Consider now the inheritance of properties of new processes

Assignment Help Computer Network Security
Reference no: EM13331408

1)  Chapter 18 (pgs. 494-495) -Problem#7
A company develops a new security product using the extreme programming software development methodology. Programmers code, then test, the en add more code, then test, and continue this iteration. Every day they test the code base as a whole. The programmers work in pairs when writing code to ensure that at least two people review the code. How would you explain to this company how their software is in fact not high assurance" software?

2)  Chapter 22 (pgs. 642-643) -Problem#2
Consider how a system with capabilities as its access control mechanism could deal with Trojan Horses.

A) In general, do capabilities offer more or less protection against Trojan horses than do access control lists? Justify your answer in light of the theoretical equivalence of ACLs and C-Lists

B) Consider now the inheritance of properties of new processes. If the creator controls which capabilities the created process is given initially, how could the creator limit a damage that a Trojan Horse will do?

C) Can capabilities protect against all Trojan Horses? Either show that they can or describe a Trojan horse process that can C-Lists cannot protect against

3)  Chapter 22 (pgs. 642-643) -Problem#12
Assume that the Clark -Wilson model is implemented on a computer system. Could a computer virus that scrambled constrained data items be introduced into the system? Why or why not? Specifically, if not identify the precise control that would prevent the virus from being introduced, and explain why it would prevent the virus from being introduced; if yes identify the specific control or controls that would allow the virus to be introduced and explain why they fail to keep it out.

4)  Chapter 23 (pgs. 685-687) -Problem#1
Classify the following vulnerabilities using the RISOS model. Assume that the classification is for the implementation level. Justify your answer:
a)The presence of the wiz command in the sendmail program(see Sect. 23.2.8)
b) The failure to handle the IFS shell variable by loadmodule(see section 23.2.8)
c) The failure to select an Administrator password that was difficult to guess(see sect. 23.2.9)
d)The failure of the Burroughs system to detect offline changes to files(see section 23.2.3.6)

5) Chapter 23 (pgs. 685-687) -Problem#4
A common error in the UNIX system occurs during configuration of bind, a directory name server. The time-to-expire field is set at 0.5 because the administrator believes that this field unit is minutes (and wishes to set the time to 30 seconds) However, bind expects the field to be in seconds and reads the value as 0 - meaning that no data is ever expired.
a) Classify this vulnerability using the RISOS model, and justify your answer
b) Classify this vulnerability using the PA model and justify your answer
c) Classify this vulnerability using the Aslam's model and justify your answer

6)  Essay Question:Secure software certification. Your present company (assignment#2) is at EAL4. You are the new program manager on this effort and your job is to bring your present software secure package to EAL7. Explain to me your management plan on upgrading your present software package from EAL4 to EAL7. Your management plan should include discussing your past documentation (assignment#2), the difference between EAL4 and EAL7, what additional paperwork will be needed to reach EAL7 certification, and finally, define your risk based on reusing software code for this migration from EAL4 to EAL7 certification.

Reference no: EM13331408

Questions Cloud

How system with capabilities as its access control mechanism : In general, do capabilities offer more or less protection against Trojan horses than do access control lists? Justify your answer in light of the theoretical equivalence of ACLs and C-Lists.
Do such duopolists produce pareto efficient level of output : Consider two firms that act as Cournot competitors and face the inverse demand function p(.), where p'(Y1 + Y2) 0 i = 1,2.
How their software is in fact not high assurance software : How would you explain to this company how their software is in fact not high assurance" software?
Explain the h+ ion concentration in an aqueous solution : If the H+ ion concentration in an aqueous solution at 25.0 °C is measured as 6.6 x 10-4 M, then the pH is 1) 3.00 2) 3.18 3) 6.60 4) 9.55 5) 10.82
Consider now the inheritance of properties of new processes : Consider how a system with capabilities as its access control mechanism could deal with Trojan Horses.
Why might this news not be as good as they suggest : In a 1990 article assessing the 1980's, Time reported that: "The good news is that U.S. gross national product doubled during the 1980s, from $2.7 trillion to $5.3 trillion." The GNP number they refer to is nominal GNP. Why might this news not be as ..
Show a favorable balance sheet : Cash receipts recorded in the December cash book totaled $45,640, of which $28,000 represents cash sales, and $17,640 represents collections on account for which cash discounts of $360 were given.
Explain The bf3 molecule acts as a lewis acid : the BF3 molecule acts as a Lewis acid, accepting an electron pair from the F- ion to form a coordinate covalent bond. 5) the BF3 molecule acts as a Lewis base, donating an electron pair to the F- ion to form a coordinate covalent bond.
Explain accepting a proton from the bf3 molecule : NH3 can react with BF3, forming NH3¾BF3. In this reaction, 1) NH3 acts as a Brønsted base, accepting a proton from the BF3 molecule. 2) NH3 acts as a Lewis base, donating a proton to the BF3 molecule

Reviews

Write a Review

Computer Network Security Questions & Answers

  Basic function / purpose of a firewall

What is the basic function / purpose of a firewall? What are some different firewall implementations (stateful inspection, dual-homed, etc) and how might an organization use firewalls

  Concept of subletting in v6

small package routing is more efficient in IPV6 than in IPV4, increase the hacking factor, network security model (NSM), ACL, VLAN, war dialing

  Desktop publishing system

Consider a desktop publishing system used to produce documents for various organizations. a. Give an example of a type of publication for which confidentiality of the stored data is the most important requirement

  Identify the responsibilities of a project manager

Identify the responsibilities of a Project manager when participating in a real world project and define the role of management in projects, particularly from the view point of the practitioner as a member of the project team;

  Calculate the crc or fcs for the sender

The pattern or generator is P 1001. Calculate the CRC or FCS for the sender. You must give the details of this calculation.

  What is the encrypted message entropy

Consider the following plaintext message: FAIN 460 9043 IS A GRADUATE COURSE.

  Implement the cipher as a class

Implement the cipher as a class which implements the provided interface.

  Computing the value of shared secret key

You begin the session by sending Bob your calculated value of TA. Bob responds by sending you the value TB = 291. What is the value of your shared secret key?

  Computing decryption function and recovered plaintext

Decrypt to recover the plaintext. What is the decryption function, and the recovered plaintext? What type of cipher is this?

  Apply division method to calculate hash value of character

How can we apply division method to calculate hash value of character string without using more than constant number of words of storage outside string itself?

  Define ethics for the information age

Define ethics for the information age; cite your sources. You may use any original works but may not discuss your answers with fellow classmates.

  Will your file system of choice provide security

What type of OS to use along with the file system and why is this architecture is better than others? Will you use the same OS for servers and Desktops? Will your file system of choice provide security?

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd