Читать реферат по английскому: "System Security Essay Research Paper System Security" Страница 2

назад (Назад)скачать (Cкачать работу)

Функция "чтения" служит для ознакомления с работой. Разметка, таблицы и картинки документа могут отображаться неверно или не в полном объёме!

was named using the initials of its creators Rivest, Shamir, and Adleman. RSA is a public-key encryption algorithm. RSA gets its security from the difficulty of factoring large numbers. The public and private keys are functions of a pair of large (100 to 200 digits or even larger) prime numbers. Recovering the plaintext from the public-key and the ciphertext is conjectured to be equivalent to factoring the product of the two primes. 1 An important part of RSA encryption is that the keys can also be used to authenticate a message. The encrypted public-key can be used as a signature for the person who sent the message. The most recent use of encryption technologies has been to protect business transactions across the Internet. More to the point transactions through a World Wide Web based medium. SSL or Secure Sockets Layer is a protocol that was designed by Netscape to provide security during the transmission of sensitive data over the Internet. It uses the RSA encryption algorithm to protect data that is transferred between the browser on your home PC and the server of the Web site. The key length for the encryption algorithm controls how strong or weak the code is to break and also the speed at which the code can be decrypted with the key. If you ever bought anything online you might have noticed that it takes a little longer for the page to load up when using a secure connection. Although SSL is fairly secure some measure of caution should be used when sending information across secure channels. The key length for any server outside the U.S. and Canada is limited to 56 bits or less. The RSA algorithm is able to be broken at that level. Within the borders of the U.S. and Canada the key size is limited to 128 bits. With enough computing power this is also able to be broken but it would take much longer than a 56 bit key. With encryption it often comes down to the speed at which the algorithm works weighed against the length of time the data needs to be protected. I might not agree to online banking or stock trades over SSL but I might purchase things with my credit card. The amount of damage that someone could do to you, by acquiring data about you should be taken into account when conducting transactions online.

The whole reason that data should be encrypted across networks is due to the fact that just about any system administrator can view data that passes through his system. The Internet is just a network of networks, and all along the path between you and the server you re communicating with, there could be someone listening. This eves-dropping on network traffic is generally referred to as sniffing. When data is sent across the Internet it is broken down into chewable pieces called packets. Now the packets each have the address they re trying to get to and the order in which they re supposed to be read in, encoded on them. Each individual packet will find its own way between you and the web site you re surfing. If somewhere along that line someone makes a copy of a packet or two, of yours, they might be able to find out information that you don t want them to know. This technique has been used to gain access to systems by sniffing usernames and passwords off the network. It has also found some publicity in individuals identities being stolen and huge debts being run up on their credit cards. Sniffing tools have been developed for the purposes of debugging network configurations and such. There is always going to be the ability for a malicious person to receive information that wasn t intended for them. Due to this ability, it reinforces the importance that strong encryption has on Internet commerce and the importance that it will continue to have into the future. Firewalls Other than information that is traveling outside the corporate Intranet there isn t too much worry about network security. Many corporations are setting up filtering routers or Unix hosts that filter the network traffic coming into their system. This method of filtering network traffic is called a firewall. A firewall is a combination of hardware and software components that provide a choke point between a trusted network and an untrusted network such as the Internet. The firewall provides a certain level of control as to what can go between the two networks. 2 As sniffing can be used maliciously by an attacker, it has also started to become a tool used by corporations to monitor traffic flow across their networks. Corporations have been trying to cut back on web surfing by employees and extraneous emails. The access to the Internet has been, counter productive to some employees. The firewall provides an excellent point for network monitoring to take place. By monitoring the network traffic the corporation can be sure that the employees aren t wasting time or downloading anything that might be dangerous to the system. Recently there has been a scare about a macro virus named Melissa. A computer virus is a program that, when executed, tries to duplicate itself. They generally either infect the boot record of a disk or attach themselves to some kind of executable file. In this manner they have ample opportunity to be executed. The Melissa virus was a Microsoft Office Macro that was designed to spread using the names in the victims Outlook address book. It would email itself to the first fifty entries where once opened by the recipients, it would start the process over again. The computer virus can cause big losses in productivity from downed systems and corrupted data. For the virus to duplicate it tries to copy itself to a new location and in doing so can cause data to be over written. In systems that are Unix based there isn t too much of a problem with viruses. The design of the operating system doesn t give programs the freedom to roam as much as the PC architecture does. On Windows based machines there should be a current virus scanner running, to help keep virus losses to a minimum. The scanner should


Интересная статья: Быстрое написание курсовой работы