| Document revision date: 24 June 2002 | |
![]() |
|
|
|
http://www.openvms.compaq.com/
. . .
|
Question: Could you tolerate the following
event?
|
Level of Security Requirements Based on
Toleration Responses
|
||
|
Low
|
Medium
|
High
|
|
|
A
user knowing the images being executed on your
system
|
Y
|
Y
|
N
|
|
A
user knowing the names of another user’s files
|
Y
|
Y
|
N
|
|
A
user accessing the file of another user in the group
|
Y
|
Y
|
N
|
|
An outsider knowing the name of the system
just dialed into
|
Y
|
Y
|
N
|
|
A
user copying files of other users
|
Y
|
N
|
N
|
|
A
user reading another user’s electronic mail
|
Y
|
N
|
N
|
|
A
user writing data into another user’s file
|
Y
|
N
|
N
|
|
A
user deleting another user’s file
|
Y
|
N
|
N
|
|
A
user being able to read sections of a disk that might contain
various old files
|
Y
|
N
|
N
|
|
A
user consuming machine time and resources to perform unrelated or
unauthorized work, possibly even playing games
|
Y
|
N
|
N
|

|
Item
|
Element
|
Description
|
|---|---|---|
|
1
|
Subjects
|
Active entities, such as user processes,
that gain access to information on behalf of people.
|
|
2
|
Objects
|
Passive repositories of information to be
protected, such as files.
|
|
3
|
Authorization database
|
Repository for the security attributes of
subjects and objects. From these attributes, the reference
monitor determines what kind of access (if any) is
authorized.
|
|
4
|
Audit trail
|
Record of all security-relevant events, such
as access attempts, successful or not.
|
|
Class Name
|
Definition
|
|---|---|
|
Capability
|
A
resource to which the system controls access; currently, the only
defined capability is the vector processor.
|
|
Common event flag cluster
|
A
set of 32 event flags that enable cooperating processes to post
event notifications to each other.
|
|
Device
|
A
class of peripherals connected to a processor that are capable of
receiving, storing, or transmitting data.
|
|
File
|
Files-11 On-Disk Structure Level 2 (ODS-2)
files and directories.
|
|
Group global section
|
A
shareable memory section potentially available to all processes
in the same group.
|
|
Logical name table
|
A
shareable table of logical names and their equivalence names for
the system or a particular group.
|
|
Queue
|
A
set of jobs to be processed in a batch, terminal, server, or
print job queue.
|
|
Resource domain
|
A
namespace controlling access to the lock manager’s
resources.
|
|
Security class
|
A
data structure containing the elements and management routines
for all members of the security class.
|
|
System global section
|
A
shareable memory section potentially available to all processes
in the system.
|
|
Volume
|
A
mass storage medium, such as a disk or tape, that is in ODS-2
format. Volumes contain files and may be mounted on
devices.
|
|
File
|
Contents
|
Data Used to Interpret
|
|---|---|---|
|
#SYSUAF.DAT
|
User names
|
Logins
|
|
Passwords
|
Logins
|
|
|
UICs
|
Access control checks
|
|
|
#NETPROXY.DAT
|
User names
|
Logins
|
|
#NET$PROXY.DAT
|
User names
|
Logins
|
|
#RIGHTSLIST.DAT
|
Rights identifiers
|
Access control checks
|
|
#VMS$OBJECTS.DAT
|
UICs
|
Access control checks
|
|
Protection codes
|
Access control checks
|
|
|
Access control lists
|
Access control checks
|
|
|
#VMS$AUDIT_
#SERVER.DAT |
Auditable events
|
Reporting of events
|
|
Destination
|
Events Audited by Default
|
|---|---|
|
Log file or terminal display
|
Authorization database changes
|
|
Intrusion attempts
|
|
|
Login failures
|
|
|
Use of DCL command SET AUDIT
|
|
|
Events triggered by Audit or Alarm
ACEs
|

|
Secure Passwords
|
Insecure Passwords
|
|---|---|
|
Nonsense syllables:
aladaskgam eojfuvcue joxtyois |
Words with a strong personal
association:
your name the name of a loved one the name of your pet the name of your town the name of your automobile |
|
A
mixed string:
492_weid $924spa zu_$rags |
A
work-related term:
your company name a special project your work group name |
|
Failure Indicator
|
Reason
|
|---|---|
|
No response from the terminal.
|
A
defective terminal, a terminal that requires a system password, a
terminal that is not powered on, or a communications problem
caused by defective wiring or by a misconfigured or
malfunctioning modem.
|
|
No response from any terminal.
|
The system is down or
overloaded.
|
|
No response from the terminal when you enter
the system password.
|
The system password changed.
|
|
System messages:
|
|
|
“User authorization
failure”
|
A
typing error in your user name or password. The account or
password expired.
|
|
“Not authorized to log in from this
source”
|
Your particular class of login (local,
dialup, remote, interactive, batch, or network) is
prohibited.
|
|
“Not authorized to log in at this
time”
|
You do not have access to log in during this
hour or this day of the week.
|
|
“User authorization failure”
(and no known user failure occurred)
|
An apparent break-in has been attempted at
the terminal using your user name, and the system has temporarily
disabled all logins at that terminal by your user
name.
|
%SET-E-INVPWDLEN, invalid password length - password not changed
NoteYour password has expired; you must set a new password to log in New password:
My password is GOBBLEDYGOOK.
NODE"username password"::disk:[directory]file.typ

%%%%%%%%%%% OPCOM 7-DEC-2001 07:21:11.10 %%%%%%%%%%% Message from user AUDIT$SERVER on BOSTON Security audit (SECURITY) on BOSTON, system id: 19424 Auditable event: Attempted file access Event time: 7-DEC-2001 07:21:10.84 PID: 23E00231 Username: ABADGUY Image name: BOSTON$DUA0:[SYS0.SYSCOMMON.][SYSEXE]DELETE.EXE Object name: _BOSTON$DUA1:[RWOODS]CONFIDREVIEW.MEM;1 Object type: file Access requested: DELETE Status: %SYSTEM-S-NORMAL, normal successful completion Privileges used: SYSPRV
|
Events Initiating Security Audits or
Alarms
|
|
|---|---|
|
Logins, logouts, login failures, and
break-in attempts
Volume mounts and dismounts |
Modifications to:
System and user passwords System time System authorization file Network proxy file Rights database SYSGEN parameters |
|
Connection or termination of logical
links
|
Execution of:
SET AUDIT command NCP commands |
|
Creation and deletion of selected
protected objects |
Installation of images
|
|
Selected types of access and deaccess to
selected protected objects
|
Access event requested by an ACL on a
protected object
|
|
Successful or unsuccessful use of a
privilege or an identifier
|
Use of the process control system services,
including $CREPRC and $DELPRC
|
Note