Thursday, September 27, 2018

Mobile Cloud Computing

Cloud Computing offers such smartphones that have rich Internet media support, require less processing and consume less power. In terms of Mobile Cloud Computing (MCC), processing is done in cloud, data is stored in cloud, and the mobile devices serve as media for display.
Today smartphones are employed with rich cloud services by integrating applications that consume web services. These web services are deployed in cloud.
There are several Smartphone operating systems available such as Google's Android, Apple's iOS, RIM BlackBerry, Symbian, and Windows Mobile Phone. Each of these platforms support third-party applications that are deployed in cloud.
Architecture
  • Distant mobile cloud
  • Distant immobile cloud
  • Proximate mobile computing entities
  • Proximate immobile computing entities
  • Hybrid

MCC includes four types of cloud resources:
The following diagram shows the framework for mobile cloud computing architecture:
Mobile Computing

Issues

Despite of having significant development in field of mobile cloud computing, still many issues remain unsorted such as:

Emergency Efficient Transmission

There should be a frequent transmission of information between cloud and the mobile devices.

Architectural Issues

Mobile cloud computing is required to make architectural neutral because of heterogeneous environment.

Live VM Migration

It is challenging to migrate an application, which is resource-intensive to cloud and to execute it via Virtual Machine.

Mobile Communication Congestion

Due to continuous increase in demand for mobile cloud services, the workload to enable smooth communication between cloud and mobile devices has been increased.

Security and Privacy

This is one of the major issues because mobile users share their personal information over the cloud.

Unit 5: Security in Cloud Computing

Cloud Security Challenges:

Software as a Service Security:

The seven security issues which one should discuss with a cloud-computing vendor:
  1. Privileged user access —inquire about who has specialized access to data, and about the hiring and management of such administrators.
  2. Regulatory compliance—make sure that the vendor is willing to undergo external audits and/or security certifications.
  3. Data location—does the provider allow for any control over the location of data?
  4. Data segregation —make sure that encryption is available at all stages, and that these encryption schemes were designed and tested by experienced professionals.
  5. Recovery —Find out what will happen to data in the case of a disaster. Do they offer complete restoration? If so, how long would that take?
  6. Investigative support —Does the vendor have the ability to investigate any inappropriate or illegal activity?
  7. Long-term viability —What will happen to data if the company goes out of business? How will data be returned, and in what format?

To address the security issues listed above, SaaS providers will need to incorporate and enhance security practices used by the managed service providers and develop new ones as the cloud computing environment evolves. The baseline security practices for the SaaS environment as currently formulated are discussed in the following sections.

- Security Management (People): One of the most important actions for a security team is to develop a formal charter for the security organization and program. This will foster a shared vision among the team of what security leadership is driving toward and expects, and will also foster “ownership” in the success of the collective team. The charter should be aligned with the strategic plan of the organization or company the security team works for. Lack of clearly defined roles and responsibilities, and agreement on expectations, can result in a general feeling of loss and confusion among the security team about what is expected of them, how their skills and experienced can be leveraged, and meeting their performance goals. Morale among the team and pride in the team is lowered, and security suffers as a result.

- Security Governance: A security steering committee should be developed whose objective is to focus on providing guidance about security initiatives and alignment with business and IT strategies. A charter for the security team is typically one of the first deliverables from the steering committee. This charter must clearly define the roles and responsibilities of the security team and other groups involved in performing information security functions. Lack of a formalized strategy can lead to an unsustainable operating model and security level as it evolves. In addition, lack of attention to security governance can result in key needs of the business not being met, including but not limited to, risk management, security monitoring, application security, and sales support. Lack of proper governance and management of duties can also result in potential security risks being left unaddressed and opportunities to improve the business being missed because the security team is not focused on the key security functions and activities that are critical to the business.

- Risk Management: Effective risk management entails identification of technology assets; identification of data and its links to business processes, applications, and data stores; and assignment of ownership and custodial responsibilities. Actions should also include maintaining a repository of information assets. Owners have authority and accountability for information assets including protection requirements, and custodians implement confidentiality, integrity, availability, and privacy controls. A formal risk assessment process should be created that allocates security resources linked to business continuity.


- Risk Assessment: Security risk assessment is critical to helping the information security organization make informed decisions when balancing the dueling priorities of business utility and protection of assets. Lack of attention to completing formalized risk assessments can contribute to an increase in information security audit findings, can jeopardize certification goals, and can lead to inefficient and ineffective selection of security controls that may not adequately mitigate information security risks to an acceptable level. A formal information security risk management process should proactively assess information security risks as well as plan and manage them on a periodic or as-needed basis. More detailed and technical security risk assessments in the form of threat modeling should also be applied to applications and infrastructure. Doing so can help the product management and engineering groups to be more proactive in designing and testing the security of applications and systems and to collaborate more closely with the internal security team. Threat modeling requires both IT and business process knowledge, as well as technical knowledge of how the applications or systems under review work.

- Security Monitoring and Incident Response:  Centralized security information management systems should be used to provide notification of security vulnerabilities and to monitor systems continuously through automated technologies to identify potential issues. They should be integrated with network and other systems monitoring processes (e.g., security information management, security event management, security information and event management, and security operations centers that use these systems for dedicated 24/7/365 monitoring). Management of periodic, independent third-party security testing should also be included. Many of the security threats and issues in SaaS center around application and data layers, so the types and sophistication of threats and attacks for a SaaS organization require a different approach to security monitoring than traditional infrastructure and perimeter monitoring. The organization may thus need to expand its security monitoring capabilities to include application- and data-level activities. This may also require subject-matter experts in applications security and the unique aspects of maintaining privacy in the cloud. Without this capability and expertise, a company may be unable to detect and prevent security threats and attacks to its customer data and service stability.

- Third-Party Risk Management: As SaaS moves into cloud computing for the storage and processing of customer data, there is a higher expectation that the SaaS will effectively manage the security risks with third parties. Lack of a third-party risk management program may result in damage to the provider’s reputation, revenue losses, and legal actions should the provider be found not to have performed due diligence on its third-party vendors.

Security Architecture Design:

A security architecture framework should be established with consideration of processes (enterprise authentication and authorization, access control, confidentiality, integrity, non-repudiation, security management, etc.), operational procedures, technology specifications, people and organizational management, and security program compliance and reporting. A security architecture document should be developed that defines security and privacy principles to meet business objectives. Documentation is required for management controls and metrics specific to asset classification and control, physical security, system access controls, network and computer management, application development and maintenance, business continuity, and compliance. A design and implementation program should also be integrated with the formal system development life cycle to include a business case, requirements definition, design, and implementation plans. Technology and design methods should be included, as well as the security processes necessary to provide the following services across all technology layers:

1. Authentication
2. Authorization
3. Availability
4. Confidentiality
5. Integrity
6. Accountability
7. Privacy

The creation of a secure architecture provides the engineers, data center operations personnel, and network operations personnel a common blueprint to design, build, and test the security of the applications and systems. Design reviews of new changes can be better assessed against this architecture to assure that they conform to the principles described in the architecture, allowing for more consistent and effective design reviews.

Vulnerability Assessment:

Vulnerability assessment classifies network assets to more efficiently prioritize vulnerability-mitigation programs, such as patching and system upgrading. It measures the effectiveness of risk mitigation by setting goals of reduced vulnerability exposure and faster mitigation. Vulnerability management should be integrated with discovery, patch management, and upgrade management processes to close vulnerabilities before they can be exploited.

Data Privacy:

A risk assessment and gap analysis of controls and procedures must be conducted. Based on this data, formal privacy processes and initiatives must be defined, managed, and sustained. As with security, privacy controls and protection must an element of the secure architecture design. Depending on the size of the organization and the scale of operations, either an individual or a team should be assigned and given responsibility for maintaining privacy. A member of the security team who is responsible for privacy or a corporate security compliance team should collaborate with the company legal team to address data privacy issues and concerns. As with security, a privacy steering committee should also be created to help make decisions related to data privacy. Typically, the security compliance team, if one even exists, will not have formalized training on data privacy, which will limit the ability of the organization to address adequately the data privacy issues they currently face and will be continually challenged on in the future. The answer is to hire a consultant in this area, hire a privacy expert, or have one of your existing team members trained properly. This will ensure that your organization is prepared to meet the data privacy demands of its customers and regulators.

For example, customer contractual requirements/agreements for data privacy must be adhered to, accurate inventories of customer data, where it is stored, who can access it, and how it is used must be known, and, though often overlooked, Request for Interest/Request for Proposal questions regarding privacy must answered accurately. This requires special skills, training, and experience that do not typically exist within a security team. As companies move away from a service model under which they do not store customer data to one under which they do store customer data, the data privacy concerns of customers increase exponentially. This new service model pushes companies into the cloud computing space, where many companies do not have sufficient experience in dealing with customer privacy concerns, permanence of customer data throughout its globally distributed systems, cross-border data sharing, and compliance with regulatory or lawful intercept requirements.

Data Security:

The ultimate challenge in cloud computing is data-level security, and sensitive data is the domain of the enterprise, not the cloud computing provider. Security will need to move to the data level so that enterprises can be sure their data is protected wherever it goes. For example, with data-level security, the enterprise can specify that this data is not allowed to go outside of the United States. It can also force encryption of certain types of data, and permit only specified users to access the data. It can provide compliance with the Payment Card Industry Data Security Standard (PCI DSS). True unified end-to-end security in the cloud will likely requires an ecosystem of partners.

Application Security:

Application security is one of the critical success factors for a world-class SaaS company. This is where the security features and requirements are defined and application security test results are reviewed. Application security processes, secure coding guidelines, training, and testing scripts and tools are typically a collaborative effort between the security and the development teams. Although product engineering will likely focus on the application layer, the security design of the application itself, and the infrastructure layers interacting with the application, the security team should provide the security requirements for the product development engineers to implement. This should be a collaborative effort between the security and product development team. External penetration testers are used for application source code reviews, and attack and penetration tests provide an objective review of the security of the application as well as assurance to customers that attack and penetration tests are performed regularly. Fragmented and undefined collaboration on application security can result in lower-quality design, coding efforts, and testing results.

Virtual Machine Security:

In the cloud environment, physical servers are consolidated to multiple virtual machine instances on virtualized servers. Not only can data center security teams replicate typical security controls for the data center at large to secure the virtual machines, they can also advise their customers on how to prepare these machines for migration to a cloud environment when appropriate.

Firewalls, intrusion detection and prevention, integrity monitoring, and log inspection can all be deployed as software on virtual machines to increase protection and maintain compliance integrity of servers and applications as virtual resources move from on-premises to public cloud environments. By deploying this traditional line of defense to the virtual machine itself, you can enable critical applications and data to be moved to the cloud securely. To facilitate the centralized management of a server firewall policy, the security software loaded onto a virtual machine should include a bidirectional stateful firewall that enables virtual machine isolation and location awareness, thereby enabling a tightened policy and the flexibility to move the virtual machine from on-premises to cloud resources. Integrity monitoring and log inspection software must be applied at the virtual machine level.

This approach to virtual machine security, which connects the machine back to the mother ship, has some advantages in that the security software can be put into a single software agent that provides for consistent control and management throughout the cloud while integrating seamlessly back into existing security infrastructure investments, providing economies of scale, deployment, and cost savings for both the service provider and the enterprise.

Wednesday, April 5, 2017

System Analysis and Design

Overview of Systems Analysis and Design


What is System?

 A system is a collection of components (subsystems) that work together to realize some objective. For example, the library system contains librarians, books, and periodicals as components to provide knowledge for its members.


Every system has three activities or functions. These activities are input, processing and output. 
• Input: It involves capturing and assembling elements that enter the system to be processed. Inputs to the system are anything to be captured by the system from its environment.
 For example, raw materials.

 • Processing: It involves transformation processes that convert input to output. For example, a manufacturing process.

 • Output: It involves transferring elements that have been produced by a transformation process to their ultimate destinations. Outputs are the things produced by the system and sent into its environment. For example, finished products. The system also includes other two additional activities. These activities include feedback and control.

 • Feedback: It is data about the performance of a system. It is the idea of monitoring the current system output and comparing it to the system goal. Any variation from the goal are then fed back in to the system and used to adjust it to ensure that it meets its goal. For example, data about sales performance is feedback to a sales manager.

• Control: It involves monitoring and evaluating feedback to determine whether a system is moving toward the achievement of its goals. The control function then makes necessary adjustments to a system’s input and processing components to ensure that it produces proper output.
 For example, a sales manager exercises control when reassigning salespersons to new sales territories after evaluating feedback about their sales performance. 
Theoretical approaches to systems have introduced many generalized principles. Goal setting is one such principle. It defines exactly what the system is supposed to do. There are principles concerned with system structure and behavior.
 System boundary is one such a principle. This defines the components that make up the system. Anything outside the system boundary is known as system environment. A system can be made up of any number of subsystems.
 Each subsystem carries out part of the system function i.e. part of the system goal. The subsystems communicate by passing messages between themselves. Several systems may share the same environment. 
Some of these systems may be connected to one another by means of a shared boundary, or interface. 
A system that interacts with other systems in its environment is called open system.
 Finally, a system that has the ability to change itself or environment in order to survive is called an adaptive system.

Saturday, December 31, 2016

Abstraction (Basic concept of OOAD)

Abstraction means to focus on essential features of an element or object in OOP, ignoring its extraneous or accidental properties.
The essential features are relative to the context in which the object is being  used.

Grady Booch has defined Abstraction as follows:
"An Abstraction denotes the essential characteristics of an object that distinguish it from other kind of objects and thus, Provides crisply defined conceptual boundaries, relative to prospective to viewer".
for example:
when a class student is designed the attributes student-id, Name, Course and Address are included while characteristics like pulse-rate and size of a shoe are eliminated  , Since they are irrelevant in the Prospective of educational institution.

Friday, December 30, 2016

Class (Basic concept of OOAD)

A class represents a collection of objects having same characteristics properties that exhibit common behavior. It gives the blue print or description of an object that can be created from it. creation of an object is an instance of a class.

The constitution of a class are:
  • A set of attributes for the object that are to be instantiated from the class. Generally different objects of a class have some difference in values of the attributes . attributes are often refereed as a class data.
  • A set of operations that shows the behavior of the objects of the class. operations are also refereed as functions or methods.


    Let us consider a simple class, circle that represents the geometrical figure circle in 2 dimensional space.
The attributes of this class can be x= x-coordinate of center, y=y-coordinate of a center, r=radius of the circle.

some of its operations can be defined as findArea(): method to calculate area.
scale(): method to increase or decrease the radius.

During Instant-ion, values are assigned for at least some of the attributes.
if we create an object my_circle, we can assign values like x=2,y=3 and r=4, to depict its state .
now if the operation scale() is performed on my_cycle with a scaling factor 2 , the value of r will become 8. 
This operation brings a change in the state of my_cycle. ie,the object has exhibited certain behavior.
 

Objects (Basic Concepts of OOAD)

An object is a real word element in an object oriented environment that may have a physical or a conceptual existence.
Objects can be modeled according to the needs of the application. An Object may have physical existence like a customer, a car etc. or an intangible conceptual existence like a project, a process etc.

Each Object has:
  • Identity that distinguish it from other objects in the system.
  • state that determines the characteristic properties that the object holds.
Behavior that represent externally visible activities performed by an object in terms of changes in its state.





    OOP(Introduction to OOAD)

    It refers to a type of Computer Programming in which Programmers define not only the data type of data structure, but also the type of Operations (functions)that can be applied to data structure.
    In this way the data structure becomes object that includes both data and functions. In addition, Programmers can create relationship between One Object and another Object.
    Object Oriented Programming is a programming Paradigm based upon object (having both data and methods) that advantages of module and re usability.

    Objects,which are usually instances of classes, are used to interact with one another to design application and computer programs.

    Grady booch
    Grady booch has defined Object Oriented Programing as "A method of Implementing in which Programs are Organized as co-operative collection of objects, each of which represents an instance of some Hierarchy of classes united via Inheritance relationship."

    OOD (Introduction to OOAD)

    Design emphasizes a conceptual solution that fulfill the requirement rather than its implementation.
    for example: a description of database schema and software object.
    Ultimately design can be implemented, Design encompasses the discipline approach. we use to invert a solution for some problem, so design providing path from requirement to implementation.
    In Contrast, in the OOD phase typical Question starts with "How...?"
    "how will this class handle its responsibility?","How to ensure that class knows all the information it needs?","How will classes in the design communicate?". The OOD phases deals with finding conceptual solution to the problem -It is about fulfilling the requirements, but not about implementing solutions.

    Thursday, December 29, 2016

    OOA-(Introduction to OOAD)

    Analysis emphasis an investigation of a  problem and requirements, raaather then a solution ''Analysis is abroad term best qualified as in requirement analysis (an investigation of the requirement ) or object analysis (an investigation of the domain objects)"
    In the phase of OOA the typical question start with  What....? like "what will the classes in my program be?","what will be my progeam need to do?","what will each classes be responsible for?".

    Hence,OOA cares about the real world and how to model this real world without getting into much detail. The OOA is an investigation of the problem and requirements, rather then finding a solution to the problem.

    The primary task in OOA are:-
    • Identifying Objects.
    • Organize object
    • defining the internal of the objects (object attributes).
    • defining behavior of  the object (Object action).
    • Describing how the object interact.

    Evolution of OOAD

    The object oriented paradigm took its shape from the initial concept of a new programming approach, While the method came much later.
    1. The first Object-Oriented Language was simula (Simulation of real systems)that was developed  in 1960 by researchers at the Norwegian Computing Center. 
    2. In 1970, Alan Kay and his research group at Xerox PARK created a personal Computer named Dynabook and the first pure object oriented programming language(OOPL)-smalltalk, for the programming the dyna book.
    3. In 1980s, Grady Booch Published a paper titled Object Oriented Design that mainly Presented design for the programming language,Ada.In the ensuing editions, he extended his ideas to a complete Object-Oriented design method.
    4. In the 1990s, coad incorporated behavioural ideas to object-Oriented method.
      The other significant innovations were object Modelling Techniques (OMT) by James Rumbaugh and Object-Oriented Software Engineering(OOSE) by Ivar Jacobson.

    Tuesday, December 27, 2016

    Database Security

    7. Database Security

    The data stored in the database need to be protected from unauthorized access, malicious destruction and alteration of data. To protect the database, we must take security measures at several levels.
    v  Physical : The site or sites containing the computer systems must be physically secured against armed or surreptitious entry by intruders.
    v Human: Users must be authorized carefully to reduce the chance of any such user giving access to an intruder in exchange for a bribe of other favours.
    v Operating System: No matter how secure the database system is, Weakness in operating system security may serve as a means of unauthorized access to the database.
    v Network: Since most all database systems allow remote access through terminals or networks, software level security within the network software is as important as physical security, both the internet and in networks private to an enterprise.
    v Database System: Some database system users may be authorized to access only a limited portion of the database. Other users may be allowed to issue queries, but may be forbidden to modify the data.

     

    7.1 SQL Access for database Security

    Database Security and the DBA

    The database administrator (DBA) is the central authority for managing a database system. The DBA's responsibilities include granting privileges to users who need to Use the system and classifying users and data in accordance with the policy of the organization. The DBA has a DBA account in the DBMS, sometimes called a system or superuser account, which provides powerful capabilities that are not made available to regular database accounts and users. DBA privileged commands include commands for granting and revoking privileges to individual accounts, users, or user groups and for performing the following types of actions:
    1.         Account creation: This action creates a new account and password for a user or a group of users to enable them to access the DBMS.
    2.         Privilege granting: This action permits the DBA to grant certain privileges to certain accounts.
    3.         Privilege revocation: This action permits the DBA to revoke (cancel) certain privileges that were previously given to certain accounts.
    4.         Security level assignment: This action consists of assigning user accounts to the appropriate security classification level.
    The DBA is responsible for the overall security of the database system.

    GRANT and REVOKE

    The view mechanism allows the database to be conceptually divided up into pieces in var­ious ways so that sensitive information can be hidden from unauthorized users. However, it does not allow for the specification of the operations that authorized users are allowed to execute against those pieces is performed by the GRANT statement.
    Note first that the creator of any object is automatically granted all privileges that make sense for that object. For example, the creator of a base table T is automatically granted the SELECT, INSERT, UPDATE, DELETE, and REFERENCES privileges on T

    The SQL commands used by DBA for security are as follows.
    Creating user:
    Create user supriya identified by s;
    This sql commands creates user supriya whose password is s. The privileges which can be granted to supriya by DBA on any table employee (suppose the table employee is already created) are SELECT,INSERT,UPDATE,DELETE,INDEX,ALTER and REFERENCE.
    The privileges can be granted by DBA to user supriya as follows.
    Grant SELECT on employee to supriya;
    Similarly INSERT,UPDATE,DELETE,INDEX,ALTER and REFERENCE can be granted to any user.
    Grant all on employee to supriya;
    Grant SELECT,UPDATE on employee to supriya;
    The REFERENCE Privilege allows the grantee to create integrity constraints that reference that table.
    Similarly the privileges can be revoked using revoke command as follows.
    Revoke all on employee from supriya;
    Revoke UPDATE on employee from supriya;


    The current SQL standard supports discretionary access control only. Two more or less in­dependent SQL features are involved-the view mechanism, which  can be used to hide sensitive data from unauthorized users, and the authorization subsystem itself, which allows users having specific privileges selectively and dynamically to grant those privileges to other users, and subsequently to revoke those privileges, if de­sired. Both features are discussed below.

    Views and Security

    To illustrate the use of views for security purposes in SQL:
         CREATE VIEW LS AS
           SELECT S.S#, S.SNAME, S.STATUS S.CITY
           FROM S
           WHERE S,CITY = 'London' ;
    The view defines the data over which authorization is to be granted. The granting it­self is done by means of the GRANT statement--e.g.:
    GRANT SELECT, UPDATE , DELETE
    ON LS
    TO Dan, Misha ;


    7.2 ACCESS CONTROL

    The access to the database is controlled by defining user to the database, assigning passwords to each user, assigning access privileges such as read, write, delete privileges, by physical access control such as secured entrances, password protected workstations, voice recognition technology etc.  and by using DBMS utilities access control such as auditing and log file features. Some used access control methods are Discretionary and Mandatory control.

    Discretionary Access Control Based on Granting/Revoking of Privileges

    The typical method of  enforcing discretionary access control in a database system is based on the granting and revoking of privileges. Let us consider privileges in the context of a relational DBMS.
    Informally there are two levels for assigning privileges to use the database system.
    1.                     The account level: At this level, the DBA specifies the particular privileges that each account holds independently of the relations in the database.
    2.                     The relation( or table) level: At this level, we can control the privilege to access each individual relation or view in the database.
    The privileges at the account levels include CREATE TABLE  to create table,  CREATE VIEW  to       create view, CREATE SYNONYM to create synonym and all the privileges are granted by DBA to individual user  or account.
    The privileges at the relation levels include SELECT, UPDATE, REFERENCES, DELETE for particular relations and are granted by DBA.
     In SQL2, the DBA can assign an owner to a whole, schema by creating the schema and associating the appropriate authorization identifier with that schema using the CREATE SCHEMA command. The owner account holder can pass privileges on any of the owned relations to other users by granting privileges to their accounts. In SQL the following types of privileges can be granted on each individual relation R:­
    n  SELECT (retrieval or read) privilege on R: Gives the account retrieval;  privilege In SQL this gives the account the privilege to use the SELECT statement to retrieve, tuples from R.
    n  MODIFY privileges on R:. This gives the account the capability to modify tuples of R. In SQL this privilege is further divided into UPDATE, DELETE, and INSERT Privilege to apply the corresponding SQL command to R. In addition, both the INSERT and UPDATE privileges can specify that only certain attributes of R can be updated by the account.
    n  REFERENCES privilege on R: This gives the account the capability to reference relation R when specifying integrity constraints. This privilege can also be restricted to          specific attributes of R.
    Notice that to create a view the account must have SELECT privilege on all the involved in the view definition.

    Specifying Privileges Using Views

    The mechanism of views is an important discretionary authorization mechanism in its own right. For example, if the owner A of a relation R wants another account B to be able to retrieve only some fields of R, then A can create a view V of R that includes only that ' attributes and then grant SELECT on V to B. The same applies to limiting B to retrieving only certain tuples of R; a view V can be created by defining the view by means of a query that selects only those tuples from R that A wants to allow B to access.

    Revoking Privileges

    In some cases it is desirable to grant some privilege to a user temporarily. For example, the owner of a relation may want to grant the SELECT privilege to a user for a specific task and then revoke that privilege once the task is completed. Hence, a mechanism for revoking privileges is needed. In SQL a REVOKE command is included for the purpose of canceling privileges.

    Propagation of Privileges Using the GRANT OPTION

    Whenever the owner A of a relation R grants a privilege on R to another account B, the privilege can be given to B with or without the GRANT OPTION. If the GRANT OPTION is given, this means that B can also grant that privilege on R to other accounts.

    Specifying Limits on Propagation of Privileges

    Techniques to limit the propagation of privileges have been developed, although they have not yet been implemented in most DBMSs and are not a part of SQL. Limiting hori­zontal propagation to an integer number i means that an account B given the GRANT OPTION can grant the privilege to at most i other accounts. Vertical propagation is more complicated; it limits the depth of the granting of privileges. Granting a privilege with vertical propagation of zero is equivalent to granting the privilege with no GRANT OPTION. If account A grants a privilege to account B with vertical propagation set to an integer number j > 0, this means that the account B has the GRANT OPTION on that priv­ilege, but B can grant the privilege to other accounts only with a vertical propagation less than j. In effect, vertical propagation limits the sequence of grant options that can be given from one account to the next based on a single original grant of the privilege.

    Mandatory Access Control for Multilevel Security

    The discretionary access control technique of granting and revoking privileges on rela­tions has traditionally been the main security mechanism for relational database systems. This is an all-or-nothing method: a user either has or does not have a certain privilege. In many applications, an additional security policy is needed that classifies data and users based on security classes. This approach-known as mandatory access control-would typi­cally be combined with the discretionary access control mechanisms. It is important to note that most commercial DBMSs currently provide mechanisms only for discretionary access control. However, the need for multilevel security exists in government, military, and intelligence applications, as well as in many industrial and cor­porate application.
    Typical security classes are top secret (TS), secret (S), confidential (C), and unclas­sified (U), where TS is the highest level and U the lowest Other more complex security classification schemes exist, in which the security classes are organized in a lattice. For simplicity,  four security classification levels, where TS ³ S ³ C ³ U are used in the system. The commonly used model for multilevel security known as the Bell-LaPadula model, classifies each subject (user, account, program) and object (relation, tuple, column, view, operation) into one of the security classifications TS, S, C, or U. We will refer to the clearance (classification) of a subject S as class (S) and to the classification of an object O as class (O). Two restrictions are enforced on data access based on the subject/object classifications:               '
    1.         A subject S is not allowed read access to an object O unless class(S) ³ class(O).
                 This is known as the simple security property.
    2.         A subject S is not allowed to write an object O unless class(S) £ class(O). This is, known as the *property (or star property).
    The first restriction is intuitive and enforces the obvious rule that no subject can read an object whose security classification is higher than the subject's security clearance. The second restriction is less intuitive. It prohibits a subject from writing an object at a lower security classification than the subject's security clearance. Violation of this rule would allow information to flow from higher to lower classifications, which violates a basic tenet of multilevel security. For example, a user (subject) with TS clearance may make a copy' of an object with classification TS and then write it back as a new object with classification U,  thus making it visible throughout the system.
    To incorporate multilevel security notions into the relational database model, it is common to consider attribute values and tuples as data objects. Hence, each attribute A is associated with a classification attribute C in the schema, and each attribute value in a tuple is associated with a corresponding security classification,- In addition, in some mod­els, a tuple classification attribute TC is added to the relation attributes to provide a clas­sification for each tuple as a whole. Hence, a multilevel relation schema R with n attributes would be represented as
    R(A1, C1, A2, C2, ..., An, Cn, TC)
       where each Ci represents the classification attribute associated with attribute Ai.
    The value of the TC attribute in each tuple t-which is the highest of all attribute classification values within t-provides a general classification for the tuple itself, whereas each ci provides a finer security classification for each attribute value within the tuple. The apparent key of a multilevel relation is the set of attributes that would have formed the primary key in a regular (single-level) relation. A multilevel relation will appear to contain different data to subjects (users) with different clearance levels. In some cases, it is possible to store a single tuple in the relation at a higher classification level and produce the corresponding tuples at a lower level classification through a process known as filter­ing. In other cases, it is necessary to store two or more tuples at different classification lev­els with the same value for the apparent key, This leads to the concept of poly­instantiation, where several tuples can have the same apparent key value but have dif­ferent attribute values for users at different classification levels.

    Assume that the Name attribute is the apparent key, and consider the query  SELECT * FROM EMPLOYEE. A user with security clearance S would see the same relation shown below in fig.a, since all tuple classifications are less than or equal to S. However a user with security clearance C would not be allowed to see values for salary of Shyam and job performance for Ram as shown below in fig. b .


    a.       EMPLOYEE
       Name                                    Salary                    JobPerformance                                                 TC
       Ram       U                             5000       C             Fair        S                                                              S
       Shyam  C                             5000       S              Good     C                                                             S
                                                       Fig. The original Employee tuples

    b.       EMPLOYEE
       Name                                    Salary                    JobPerformance                                                 TC
       Ram       U                             5000       C             Null       C                                                             C
       Shyam  C                             null        C             Good     C                                                             C
                                                       Fig. Appearance of EMPLOYEE after filtering for classification C users

    7.3 ENCRYPTION

    Access control is only applied to the established avenues of access to the database. Clever people using clever instruments may be able to access the data by circumventing the controlled avenues of access. Also, innocent people who passively stumble upon an avenue of access may be unable to resist the temptation 'to look at and pet misuse the data so acquired. To counteract the possibility that either active or passive intruders obtain unauthorized access to sensitive data, it is desirable to obscure or hide the meaning of the data accessed.
    Encryption is any sort of transformation applied to data (or text) prior to transmis­sion or prior to storage, which makes it more difficult to extract information content or meaning. Decryption is method of retrieving the original message(text) from the encrypted message. The word 'cryptography' comes from the Greek meaning 'hidden or secret. Cryptography includes both  encryption and decryption.
    Encryption techniques complement access controls. Access controls are ineffective if
    n  A user leaves a listing in the work area or in the trash.
    n  Passwords are written down and found.
    n  Offline backup files are stolen.
    n  Confidential data is left in main memory after a job has completed.
    n  Someone taps in on a communication line.
    When a data system' is geographically dispersed, physical security measures be come less practical and less effective against intrusion because the system is more open and vulnerable to penetration at more points. If the computer system and all the sensitive data are maintained in a single, isolated environment into which a user must be admitted before access to data is permitted, little need for encryption exists. An increased need for encryption comes with the increased tendency for systems to reach out into the using environment and become 'more available to the users.
    The basic encryption scheme is shown in Figure . Original plaintext is trans­formed by an encryption algorithm using an encryption key to produce ciphertext. An inverse decryption algorithm transforms the ciphertext using the same (or related) key to reconstruct the plaintext.


    Figure  Basic Encryption/ Decryption System.

    An encryption algorithm (T). transforms a sender's plaintext message (M) using a key (K) to produce ciphertext. Plaintext'is in a form recognizable by humans (or computers). The encrypted message or data can be transmitted through an insecure channel or stored in an insecure area since a potential intruder would only see a scrambled message. Using the same (or related) key, the decryption algorithm applies an in years transformation (T-1) to the ciphertext to reconstruct the original message (M). Transmission of the key to the decryption must be kept secure, since knowing the decryption key and the encryption algorithm makes it easy to decrypt or decipher a message, thereby disclosing sensitive information.
    In a database environment, encryption techniques can be applied to:
    n  Transmitted data sent over communication lines between computer systems, or to and from remote terminals (1).
    n  Stored data:
    Ü  remote backup data on removable media (2)
    Ü  active data on secondary storage devices (3)
    Ü  tables and buffers in internal main memory (4)
    The figure below indicates the points where encryption can be used to protect data from unauthorized access during transmission between the user and the system. With a remote database, encryption can be used to protect the stored data from unauthorized access.
    Fig Encryption in a Database Environment.
    Encryption techniques can be used in the transmission or storage of data. The stored data may be remote backup data on removable media, active (updated) data on secondary storage devices, or tables and buffers in internal memory. Sensitive data outside of secured area is more exposed to unauthorized disclosure and therefore encryption can contribute significantly to greater security.
    Encryption methods can be classified according to:
    1. The nature of the algorithm:
    n  Transposition, or permutation in general.
    n  Substitution, either mono-alphabetic or polyalphabetic.
    n  Product, combining permutations and substitutions.

    Cryptographic techniques have been widely used in military and government intel­ligence activities for centuries but due to the secretive nature of the subject.
    The increased potential for more sophisticated encryption and cryptanalysis through the use of computers, coupled with the increased concern for data privacy, has generated a great surge of interest in the past decade or two. There has been substantial published literature on the use of encryption in computerized database systems. The U:S. Government has adopted a data encryption standard(DES).
     Choosing an encryption method depends upon the cost, what is available, and the level of user need. The object of any particular method is to raise the work factor high enough to discourage anyone from breaking the code. The cost of the chosen method must be commensurate with the level of risk and the degree of security desired. Even fairly modest and simple encryption methods can render transmitted messages and stored data secure from all but the most persistent penetrators.

    Traditional Methods: Transposition and Substitution

    Historically, transposition and substitution have been the two major classes of encryption techniques. They were applied manually to encrypt streams of text prior to transmission. Permutations and substitutions serve as the basis for some present-day computerized methods.
    Transposition techniques permute the ordering of characters in the data stream according to some rule. For example, if the transposition pattern or rule is to transpose each consecutive pair of characters, the phrase
    database
     would appear as

              ADATABES


    obviously not very secure. An example of a general permutation would be to form blocks of, say, four characters and permute, 1234 to 3124. The phrase would now appear as:

    TDAASBAE

    With a correct guess of the length of the permutation block, only a few trials are needed to break the code.
    Substitution techniques retain the relative position of the characters in the original plaintext but hide their identity in the ciphertext. By contrast, transposition techniques retain the identity of the original characters but change their position.
    A simple example is the Caesar Cipher which substitutes the nth letter away from ..the plaintext character in the alphabet. This is applied 'modulo 27' (includes a blank), that is, if you count past the end of the alphabet, cycle back to the beginning. The plaintext message in Fig. was encrypted using a Caesar Cipher. The n is the key indicating the alphabet shift.
    A general mono-alphabetic substitution cipher replaces characters in the plain­text with characters from some other alphabet, called a cipher alphabet, which be­comes the key. For example:
    Plaintext alphabet:                       abcdefghijklmnopqrstuvwxyz
    Ciphertext alphabet:                    GORDNCHALESZYXWVUTQPMKJIFB
    Transforms the Plaintext:           database management system
    Into the Ciphertext:                       DGPGOGQN YGXGHNYNXP QFQPNYQ
    Assuming that the plaintext message is written in natural English using 26 letters, mono-alphabetic substutions are susceptible to frequency analysis of single let­ters, letter pairs, and reversals. The analysis is increasingly accurate for larger mes­sages the letter frequencies in the message would approach the 'characteristic letter frequencies for the language. In English the most frequently occurring letters are E,T,A,O,N,R,I,S,H. Some people can' even read such ciphertext directly Some com­puters have built-in machine instructions to perform substitutions between two alpha­bets (needed for A_CII-EBCDI_ code conversion), thus enabling faster exhaustive analysis of mono-alphabetic' substitutions.
    Polyalphabetic substitution uses multiple alphabets cyclically according to some rule. Each character of the plaintext is replaced' with a character from a different Ciphertext alphabet, thereby obscuring the frequency characteristics of the characters in the plaintext alphabet.


    Mobile Cloud Computing

    Cloud Computing offers such smartphones that have rich Internet media support, require less processing and consume less power. In terms of ...