1 of 74

DISTRIBUTED COMPUTING

Sunita Mahajan, Principal, Institute of Computer Science, MET League of Colleges, Mumbai

Seema Shah, Principal, Vidyalankar Institute of Technology, Mumbai University

© Oxford University Press 2011

2 of 74

Chapter - 10�Security In Distributed Systems

© Oxford University Press 2011

3 of 74

Topics

  • Introduction
  • Overview of security techniques
  • Secure channels
  • Access control
  • Security management
  • Case study

© Oxford University Press 2011

4 of 74

Introduction

© Oxford University Press 2011

5 of 74

Goals of computer security

  • Secrecy
  • Privacy
  • Authenticity
  • Integrity

© Oxford University Press 2011

6 of 74

Approaches to computer security

  • Physically limited access
  • Hardware mechanisms
  • Operating system mechanisms
  • Programming strategies

© Oxford University Press 2011

7 of 74

Complete security

  • External security
  • Internal security
    • User authentication
    • Access control
    • Communication security

© Oxford University Press 2011

8 of 74

Potential threats and attacks

  • Interception
  • Interruption
  • Modification
  • Fabrication

© Oxford University Press 2011

9 of 74

Security mechanisms

  • Encryption
  • Authentication
  • Authorization
  • Auditing tools
  • Intruder : person/program vying for unauthorized access to data

© Oxford University Press 2011

10 of 74

Attacks

  • Passive attacks
  • Browsing
  • Inferencing
  • Masquerading

  • Active attacks
  • Virus
  • Worm
  • Logic bomb
  • Integrity attack
  • Authenticity attack
  • Delay attack
  • Replay attack
  • Denial attack

© Oxford University Press 2011

11 of 74

Categories of Virus-1

(Continued in next slide)

© Oxford University Press 2011

12 of 74

Categories of Virus-2

© Oxford University Press 2011

13 of 74

Virus vs worm

© Oxford University Press 2011

14 of 74

Integrity Attack

© Oxford University Press 2011

15 of 74

Authenticity attack

A

© Oxford University Press 2011

16 of 74

Denial attack

© Oxford University Press 2011

17 of 74

Delay attack

© Oxford University Press 2011

18 of 74

Replay attack

© Oxford University Press 2011

19 of 74

Confinement problems

© Oxford University Press 2011

20 of 74

Types of channels

  • Legitimate channel
  • Storage channel
  • Covert channel

© Oxford University Press 2011

21 of 74

Design issues

  • Minimum privilege
  • Fail safe defaults
  • Build it into the system
  • Check for current authority
  • Easy grant and revocation of access rights
  • Build firewalls
  • Cost effectiveness
  • Simplicity

© Oxford University Press 2011

22 of 74

Focus of control

  • Protection against invalid operations on secure data
  • Protection against unauthorized invocations
  • Protection against unauthorized users

© Oxford University Press 2011

23 of 74

Protection

© Oxford University Press 2011

24 of 74

Layering of security systems

Application

© Oxford University Press 2011

25 of 74

RISSC

© Oxford University Press 2011

26 of 74

Cryptography

© Oxford University Press 2011

27 of 74

Basic operations: �Encryption and decryption

© Oxford University Press 2011

28 of 74

Types

  • Symmetric cryptosystem
  • Asymmetric cryptosystem
  • Using Hash function

© Oxford University Press 2011

29 of 74

DES algorithm

© Oxford University Press 2011

30 of 74

DES Key generation

© Oxford University Press 2011

31 of 74

Needham –Schroeder algorithm

  • Needham –Schroeder Symmetric key protocol
  • Needham –Schroeder public key protocol

© Oxford University Press 2011

32 of 74

Asymmetric cryptosystem

© Oxford University Press 2011

33 of 74

RSA protocol

  • Key generation
  • Encryption of message
  • Decryption of message
  • Digital signing
  • Signature verification

Alice’s

public key

© Oxford University Press 2011

34 of 74

Hash function MD5

© Oxford University Press 2011

35 of 74

MD5

© Oxford University Press 2011

36 of 74

Secure Channels

© Oxford University Press 2011

37 of 74

Authentication

  • User login authentication
  • One way authentication of communicating entities
  • Two way authentication of communicating entities

© Oxford University Press 2011

38 of 74

User log in authentication

  • Maintain secrecy of passwords
  • Make passwords difficult to guess
  • Limit damage due to a compromised password
  • Identify and discourage unauthorized login
  • Adopt Single sign-on policy for using system resources

© Oxford University Press 2011

39 of 74

One way authentication of communicating entities

  • Protocols based on symmetric cryptosystems
  • Protocols based on asymmetric cryptosystems

© Oxford University Press 2011

40 of 74

Two way authentication of communicating entities

KS+

© Oxford University Press 2011

41 of 74

Authentication

© Oxford University Press 2011

42 of 74

Message Integrity and Confidentiality

  • Digital signature

© Oxford University Press 2011

43 of 74

Using message digest

  • Session key

© Oxford University Press 2011

44 of 74

Secure group communication

  • Confidential group communication
  • Secure replicated servers

© Oxford University Press 2011

45 of 74

Access Control

© Oxford University Press 2011

46 of 74

General issues

© Oxford University Press 2011

47 of 74

Protection domains �Domain is an abstract definition of a set of access rights

© Oxford University Press 2011

48 of 74

Realizing domains

  • Each user has a domain
  • Each process has a domain
  • Each procedure has a domain
  • Domains may be disjoint

© Oxford University Press 2011

49 of 74

Hierarchical grouping

© Oxford University Press 2011

50 of 74

Access matrix

© Oxford University Press 2011

51 of 74

Issues in representing protection state

  • Deciding the contents of the access matrix
  • Validating access to objects by subjects
  • Allowing subjects to switch domains in a controlled manner
  • Allowing changes in the protection state of the system in a controlled manner

© Oxford University Press 2011

52 of 74

Access matrix- 1

© Oxford University Press 2011

53 of 74

Access matrix-2

© Oxford University Press 2011

54 of 74

Implementation of Access Matrix

  • Access Control Lists (ACL)
    • Access validation,
    • Granting rights
    • Passing rights
    • Revoking rights
  • Capabilities

© Oxford University Press 2011

55 of 74

Firewalls

© Oxford University Press 2011

56 of 74

Secure mobile code

  • Protecting an agent
  • Protecting the target

© Oxford University Press 2011

57 of 74

Sandbox

© Oxford University Press 2011

58 of 74

Java object references as capabilities

© Oxford University Press 2011

59 of 74

Stack introspection

© Oxford University Press 2011

60 of 74

Security Management

© Oxford University Press 2011

61 of 74

Key management

  • Key establishment
  • Diffe-Hellman key exchange

© Oxford University Press 2011

62 of 74

Key distribution

  • Key distribution in symmetric cryptosystem
    • Centralized approach
    • Fully distributed approach
    • Partially distributed approach
  • Key distribution in asymmetric cryptosystem
  • Lifetime certificates

© Oxford University Press 2011

63 of 74

Issues in key distribution

Baby

© Oxford University Press 2011

64 of 74

  • Secure group management
    • Have a group of secure servers
    • Use KDCs and CAs
  • Authorization management
    • Grant access rights to a user group
    • Use capabilities to get access rights
    • Capability is a list of ordered pairs, associated with a domain and defines all objects to which a domain has access rights

© Oxford University Press 2011

65 of 74

Capabilities

  • Access validation
  • Granting and passing rights
  • Protecting capabilities against unauthorized access
  • Rights amplification
  • Rights revocation
  • Hybrid approach

© Oxford University Press 2011

66 of 74

Delegation of access rights-1

© Oxford University Press 2011

67 of 74

Delegation of access rights-2

© Oxford University Press 2011

68 of 74

Case Study

© Oxford University Press 2011

69 of 74

Kerberos system-1

© Oxford University Press 2011

70 of 74

Kerberos system-2

© Oxford University Press 2011

71 of 74

Kerberos-3

© Oxford University Press 2011

72 of 74

Kerberos-4

© Oxford University Press 2011

73 of 74

Epayment

  • Methods
  • Secure electronic transactions
    • Open standard for protecting the privacy and ensuring the authenticity of electronic transactions
  • Major technologies used are
    • DES for confidentiality of information
    • RSA for data integrity
    • Digital signatures with SHA-1 hash code

© Oxford University Press 2011

74 of 74

Summary

  • Introduction
  • Overview of security techniques
  • Secure channels
  • Access control
  • Security management
  • Case study

© Oxford University Press 2011