mechanisms: secure, precise, broad
-
Assurance
-
Specification
-
Design
-
Implementation
-
Maintenance and operation
-
Operational Issues
-
Cost-benefit analysis
-
Risk analysis
-
Laws and customs
-
Human issues
-
Organizational problems
-
People problems
Here is a PDF version of this document.