NODE cc572d51Re: NT's C2 rating
David Loysen <dwl@hnc.com>Fri, 22 Mar 1996 05:49:23 +0800
At 04:53 AM 3/21/96 -0800, you wrote:
>> Basically, I'm now questioning the C2 rating of Windows NT. The
>> entire security layer is modular to the Kernel. As a modular
>> driver, it can be removed, rewritten, and replaced.
>
>Good questioning.
>
>> So, what makes it secure? What gives it the C2 Rating? How would
>> one go about getting a C2 rating?
>
>The fine print says its insecure as soon as its connected to a network.
Ain't nothing fine about that print. An operating system or piece of
hardware may be C2 certifiable. But only a complete system in a specific
configuration can be certified as C2 compliant. The way I read the orange
book, no system with a network connection can ever be C2. For that matter a
system can't get C2 unless it is in an area where you can control and
monitor physical access to the system.
So if you can't hack it over the wire, and you can't remove, rewrite and
replace the kernel because you can't get near the keyboard what's the problem?
dwl@hnc.com
David Loysen
619-546-8877 x245
NODE 4663f9deRe: NT's C2 rating
Derek Atkins <warlord@MIT.EDU>Fri, 22 Mar 1996 08:05:58 +0800
> configuration can be certified as C2 compliant. The way I read the orange
> book, no system with a network connection can ever be C2. For that matter a
> system can't get C2 unless it is in an area where you can control and
> monitor physical access to the system.
This is incorrect -- you can have a C2 system which has a network
connection. Indeed, you can get a B2 rating with a networked system,
c.f. Multics.
-derek
NODE d70d9063Re: NT's C2 rating
Mark Aldrich <maldrich@grctechs.va.grci.com>Fri, 22 Mar 1996 20:36:59 +0800
On Thu, 21 Mar 1996, David Loysen wrote:
> Ain't nothing fine about that print. An operating system or piece of
> hardware may be C2 certifiable. But only a complete system in a specific
> configuration can be certified as C2 compliant. The way I read the orange
> book, no system with a network connection can ever be C2. For that matter a
> system can't get C2 unless it is in an area where you can control and
> monitor physical access to the system.
I have to disagree. C2 most certainly can be given to a network product.
That's why we have the TNI (Trusted Network Interpretation) of the
criteria. There are actually A1 network products on the EPL. I've
personally worked on both C2 and B1 network and database product
evaluations, for example.
Also, evaluation is given to commercial products, not "complete
systems." A complete system goes through certification and
accreditation, not evaluation against the Criteria.
Also, the physical security measures make no difference in regard to a C2
rating. A product can be C2 whether it's in a kiosk in a shopping mall,
or inside of a SCIF. The over-all security policy of the system dictates
the right mix of software countermeasures (C2, B1, B2, ,etc.) and the
physical countermeasures (public, locked room, not networked, in a SCIF).
Normally, as you boost one side of the equation, you can lower the other.
In short, the criteria is used to rate the level of trust that can be
placed in a given commercial product. Sort of like a UL rating. Once
you buy it, though, the security posture in which you operate it is up to
you.
-------------------------------------------------------------------------
| Liberty is truly dead |Mark Aldrich |
| when the slaves are willing |GRCI INFOSEC Engineering |
| to forge their own chains. |maldrich@grci.com |
| STOP THE CDA NOW! |MAldrich@dockmaster.ncsc.mil |
|_______________________________________________________________________|
|The author is PGP Empowered. Public key at: finger maldrich@grci.com |
| The opinions expressed herein are strictly those of the author |
| and my employer gets no credit for them whatsoever. |
-------------------------------------------------------------------------