You get a bonus - 1 coin for daily activity. Now you have 1 coin

11.5. Protection and operational safety characteristics of software

Lecture



The continuously increasing complexity, and consequently the vulnerability, of systems and software products to accidental and deliberate negative impacts has pushed a number of problems related to the security of systems and software tools into the category of the most important — strategic ones, determining the fundamental feasibility and effectiveness of applying software products in administrative systems, in industry, and in military technology. In this connection, two areas of analysis and assurance have emerged: information security, concerned mainly with protection against deliberate, negative impacts on the information resources of systems, and functional safety, caused by failure situations and loss of operability of systems and software tools due to unintentional, random defects and failures of programs, data, hardware, and the external environment. From the standpoint of the dominant security category, automated systems, their software products, and databases can be conditionally divided into two large classes:

— systems in which large volumes of information from the external environment are accumulated, processed, and stored with the active participation of users, for which the confidentiality, integrity, and availability of data to consumers must be ensured, which is reflected mainly in requirements for the characteristics of information security,

— systems and automation objects into whose hardware are embedded software complexes for real-time control and information processing, the main tasks of which are to ensure the reliable implementation of effective and stable control of external environment objects with relatively little (negative) participation of users in their resolution, and with high requirements for the characteristics of functional safety.

In a number of cases these two concepts and their characteristics are close and are related to a violation of the fulfillment of specification requirements for the functional suitability of the object or system; however, they have significant features that it is worth clarifying.

Ensuring information security of system operation during development and use is developing owing to the increasing complexity and responsibility of tasks involving the use of information resources and the growing vulnerability of these resources to deliberate, external impacts aimed at the unlawful use or distortion of information and programs which, by their content, are intended for use by a limited circle of persons. The main focus of modern theory and practice in ensuring the security of information systems is on protection against malicious destruction, distortion, theft, and unregulated use of software tools and the information resources of databases. To solve this problem, methods, tools, and standards for ensuring information security — protection of programs and data against deliberate negative external impacts — have been created and are being actively developed. At the same time, the concepts of ensuring security and protecting the system and information are often not distinguished. Security factors characteristic of complex information systems — the integrity, availability, and confidentiality of information resources, as well as a number of standard procedures of protection systems — cryptographic support, identification and authentication, and the protection and preservation of user data under deliberate negative external impacts from the external environment — are not further considered or taken into account.

Ensuring functional safety under random, destabilizing impacts and in the absence of malicious influence on systems, software tools, or database information, differs substantially from information security tasks (Fig. 11.1). The functional safety of objects and systems depends on failure situations that negatively affect the operability and performance of their basic functions, the causes of which may be defects and anomalies in hardware, programs, data, or computational processes. In this case the process of system operation is distorted catastrophically, critically, or substantially, causing significant damage in their application. The main sources of failure situations may be incorrect initial requirements from the customer, malfunctions and failures in hardware, and defects or errors in the programs and data of functional tasks, manifesting themselves during their execution in accordance with their intended purpose. Under such impacts the external, functional operability of systems may not be destroyed completely, but the full performance of the specified functions and the quality requirements for information for consumers becomes impossible. The safety of their operation is determined by manifestations of destabilizing factors causing major damage:

  • technical failures of external hardware and distortions of source information from objects of the external environment and from users of systems and processed information;

  • random malfunctions and physical destruction of elements and components of computing hardware and telecommunication tools;

  • defects and errors in complexes of information-processing programs and in data;

  • gaps and shortcomings in the tools for detecting dangerous failures and for the operational restoration of the operable state of systems, programs, and data.

When analyzing the characteristics of functional safety it is advisable to distinguish two classes of systems and their software tools. The first class consists of systems having built-in complexes of hard-real-time programs that automatically control dynamic external objects or processes. The required reaction time to failure situations of such systems is usually measured in seconds or fractions of a second, and the processes of restoring operability must be carried out within this time in a sufficiently automated way (onboard systems in aviation, transport, some weapon systems, and nuclear power plant control systems). These systems use relatively small information resources, complex logical control program complexes, and are practically inaccessible to deliberate negative external impacts.

Systems of the second class are used for controlling processes and for processing business information from the external environment, in which specialist operators actively participate (banking, administrative, and military staff systems). The permissible reaction time to dangerous failures in these systems can amount to tens of seconds and minutes, and the operations for restoring operability can be partly entrusted to specialist administrators responsible for functional safety. In these systems deliberate negative external impacts are possible, but they are not considered further below.

The concepts and characteristics of the functional safety of systems are close to the concepts of reliability (see above, section 11.3). The main difference is that reliability indicators take into account all occurrences of dangerous failures, whereas the characteristics of functional safety should register and take into account only those failures that led to such large, catastrophic damage that it affected the safety of the system and the information for consumers. Statistically, there may be several times fewer such failures than those taken into account in reliability values. However, the methods, influencing factors, and actual values of the reliability characteristics of software tools can serve as guidelines when assessing the functional safety of critical systems. Therefore, the methods for evaluating the characteristics and testing of functional safety can be based on the methods for determining the reliability of the operation of program complexes and databases.

Damage from defects and errors in programs and data can manifest itself in more or less systematic failures, each of which affects reliability but does not constitute a catastrophe with major damage affecting the safety of the system. The accumulation of such failures over time can lead to consequences that violate the functional safety of systems and their application. Thus, the concepts and characteristics of reliability and functional safety of complex systems and software tools additionally converge.

An effective system for protecting information and software tools implies the existence of a set of organizational and technical measures aimed at preventing various security threats, and at their detection, localization, and elimination. Creating such a system involves the planning and implementation of a purposeful policy of comprehensive security assurance for systems and software products (see Fig. 11.1). Requirements for the characteristics of software tools that ensure security are usually presented as part of the overall specification of requirements for the characteristics of the system.

Most fully, the degree of protection of a system is characterized by the magnitude of the prevented damage risk (see Lecture 10), possible upon the manifestation of destabilizing factors and the realization of specific security threats to the use of the software product by users, as well as by the average time between possible manifestations of threats that violate security. From this standpoint, the resources spent by developers and customers on ensuring the security of system operation should be commensurate with the possible average damage to users from a security violation. The design of system protection using software tools involves preparing a set of interrelated measures aimed at achieving the required characteristics and level of security. To ensure the effectiveness of systems, it is advisable to base the program complex for ensuring security on the following general principles:

  • the cost of creating and operating the software protection and security system should be less than the size of the most probable or possible (on average), unacceptable-to-consumers system risk-damage from any potential threats;

  • the software protection of functional programs and data should be comprehensive and multilevel, oriented toward all types of threats with account taken of their danger to the consumer;

  • the protection program complex should have targeted, individual components intended to ensure the safety of the operation of each separately taken object and functional task of the software tool, with account taken of their vulnerability and degree of influence on the safety of the system as a whole;

— the protection program system should not lead to noticeable difficulties, interference, and a reduction in the effectiveness of the application and solution of the main, functional tasks by users as a whole.

The processes of designing security assurance programs for software tools, as an independent system, do not fundamentally differ from the technology of designing any other complex program complexes. For this, above all, it is necessary to analyze and specify in the specification of requirements of the software tool project the tasks, as well as the source data and factors that determine the safety characteristics of program operation:

— quality criteria and characteristic values reflecting the necessary and sufficient level of security for the application of the system by users as a whole, and of each of its main functional components, in accordance with the conditions of the application environment and the requirements of the customer's specifications;

  • the list and characteristics of possible internal and external destabilizing factors and threats capable of affecting the safety characteristics of the operation of software tools and databases;

  • requirements for methods and tools for preventing and reducing the influence of security threats caused by deliberate negative external impacts, as well as by possible defects in programs and data;

  • the list of protection tasks to be solved, covering all potentially possible threats, and assessments of the characteristics of the solution of individual tasks necessary for ensuring equally robust security of the system with a given effectiveness;

  • operational methods and tools for increasing the safety characteristics of program operation throughout the entire life cycle of the system by introducing temporal, program, and information redundancy into the program complex to implement a protection system against relevant types of threats;

  • the resources necessary and available for the development and deployment of the software security assurance system (financial-economic, limited specialist qualification, and computer computational resources);

  • standards, regulatory documents, and methods for reproducible measurement of safety characteristics, as well as the composition and values of the source and resulting data mandatory for conducting tests;

  • assessments of the comprehensive effectiveness of the protection of the system and the software product and their comparison with what is required by the customer, taking into account real constraints on the total expenditure of resources on ensuring protection.

11.5. Protection and operational safety characteristics of software

Fig. 1.11 Diagram of threats to the quality of software tools and methods for preventing them

The formation of security requirements should be based on the definition of the list and characteristics of potential security threats and the establishment of the possible sources of their occurrence (see Fig. 11.1).

External destabilizing factors that create threats to the security of the operation of software products and the system are:

  • deliberate, negative impacts by persons aimed at distorting, destroying, or stealing programs, data, and documents of the information system;

  • errors and unauthorized impacts by operational, administrative, and maintenance personnel during system operation;

  • distortions in the telecommunication channels of information arriving from external sources and transmitted to consumers, as well as unacceptable values and changes in the characteristics of information flows from objects of the external environment;

  • malfunctions and failures in the hardware of computing tools;

  • viruses spread over telecommunication channels;

  • changes in the composition and configuration of the complex of interacting system hardware beyond the limits verified during testing or certification.

Internal sources of security threats to the operation of complex systems and software tools are (see Lecture 10):

  • systemic errors in setting the goals and tasks of system design, in formulating requirements for the functions and characteristics of the protection tools for solving tasks, and in determining the conditions and parameters of the external environment in which the software product is to be used;
  • algorithmic design errors made directly in the algorithmization of the protection functions of software tools and databases, in determining the structure and interaction of the components of program complexes, and in using database information;
  • programming errors in program texts and data descriptions, as well as in the source and resulting documentation for software tool components;
  • insufficient effectiveness of the methods and tools used for the operational protection of programs and data and for ensuring the safety of system operation under conditions of random and deliberate negative impacts from the external environment.

Complete elimination of the listed threats to the safety characteristics of the operation of critical software tools is fundamentally impossible. In design, the problem consists in identifying the factors on which they depend, in creating methods and tools for reducing their influence on the safety of the software tool, and also in the effective allocation of resources to protection tools. It is necessary to assess the vulnerability of the functional components of the system to various deliberate, negative impacts and the degree of their influence on the main safety characteristics. Depending on this, the resources of the protection tools should be allocated so as to create a system design that is equally robust in terms of operational safety under any external impacts.

The magnitude and rational allocation of computer resources to individual types of protection has a significant influence on the achieved comprehensive safety of the system. The most general type of resource that must be taken into account in design is the permissible financial and economic expenditures, or the estimated cost of developing and operating the security assurance system and the software protection tools. To accommodate the protection tools in the object computer, the design must provide for program and information redundancy in the form of external and internal computer memory resources. In addition, temporal redundancy — additional computer performance — is necessary for the operation of the protection tools.

In design it is advisable to separate the computational resources necessary for directly solving the main, functional tasks of the system from the resources required for protecting and ensuring the correct, safe operation of the software product. The ratio between these types of resources in real large-scale systems depends on the complexity and composition of the functional tasks being solved, the degree of their criticality, and the requirements for the safety characteristics of the entire system. In various classes of systems, the resources for ensuring security may amount to from 5—20% to 100—300% of the resources used for solving the main, functional tasks, i.e., in special cases (critical military systems) they may exceed the latter by a factor of 2—4. In administrative and organizational systems, security assurance tools usually use 10—20% of all types of labor, hardware, and computational resources.

One of the difficulties in planning processes to achieve high quality of protection usually consists in the absence of a complete set of reliable customer requirements for safety characteristics at the initial stages of design and development, as well as in the iterative process of specifying them throughout the entire life cycle of the software tool. As a result, the initially formulated requirements for the quality characteristics of the protection and security assurance system of large software tools are successively refined and corrected in the process of interaction between the customer and the developer, taking into account the objectively changing characteristics of the evolving project.

The design of the protection system is closely related to defining the concept and functions of the system security administrator. The security administrator — a subject of access responsible for the protection of protected resources and for the effective use by users of the available protection functions of the system. Without the constant presence of an administrator, when large systems are used, protection measures may be ineffective, since an intruder gains the opportunity to make unauthorized access attempts over an unlimited time. Therefore, security assurance systems introduce:

  • administrative functions and interfaces available to the security administrator;

  • principles and tools for the consistent, effective use and adaptation of the functions of the security system's components;

  • tools for configuring the functions of the system and the security assurance complex;

— control of the permissible behavior of users and prevention of abnormal use of procedures that affect security.

In systems with a large number of objects requiring different levels of protection, there may be several administrators, united into a security administration service. An important property of the access control system should be the ability to create a so-called audit trail, i.e., a set of information about the state and operation of the protection tools, accumulated over time and intended for analyzing and managing the protection tools. To store this information, administrators usually organize control logs for recording and registering security events. The main information accumulated in these logs is data on the work of users and on attempts at unauthorized actions that exceed the authority granted to them, or from objects of the external environment.

For safety guarantees to be achieved at minimal cost, purposeful, coordinated planning and management are necessary to prevent design defects and errors, as well as to identify and eliminate them at the earliest possible stages of development. Therefore, the plan and measures ensuring the quality of protection programs must cover not only the final tests but the entire life cycle of the security assurance programs. For this, in the process of forming the technical specification, one should formulate the main provisions of the methodology and the plan for the successive improvement of safety characteristics by building up the complex of protection tools, staged testing of components, and determining the safety characteristics permissible for continuing work at the following stages.

The designs of protection complexes depend on the specific characteristics and purpose of the objects subject to protection, as well as on the regulatory documents applied and their requirements. Designing the tools for ensuring the safety of the operation of software tools is a creative process, dependent on many factors, which determines alimited standardization of a set of a number of methods and tasks. The methodological and system design tasks for the comprehensive protection of systems are most broadly and thoroughly set out in the three parts of the standard ISO 15408:1-3:1999 — Methods and tools for ensuring security. Evaluation criteria for the security of information technologies. In the first, relatively small part, the goals and concept of security assurance are presented, as well as the general model for building protection, which is distinguished by the flexibility and dynamism of forming requirements and evaluating the functions and components of the security system. It identifies: the surrounding environment; the objects of protection; the requirements and specifications of protection functions; and the tasks of the tools for the protection system. General requirements are set out for the criteria and characteristics for evaluating protection results, for the Security Profile, for the goals of evaluating requirements, and for the use of their results. A draft set of general goals, tasks, and criteria for ensuring the security of specific systems is proposed.

In the largest, second part of the standard, the paradigm for building and implementing structured and detailed functional requirements for the protection components of systems is presented. Eleven basic classes of requirements for ensuring the security of systems are identified and classified. Each class is detailed by a functional family of requirements that implement the corresponding part of the security assurance goals and, in turn, are structured by sets of requirements for smaller components of individual tasks.

Profiles of families and components serve as a basis for further specification of functional requirements in the Security Target for a particular system project and help avoid gross errors and gaps when forming a set of such requirements. Generalizations of the evaluations of the requirements specification of the Security Target should make it possible for customers, developers, and testers of the project to draw a general conclusion about the level of compliance of security with the functional requirements and the requirements for assurance of protection. The Profile and the Security Target are the main source documents for certification of compliance with the customer's requirements for the safety characteristics of the use of a specific system.

The third part of the standard is devoted to the goals, methods, and levels of ensuring quality assurance of protection systems, during the development and implementation of requirements for the security assurance functions in the system. The methods and tools that it is advisable to use for ensuring the correct implementation of the Security Target, the life cycle of protection tools, and their effective application are defined. Detailed requirements for ensuring the quality assurance of the creation and use of security systems are set out.

Thus, methodologically, the solution of the tasks of ensuring safety characteristics should be carried out as the design of a complex, sufficiently autonomous software-hardware system in the environment and interaction with the main, functional tasks and components of the system (see Fig. 11.1). Protection should be oriented toward the comprehensive assurance of the effective solution of the main, functional security tasks of the entire system. In doing so, priorities should be determined and the functional components ranked by the degree of protection required, the danger of various external and internal security threats should be assessed, and methods, tools, and regulatory documents adequate to the types of threats and the required protection should be identified,

See also

  • Database quality
  • software tool quality
  • external quality
  • internal quality
  • [[b7898]]
  • [[b9537]]
  • [[b9538]]
  • [[b9539]]
  • [[b9540]]

See also

Comments

To leave a comment

If you have any suggestion, idea, thanks or comment, feel free to write. We really value feedback and are glad to hear your opinion.
To reply

Lectures and tutorial on "Quality Assurance"

Terms: Quality Assurance