UNIT 5/LECTURE 1

 

Distributed System Structures

·         Types of Distributed Operating Systems

·         Network Structure

·         Network Topology

·         Communication Structure

·         Communication Protocols

·         Robustness

·         Design Issues

 

Chapter Objectives

·         To provide a high-level overview of distributed systems and the networks that interconnect them

·         To discuss the general structure of distributed operating systems

 

  Introduction

 

·         Distributed system is collection of loosely coupled processors interconnected by a communications network

·         Processors variously called nodes, computers, machines, hosts

Ø  Site is location of the processor

·         Reasons for distributed systems

Ø  Resource sharing

4  sharing and printing files at remote sites

4  processing information in a distributed database

4  using remote specialized hardware devices

Ø  Computation speedup – load sharing

Ø  Reliability – detect and recover from site failure, function transfer, reintegrate failed site

Ø  Communication – message passing

 

 

A Distributed System

 

 

 

Types of Distributed Operating Systems

·         Network Operating Systems

·         Distributed Operating Systems

 

 

Network-Operating Systems

·         Users are aware of multiplicity of machines.  Access to resources of various machines is done explicitly by:

1.       Remote logging into the appropriate remote machine (telnet, ssh)

2.       Remote Desktop (Microsoft Windows)

3.       Transferring data from remote machines to local machines, via the File Transfer Protocol (FTP) mechanism

 

Distributed-Operating Systems

·         Users not aware of multiplicity of machines

1.         Access to remote resources similar to access to local resources

·         Data Migration – transfer data by transferring entire file, or transferring only those portions of the file necessary for the immediate task

·         Computation Migration – transfer the computation, rather than the data, across the system

·         Process Migration – execute an entire process, or parts of it, at different sites

1.       Load balancing – distribute processes across network to even the workload

2.       Computation speedup – subprocesses can run concurrently on different sites

3.       Hardware preference – process execution may require specialized processor

4.       Software preference – required software may be available at only a particular site

5.       Data access – run process remotely, rather than transfer all data locally

 

Network Structure

·         Local-Area Network (LAN) – designed to cover small geographical area.

1.       Multiaccess bus, ring, or star network

2.       Speed » 10 – 100 megabits/second

3.       Broadcast is fast and cheap

4.       Nodes:

4  usually workstations and/or personal computers

4  a few (usually one or two) mainframes

Depiction of typical LAN

 

 

 

·         Wide-Area Network (WAN) – links geographically separated sites

1.       Point-to-point connections over long-haul lines (often leased from a phone company)

2.       Speed » 1.544 – 45  megbits/second

3.       Broadcast usually requires multiple messages

4.       Nodes:

4  usually a high percentage of mainframes

 

Communication Processors in a Wide-Area Network

 

Network Topology

 

·         Sites in the system can be physically connected in a variety of ways; they are compared with respect to the following criteria:

Ø  Basic cost -  How expensive is it to link the various sites in the system?

Ø  Communication cost -  How long does it take to send a message from site A to site B?

Ø  Reliability -   If a link or a site in the system fails, can the remaining sites still communicate with each other?

·         The various topologies are depicted as graphs whose nodes correspond to sites

Ø  An edge from node A to node B corresponds to a direct connection between the two sites

·         The following six items depict various network topologies

 

Network Topology

 

 

Communication Structure

 

The design of a communication network must address four basic issues:

 

·         Naming and name resolution -  How do two processes locate each other to communicate?

·         Routing strategies -  How are messages sent through the network?

·         Connection strategies -  How do two processes send a sequence of messages?

·         Contention -  The network is a shared resource, so how do we resolve conflicting demands for its use?

 

 

Naming and Name Resolution

 

·         Name systems in the network

·         Address messages with the process-id

·         Identify processes on remote systems by

                   <host-name, identifier> pair

·         Domain name service (DNS) – specifies the naming structure of the hosts, as well as name to address resolution (Internet)

 

Routing Strategies

 

·         Fixed routing - A path from A to B is specified in advance; path changes only if a hardware failure disables it

Ø  Since the shortest path is usually chosen, communication costs are minimized

Ø  Fixed routing cannot adapt to load changes

Ø  Ensures that messages will be delivered in the order in which they were sent

·         Virtual circuit -  A path from A to B is fixed for the duration of one session.  Different sessions involving messages from A to B may have different paths

Ø  Partial remedy to adapting to load changes

Ø  Ensures that messages will be delivered in the order in which they were sent

·         Dynamic routing -  The path used to send a message form site A to site B is chosen only when a message is sent

1.       Usually a site sends a message to another site on the link least used at that particular time

2.       Adapts to load changes by avoiding routing messages on heavily used path

3.       Messages may arrive out of order

4  This problem can be remedied by appending a sequence number to each message

 

Connection Strategies

·         Circuit switching -  A permanent physical link is established for the duration of the communication (i.e., telephone system)

·         Message switching - A temporary link is established for the duration of one message transfer (i.e., post-office mailing system)

·         Packet switching -  Messages of variable length are divided into fixed-length packets which are sent to the destination

Ø   Each packet may take a different path through the network

Ø  The packets must be reassembled into messages as they arrive

·         Circuit switching requires setup time, but incurs less overhead for shipping each message, and may waste network bandwidth

Message and packet switching require less setup time, but incur more overhead per message

 

 

 

 

 

S.NO

RGPV QUESTION

YEAR

MARKS

1

Contrast centralized and distributed operating system ?

Dec , 2013

7

 

 

 

 

 

 

REFERNCES

S.NO

BOOK  NAME

AUTHORS

EDITION

PAGE NO

  1

   OPERATING  SYSTEM  CONCEPT

Peter Bare Galvin, Abraham Silberschatz

SIXTH

613-622

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

UNIT 5/LECTURE 2

 

Contention

 

Several sites may want to transmit information over a link simultaneously.  Techniques to avoid repeated collisions include:

 

·         CSMA/CD -  Carrier sense with multiple access (CSMA); collision detection (CD)

Ø  A site determines whether another message is currently being transmitted over that link.  If two or more sites begin transmitting at exactly the same time, then they will register a CD and will stop transmitting

Ø  When the system is very busy, many collisions may occur, and thus performance may be degraded

·         CSMA/CD is used successfully in the Ethernet system, the most common network system

 

·         Token passing -  A unique message type, known as a token, continuously circulates in the system (usually a ring structure)

Ø  A site that wants to transmit information must wait until the token arrives

Ø  When the site completes its round of message passing, it retransmits the token

Ø  A token-passing scheme is used by some IBM and HP/Apollo systems

·         Message slots - A number of fixed-length message slots continuously circulate in the system (usually a ring structure)

Ø  Since a slot can contain only fixed-sized messages, a single logical message may have to be broken down into a number of smaller packets, each of which is sent in a separate slot

Ø  This scheme has been adopted in the experimental Cambridge Digital Communication Ring

 

 

Communication Protocol

 

The communication network is partitioned into the following multiple layers:

 

·         Physical layer – handles the mechanical and electrical details of the physical transmission of a bit stream

·         Data-link layer – handles the frames, or fixed-length parts of packets, including any error detection and recovery that occurred in the physical layer

·         Network layer – provides connections and routes packets in the communication network, including handling the address of outgoing packets, decoding the address of incoming packets, and maintaining routing information for proper response to changing load levels

·         Transport layer – responsible for low-level network access and for message transfer between clients, including partitioning messages into packets, maintaining packet order, controlling flow, and generating physical addresses

·         Session layer – implements sessions, or process-to-process communications protocols

·         Presentation layer – resolves the differences in formats among the various sites in the network, including character conversions, and half duplex/full duplex (echoing)

·         Application layer – interacts directly with the users’ deals with file transfer, remote-login protocols and electronic mail, as well as schemas for distributed databases

 

 

 

 

 

 

 

 

 

 

Communication Via ISO Network Model

 

The ISO Protocol Layer

 

 

 

The ISO Network Message

 

 

 

The TCP/IP Protocol Layers

 

 

 

Robustness

 

·         Failure detection

·         Reconfiguration

 

 

Failure Detection

 

·         Detecting hardware failure is difficult

·         To detect a link failure, a handshaking protocol can be used

·         Assume Site A and Site B have established a link

Ø   At fixed intervals, each site will exchange an I-am-up message indicating that they are up and running

·         If Site A does not receive a message within the fixed interval, it assumes either (a) the other site is not up or (b) the message was lost

·         Site A can now send an Are-you-up? message to Site B

·         If Site A does not receive a reply, it can repeat the message or try an alternate route to Site B

 

 

·         If Site A does not ultimately receive a reply from Site B, it concludes some type of failure has occurred

·         Types of failures:
- Site B is down

            - The direct link between A and B is down
- The alternate link from A to B is down

            - The message has been lost

·         However, Site A cannot determine exactly why the failure has occurred

 

 

 

 

S.NO

RGPV QUESTION

YEAR

MARKS

1

Explain parallel processing and concurrent processing ?

Jun , 2011

10

 

 

 

 

 

 

REFERNCES

S.NO

BOOK  NAME

AUTHORS

EDITION

PAGE NO

  1

   OPERATING  SYSTEM  CONCEPT

Peter Bare Galvin, Abraham Silberschatz

SIXTH

628-631

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

UNIT 5/LECTURE 3

Reconfiguration

 

·         When Site A determines a failure has occurred, it must reconfigure the system:

            1. If the link from A to B has failed, this must be broadcast to every site in the system

            2. If a site has failed, every other site must also be notified indicating that the services  

                  offered by the failed site are no longer available

 

When the link or the site becomes available again, this information must again be broadcast to all other sites

 

·         Transparency – the distributed system should appear as a conventional, centralized system to the user

·         Fault tolerance – the distributed system should continue to function in the face of failure

·         Scalability – as demands increase, the system should easily accept the addition of new resources to accommodate the increased demand

·         Clusters – a collection of semi-autonomous machines that acts as a single system

 

Example: Networking

 

·         The transmission of a network packet between hosts on an Ethernet network

·         Every host has a unique IP address and a corresponding Ethernet (MAC) address

·         Communication requires both addresses

·         Domain Name Service (DNS) can be used to acquire IP addresses

·         Address Resolution Protocol (ARP) is used to map MAC addresses to IP addresses

 

 

·         If the hosts are on the same network, ARP can be used

Ø  If the hosts are on different networks, the sending host will send the packet to a router which routes the packet to the destination network

 

An Ethernet Packet

 

 

 

Distributed-File Systems

 

·         Background

·         Naming and Transparency

·         Remote File Access

·         Stateful versus Stateless Service

·         File Replication

 

Objectives

 

·         To explain the naming mechanism that provides location transparency and independence

·         To describe the various methods for accessing distributed files

·         To contrast stateful and stateless distributed file servers

·         To show how replication of files on different machines in a distributed file system is a useful redundancy for improving availability

·         To introduce the Andrew file system (AFS) as an example of a distributed file system

 

Background

 

·         Distributed file system (DFS) – a distributed implementation of the classical time-sharing model of a file system, where multiple users share files and storage resources

·         A DFS manages set of dispersed storage devices

·         Overall storage space managed by a DFS is composed of different, remotely located, smaller storage spaces

·         There is usually a correspondence between constituent storage spaces and sets of files

 

 

DFS Structure

 

·         Service – software entity running on one or more machines and providing a particular type of function to a priori unknown clients

·         Server – service software running on a single machine

·         Client –  process that can invoke a service using a set of operations that forms its client interface

·         A client interface for a file service is formed by a set of primitive file operations (create, delete, read, write)

·         Client interface of a DFS should be transparent, i.e., not distinguish between local and remote files

 

Naming and Transparency

 

·         Naming – mapping between logical and physical objects

·         Multilevel mapping – abstraction of a file that hides the details of how and where on the disk the file is actually stored

·         A transparent DFS hides the location where in the network the file is stored

·         For a file being replicated in several sites, the mapping returns a set of the locations of this file’s replicas; both the existence of multiple copies and their location are hidden

 

 

Naming Structures

 

·         Location transparency –  file name does not reveal the file’s physical storage location

·         Location independence – file name does not need to be changed when the file’s physical storage location changes

 

 

Naming Schemes — Three Main Approaches

·         Files named by combination of their host name and local name; guarantees a unique systemwide name

·         Attach remote directories to local directories, giving the appearance of a coherent directory tree; only previously mounted remote directories can be accessed transparently

·         Total integration of the component file systems

Ø  A single global name structure spans all the files in the system

Ø  If a server is unavailable, some arbitrary set of directories on different machines also becomes unavailable

 

 

Remote File Access

 

·         Remote-service mechanism is one transfer approach

·         Reduce network traffic by retaining recently accessed disk blocks in a cache, so that repeated accesses to the same information can be handled locally

Ø  If needed data not already cached, a copy of data is brought from the server to the user

Ø  Accesses are performed on the cached copy

Ø  Files identified with one master copy residing at the server machine, but copies of (parts of) the file are scattered in different caches

Ø  Cache-consistency problem – keeping the cached copies consistent with the master file

4  Could be called network virtual memory

 

 

Cache Location – Disk vs. Main Memory

 

·         Advantages of disk caches

Ø  More reliable

Ø  Cached data kept on disk are still there during recovery and don’t need to be fetched again

·         Advantages of main-memory caches:

Ø  Permit workstations to be diskless

Ø  Data can be accessed more quickly

Ø  Performance speedup in bigger memories

Ø  Server caches (used to speed up disk I/O) are in main memory regardless of where user caches are located; using main-memory caches on the user machine permits a single caching mechanism for servers and users

 

 

Cache Update Policy

 

·         Write-through – write data through to disk as soon as they are placed on any cache

Ø  Reliable, but poor performance

·         Delayed-write – modifications written to the cache and then written through to the server later

Ø   Write accesses complete quickly; some data may be overwritten before they are written back, and so need never be written at all

Ø  Poor reliability; unwritten data will be lost whenever a user machine crashes

Ø  Variation – scan cache at regular intervals and flush blocks that have been modified since the last scan

Ø  Variation – write-on-close, writes data back to the server when the file is closed

4  Best for files that are open for long periods and frequently modified

 

 

 

 

S.NO

RGPV QUESTION

YEAR

MARKS

1

What do you mean by Distributed OS ? Discuss the design issues of distributed OS ?

Dec, 2012

Dec, 2011

Jun, 2011

14

10

10

 

 

 

 

 

 

REFERNCES

S.NO

BOOK  NAME

AUTHORS

EDITION

PAGE NO

  1

   OPERATING  SYSTEM  CONCEPT

Peter Bare Galvin, Abraham Silberschatz

SIXTH

641-646

 

 

NIT 5/LECTURE 4

Caches and its Use of Caching

 

Consistency

 

·         Is locally cached copy of the data consistent with the master copy?

·         Client-initiated approach

Ø  Client initiates a validity check

Ø  Server checks whether the local data are consistent with the master copy

·         Server-initiated approach

Ø  Server records, for each client, the (parts of) files it caches

Ø  When server detects a potential inconsistency, it must react

 

Comparing Caching and Remote Service

 

·         In caching, many remote accesses handled efficiently by the local cache; most remote accesses will be served as fast as local ones

·         Servers are contracted only occasionally in caching (rather than for each access)

Ø  Reduces server load and network traffic

Ø  Enhances potential for scalability

·         Remote server method handles every remote access across the network; penalty in network traffic, server load, and performance

·         Total network overhead in transmitting big chunks of data (caching) is lower than a series of responses to specific requests (remote-service)

·         Caching is superior in access patterns with infrequent writes

Ø  With frequent writes, substantial overhead incurred to overcome cache-consistency problem

·         Benefit from caching when execution carried out on machines with either local disks or large main memories

·         Remote access on diskless, small-memory-capacity machines should be done through remote-service method

·         In caching, the lower intermachine interface is different form the upper user interface

·         In remote-service, the intermachine interface mirrors the local user-file-system interface

 

 

 

 

Stateful File Service

 

·         Mechanism

Ø  Client opens a file

Ø  Server fetches information about the file from its disk, stores it in its memory, and gives the client a connection identifier unique to the client and the open file

Ø  Identifier is used for subsequent accesses until the session ends

Ø  Server must reclaim the main-memory space used by clients who are no longer active

·         Increased performance

Ø  Fewer disk accesses

Ø  Stateful server knows if a file was opened for sequential access and can thus read ahead the next blocks

 

 

Stateless File Server

 

·         Avoids state information by making each request self-contained

·         Each request identifies the file and position in the file

·         No need to establish and terminate a connection by open and close operations

 

 

Distinctions Between Stateful & Stateless Service

 

·         Failure Recovery

Ø  A stateful server loses all its volatile state in a crash

4  Restore state by recovery protocol based on a dialog with clients, or abort operations that were underway when the crash occurred

4  Server needs to be aware of client failures in order to reclaim space allocated to record the state of crashed client processes (orphan detection and elimination)

 

 

Ø  With stateless server, the effects of server failure sand recovery are almost unnoticeable

4  A newly reincarnated server can respond to a self-contained request without any difficulty

 

·         Penalties for using the robust stateless service:

Ø  longer request messages

Ø  slower request processing

Ø  additional constraints imposed on DFS design

·         Some environments require stateful service

Ø  A server employing server-initiated cache validation cannot provide stateless service, since it maintains a record of which files are cached by which clients

Ø  UNIX use of file descriptors and implicit offsets is inherently stateful; servers must maintain tables to map the file descriptors to inodes, and store the current offset within a file

 

File Replication

 

·         Replicas of the same file reside on failure-independent machines

·         Improves availability and can shorten service time

·         Naming scheme maps a replicated file name to a particular replica

Ø  Existence of replicas should be invisible to higher levels

Ø  Replicas must be distinguished from one another by different lower-level names

·         Updates – replicas of a file denote the same logical entity, and thus an update to any replica must be reflected on all other replicas

·         Demand replication – reading a nonlocal replica causes it to be cached locally, thereby generating a new nonprimary replica.

 

 

S.NO

RGPV QUESTION

YEAR

MARKS

1

Write short notes on

(i)RMI (ii)Distributed shared memory (iii) Parallel Processing

Dec, 2012

14

2

Compare remote procedure call and remote evaluation on the basis of flexibility, efficiency and security ?

          Dec, 2011

          Jun, 2011

               10

               10

 

 

REFERNCES

S.NO

BOOK  NAME

AUTHORS

EDITION

PAGE NO

  1

   OPERATING  SYSTEM  CONCEPT

Peter Bare Galvin, Abraham Silberschatz

SIXTH

647-652

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

UNIT 5/LECTURE 5

Security

 

  • The Security Problem
  • Program Threats
  • System and Network Threats
  • Cryptography as a Security Tool
  • User Authentication
  • Implementing Security Defenses
  • Firewalling to Protect Systems and Networks
  • Computer-Security Classifications

 

Objectives

 

  • To discuss security threats and attacks
  • To explain the fundamentals of encryption, authentication, and hashing
  • To examine the uses of cryptography in computing
  • To describe the various countermeasures to security attacks

 

The Security Problem

 

  • Security must consider external environment of the system, and protect the system resources
  • Intruders (crackers) attempt to breach security
  • Threat is potential security violation
  • Attack is attempt to breach security
  • Attack can be accidental or malicious
  • Easier to protect against accidental than malicious misuse

 

Security Violations

 

  • Categories

Ø  Breach of confidentiality

Ø  Breach of integrity

Ø  Breach of availability

Ø  Theft of service

Ø  Denial of service

  • Methods

Ø  Masquerading (breach authentication)

Ø  Replay attack

4  Message modification

Ø  Man-in-the-middle attack

Ø  Session hijacking

 

 

 

 

 

 

 

 

 

 

 

 

Standard Security Attacks

 

 

 

 

Security Measure Levels

 

  • Security must occur at four levels to be effective:

Ø  Physical

Ø  Human

4  Avoid social engineering, phishing, dumpster diving

Ø  Operating System

Ø  Network

  • Security is as week as the weakest chain

 

Program Threats

 

  • Trojan Horse

Ø  Code segment that misuses its environment

Ø  Exploits mechanisms for allowing programs written by users to be executed by other users

Ø  Spyware, pop-up browser windows, covert channels

  • Trap Door

Ø  Specific user identifier or password that circumvents normal security procedures

Ø  Could be included in a compiler

  • Logic Bomb

Ø  Program that initiates a security incident under certain circumstances

  • Stack and Buffer Overflow

Ø  Exploits a bug in a program (overflow either the stack or memory buffers)

  • Viruses

Ø  Code fragment embedded in legitimate program

Ø  Very specific to CPU architecture, operating system, applications

Ø  Usually borne via email or as a macro

 

  • Virus dropper inserts virus onto the system
  • Many categories of viruses, literally many thousands of viruses
    1. File
    2. Boot
    3. Macro
    4. Source code
    5. Polymorphic
    6. Encrypted
    7. Stealth
    8. Tunneling
    9. Multipartite
    10. Armored

 

A Boot-sector Computer Virus

 

 

 

 

System and Network Threats

 

  • Worms – use spawn mechanism; standalone program
  • Internet worm

Ø  Exploited UNIX networking features (remote access) and bugs in finger and sendmail programs

Ø  Grappling hook program uploaded main worm program

  • Port scanning

Ø  Automated attempt to connect to a range of ports on one or a range of IP addresses

  • Denial of Service

Ø  Overload the targeted computer preventing it from doing any useful work

Ø  Distributed denial-of-service (DDOS) come from multiple sites at once

Cryptography as a Security Tool

 

  • Broadest security tool available

Ø  Source and destination of messages cannot be trusted without cryptography

Ø  Means to constrain potential senders (sources) and / or receivers (destinations) of messages

  • Based on secrets (keys)

 

 

Secure Communication over Insecure Medium

 

 

 

S.NO

RGPV QUESTION

YEAR

MARKS

1

What is the difference between worm and the virus ? How do worm spread ? How can they be prevented ?

Dec, 2013

Dec, 2011

7

10

 

 

 

 

 

REFERNCES

S.NO

BOOK  NAME

AUTHORS

EDITION

PAGE NO

  1

   OPERATING  SYSTEM  CONCEPT

Peter Bare Galvin, Abraham Silberschatz

SIXTH

559-576

 

 

 

 

 

 

 

 

 

 

 

 

UNIT 4/LECTURE 6

Encryption

 

  • Encryption algorithm consists of

Ø  Set of K keys

Ø  Set of M Messages

Ø  Set of C ciphertexts (encrypted messages)

Ø  A function E : K → (MC). That is, for each k Î K, E(k) is a function for generating ciphertexts from messages.

1.       Both E and E(k) for any k should be efficiently computable functions.

Ø  A function D : K → (C M). That is, for each k Î K, D(k) is a function for generating messages from ciphertexts.

1.       Both D and D(k) for any k should be efficiently computable functions.

  • An encryption algorithm must provide this essential property: Given a ciphertext c Î C, a computer can compute m such that E(k)(m) = c only if it possesses D(k).

Ø  Thus, a computer holding D(k) can decrypt ciphertexts to the plaintexts used to produce them, but a computer not holding D(k) cannot decrypt ciphertexts.

Ø  Since ciphertexts are generally exposed (for example, sent on the network), it is important that it be infeasible to derive D(k) from the ciphertexts

 

 

 

Symmetric Encryption

 

  • Same key used to encrypt and decrypt

Ø  E(k) can be derived from D(k), and vice versa

  • DES is most commonly used symmetric block-encryption algorithm (created by US Govt)

Ø  Encrypts a block of data at a time

  • Triple-DES considered more secure
  • Advanced Encryption Standard (AES), twofish up and coming
  • RC4 is most common symmetric stream cipher, but known to have vulnerabilities

Ø  Encrypts/decrypts a stream of bytes (i.e wireless transmission)

Ø  Key is a input to psuedo-random-bit generator

4  Generates an infinite keystream

 

 

Asymmetric Encryption

 

  • Public-key encryption based on each user having two keys:

Ø  public key – published key used to encrypt data

Ø  private key – key known only to individual user used to decrypt data

  • Must be an encryption scheme that can be made public without making it easy to figure out the decryption scheme

Ø  Most common is RSA block cipher

Ø  Efficient algorithm for testing whether or not a number is prime

Ø  No efficient algorithm is know for finding the prime factors of a number

  • Note symmetric cryptography based on transformations, asymmetric based on mathematical functions

Ø  Asymmetric much more compute intensive

Ø  Typically not used for bulk data encryption

 

Authentication

 

  • Constraining set of potential senders of a message
    • Complementary and sometimes redundant to encryption
    • Also can prove message unmodified
  • Algorithm components
    • A set K of keys
    • A set M of messages
    • A set A of authenticators
    • A function S : K → (MA)

4  That is, for each k Î K, S(k) is a function for generating authenticators from messages

4  Both S and S(k) for any k should be efficiently computable functions

    • A function V : K → (M× A{true, false}). That is, for each k Î K, V(k) is a function for verifying authenticators on messages

4  Both V and V(k) for any k should be efficiently computable functions

  • For a message m, a computer can generate an authenticator a Î A such that V(k)(m, a) = true only if it possesses S(k)
  • Thus, computer holding S(k) can generate authenticators on messages so that any other computer possessing V(k) can verify them
  • Computer not holding S(k) cannot generate authenticators on messages that can be verified using V(k)
  • Since authenticators are generally exposed (for example, they are sent on the network with the messages themselves), it must not be feasible to derive S(k) from the authenticators

 

Authentication – Hash Functions

 

  • Basis of authentication
  • Creates small, fixed-size block of data (message digest, hash value) from m
  • Hash Function H must be collision resistant on m

Ø  Must be infeasible to find an m’m such that H(m) = H(m’)

  • If H(m) = H(m’), then m = m

Ø  The message has not been modified

  • Common message-digest functions include MD5, which produces a 128-bit hash, and SHA-1, which outputs a 160-bit hash

 

Key Distribution

 

  • Delivery of symmetric key is huge challenge
    • Sometimes done out-of-band
  • Asymmetric keys can proliferate – stored on key ring
    • Even asymmetric key distribution needs care – man-in-the-middle attack

 

Man-in-the-middle Attack on Asymmetric Cryptography

 

 

 

Digital Certificates

 

  • Proof of who or what owns a public key
  • Public key digitally signed a trusted party
  • Trusted party receives proof of identification from entity and certifies that public key belongs to entity
  • Certificate authority are trusted party – their public keys included with web browser distributions

Ø  They vouch for other authorities via digitally signing their keys, and so on

 

 

User Authentication

 

  • Crucial to identify user correctly, as protection systems depend on user ID
  • User identity most often established through passwords, can be considered a special case of either keys or capabilities

Ø  Also can include something user has and /or a user attribute

  • Passwords must be kept secret

Ø  Frequent change of passwords

Ø  Use of “non-guessable” passwords

Ø  Log all invalid access attempts

  • Passwords may also either be encrypted or allowed to be used only once

 

 

Implementing Security Defenses

 

  • Defense in depth is most common security theory – multiple layers of security
  • Security policy describes what is being secured
  • Vulnerability assessment compares real state of system / network compared to security policy
  • Intrusion detection endeavors to detect attempted or successful intrusions

Ø  Signature-based detection spots known bad patterns

Ø  Anomaly detection spots differences from normal behavior

4  Can detect zero-day attacks

Ø  False-positives and false-negatives a problem

  • Virus protection
  • Auditing, accounting, and logging of all or specific system or network activities

 

Firewalling to Protect Systems and Networks

 

  • A network firewall is placed between trusted and untrusted hosts

Ø  The firewall limits network access between these two security domains

  • Can be tunneled or spoofed

Ø  Tunneling allows disallowed protocol to travel within allowed protocol (i.e. telnet inside of HTTP)

Ø  Firewall rules typically based on host name or IP address which can be spoofed

  • Personal firewall is software layer on given host

Ø  Can monitor / limit traffic to and from the host

  • Application proxy firewall understands application protocol and can control them (i.e. SMTP)
  • System-call firewall monitors all important system calls and apply rules to them (i.e. this program can execute that system call)

 

Network Security Through Domain Separation Via Firewall

 

Computer Security Classifications

 

  • U.S. Department of Defense outlines four divisions of computer security: A, B, C, and D.
  • D – Minimal security.
  • C – Provides discretionary protection through auditing. Divided into C1 and C2. C1 identifies cooperating users with the same level of protection. C2 allows user-level access control.
  • B – All the properties of C, however each object may have unique sensitivity labels. Divided into B1, B2, and B3.
  • A – Uses formal design and verification techniques to ensure security.

 

 

 

S.NO

RGPV QUESTION

YEAR

MARKS

1

Explain security aspects of OS ?

June, 2011

10

 

 

 

 

 

 

 

 

 

 

REFERNCES

S.NO

BOOK  NAME

AUTHORS

EDITION

PAGE NO

  1

   OPERATING  SYSTEM  CONCEPT

Peter Bare Galvin, Abraham Silberschatz

SIXTH

587-599

 

 

 

Back To Home