Classify the following vulnerabilities using the risos model

Assignment Help Basic Computer Science
Reference no: EM13712168 , Length: 3900 Words

The book that we use is Computer Security Art and Science by Matt Bishop. Each answer should be from 600- 900 words.

Answer the following questions.

1)(12 pts.) Chapter 18 (pgs. 494-495) -Problem#7

A company develops a new security product using the extreme programming software development methodology. Programmers code, then test, then add more code, then test, and continue this iteration. Every day, they test the code base as a whole. The programmers work in pairs when writing code to ensure that al least two people review the code. The company does not adduce any additional evidence of assurance. How would explain to the management of this company why their software is in fact not "High-assurance" software?

2) (15 pts.) Chapter 22 (pgs. 642-643) -Problem#2

Consider how a system with capabilities as its access control mechanism could deal with Trojan horses.

  1. In general, do capabilities offer more or less protection against Trojan horses than do access control lists? Justify you answer in light of the theoretical equivalence of ACLs and C-Lists.
  2. Consider now the inheritance properties of new processes. If the creator controls which capabilities the created process is given initially, how could the creator limit the damage that a Trojan horse could do?
  3. Can capabilities protect against all Trojan horses? Either show that they can or describe a Trojan horse process that C-Lists cannot protect against.

3) (18 pts.) Chapter 22 (pgs. 642-643) -Problem#12

Assume that the Clark- Wilson model is implemented on a computer system. Could a computer virus that scrambled constrained data items be introduced into the system? Why or why not? Specifically, if not, identify the precise control that would prevent the virus from being introduced, and explain why it would prevent the virus from being introduced; if yes, identify the specific control or controls that would allow the virus to be introduced and explain why they fail to keep it out.

 

4) (20 pts.) Chapter 23 (pgs. 685-687) -Problem#1

Classify the following vulnerabilities using the RISOS model. Assume that the classification is for the implementation level. Justify your answer.

  1. The presence of the "wiz" command in the sendmail program (see Section 23.2.8)
  2. The failure to handle the IFS shel variable by loadmodule. (see Section 23.2.8).
  3. The failure to select an Administrator password that was difficult to guess. (see Section 23.2.9).
  4. The failure of the Burroughs system to detect offline changes to files (see Section 23.2.6).

5) (15 pts.) Chapter 23 (pgs. 685-687) -Problem#4

A common error on UNIX systems occurs during the configuration of bind, and directory name server. The time-to-expire field is set at 0.5 because the administrator believes that this fields unit is minutes (and wishes to set the time to 30 seconds). However, bind expects the field to be in seconds and reads the value as 0- meaning that no data is ever expired.

  1. Classify this vulnerability using the RISOS model, and justify your answer
  2. Classify this vulnerability using the PA model, and justify your answer.
  3. Classify this vulnerability using Aslam's model, and justify your answer,

Reference no: EM13712168

Questions Cloud

Single-stage ideal regenerative steam cycle : A single-stage ideal regenerative steam cycle has a boiler pressure and temperature of 5000 kPa and 500 C, and a condensing pressure of 10 kPa. The extraction pressure is 500 kPa.
What is the apparent gravity at the counterweight : Space stations don't need to be round to have artificial gravity. The tethered spacecraft in the diagram to the right represents an alternative design. Put the astronauts in a passenger capsule. (Put the "spam in a can" as they say.) Tether it to a h..
Oil has a specific gravity : Oil flows at a rate of 12gpm from a vented tank (pressure at point 1 is zero) through 1 inch inner diameter pipes and elbows, and through a pump and motor as shown. The pump adds HHPp= 3hp to and the motor extracts HHPm= 1hp from the fluid power.
Solar energy impinging on outer layer of earth’s atmosphere : Solar energy impinging on the outer layer of earth’s atmosphere (usually called “solar constant”) has been measured as 1367W/m^2. What is the solar constant on Mars
Classify the following vulnerabilities using the risos model : Classify the following vulnerabilities using the RISOS model. Assume that the classification is for the implementation level. Justify your answer.
Calculate the minimum amount of energy : Calculate the minimum amount of energy, in joules, required to completely melt 102 g of silver initially at 42.0°C. The melting point of silver is at 962°C.
What is the length of the rod : An aluminum-alloy rod has a length of 10.380 cm at 24.00°C and a length of 10.423 cm at the boiling point of water.
What is the acceleration of the heavier object : An unspecified force causes a 0.1-kg object to accelerate at 0.3 m/s2. If 0.4 kg is added to the 0.1-kg object and the force remains the same.
What is the acceleration of the heavier object : An unspecified force causes a 0.1-kg object to accelerate at 0.3 m/s2. If 0.4 kg is added to the 0.1-kg object and the force remains the same.

Reviews

Write a Review

Basic Computer Science Questions & Answers

  Information of all the processes pointed by init

Print some information of all the processes pointed by init_task, something similiar to "ps -ef", including UID, PID, PPID, thread name, etc.

  Create an object-oriented java web application

Create an object-oriented Java Web application that: a. displays the entire product inventory to the screen, including the product ID, name, description, and quantity. b. allows for a product to be searched by the product ID or product name.

  Show that curve lies lies on intersection of the cylinders

show that the curve lies lies on the intersection of the cylinders y=[2(z+1)^2]/9 and x=[(z+1)^4]/81

  Creating procedure to allow receiving clerk to add movies

Create a procedure which will allow the receiving clerk to add the new movies received to the mm_movie table.

  What effect does font selection have on readability

What effect does font selection have on readability and the viewer's perception and How does the use of font further or hinder the intended message?

  Write a program that prompts the user for an integer value

write a program that prompts the user for an integer value for a length of a youtube clip in seconds then display the number of hours

  Write a segment of java code that will rotate the elements

Write a segment of Java code that will rotate the elements of an array by one position, moving the initial element to the end, like.

  Create circuit at gate level to calculate function

Create the circuit at gate level to calculate the following function: if (a=b)y=a; else y=0;.let a,b and y be 16 bit buses. Suppose input and output capacitances are each 10 units.

  Maintain multiple databases for the two companies

Maintain multiple databases for the two companies

  Why are you normally required to bind a service

What steps need to be taken by a network service to be ready to receive TCP/IP connections? Why are you normally required to bind a service to a specific port?

  Write some code that exchanges their values

There are two string variables, s1 and s2, that have already been declared and initialized, write some code that exchanges their values.

  How digital media has changed core business processes

Digital media has changed the ways ideas, information, and arguments in society are communicated both locally and globally. Individuals and organizations frequently use digital media as a means to influence individuals and organizations.

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd