Modern technologies of data during storage
The problem of information security during storage (storage server security) has recently become relevant. The paper reviews current approaches to the protection of the hard disks, magnetic tapes and data warehousing.
usb protection software
Modern corporations are faced with the rapid growth of the volume of data required for their daily work. usb encryption software This increase is due to the need to constantly be "at your fingertips" financial, marketing, technical, statistical and other information to respond quickly to changing market conditions, the behavior of competitors and customers. We use a different kind of storage, storage area networks, arrays of hard drives and tapes.
However, the high degree of centralization of corporate information makes it more vulnerable, and simplifies the task of the attacker, who set a goal to get access to this information. The situation is aggravated by the fact that modern storage technologies, from simple file server, to architectures such as SAN or NAS, almost did not provide built-in access control and data protection.
So, often, if not always, confidential information which is of value for the company and a leak which has serious trouble - damage to business reputation, lawsuits or loss of competitive advantage, virtually no protection from a number of threats.
The main vulnerability
Since the information on corporate networks is usually stored on hard disks and magnetic tapes, they are the chief weakness. The simplest version of the loss of confidential information in this case - getting the media with the information in the wrong hands. This can occur as a result of deliberate, planned action to seize or steal vehicles or components of information systems, and as a result of accidental vehicle into the wrong hands - for example, when you send the hard drive to be repaired.
As for the tape, then with them is even worse. First, they are quite compact and can easily be brought outside the controlled area and the loss will be noticeable immediately. Second, they tend to contain a complete copy of all the information from several, if not all server information system. Finally, there are special regulations relating to business recovery following a disaster (disaster recovery), according to which the backup data to be stored in special depositories, or at least outside of the office, which also extends the range of persons who may have access to these copies, and therefore increases the likelihood of leakage.
Provide security of data storage can not be solved by means of perimeter protection, such as firewalls, intrusion detection and prevention (IDS / IPS) and the means of virtual private networks (VPN). First, the money does not limit the ability of legitimate users on the corporate network, and second, the presence of at least one security holes could allow an attacker to gain access to the stored data.
Not work in this case, and for authentication - no matter whether multifactorial, password, biometric or smart card - because the authentication will not save, if an attacker gains physical access to the information carrier.
Thus, according to various estimates, between 50 and 80% of the attacks to obtain restricted information, starting from the local network (intranet).
General principles of data protection storage
From what has been said above, it becomes clear that the only way to protect against these threats - is encryption. If the information is encrypted, even getting the information carrier in the wrong hands will not leak if it does not have the encryption key.
Modern symmetric encryption algorithms with key lengths of 128 bits require astronomical resources to complete inspection of the whole set of keys, and even a union of many computers in a network for the exhaustive key search fails in the foreseeable future. Thus, as part of an international project managed distributed.net while "overpower" the 64-bit key, and from December 2002 until now we are working on breaking the 72-bit, and by the time of this writing, was enumerated at least 0.2% all possible encryption keys.
Destruction of information
Encryption, as strange as it may seem, is very effective for the destruction of information. If the encrypted information, and destroy the encryption key, then with the proper length, and as a key and strong encryption algorithms to recover data would be impossible, since the encrypted data without the key - just garbage.
Thus, in some applications that require special rules to eliminate data media, it is often enough to encrypt data and to destroy in case the encryption key, the more that a few tens of bytes is much easier to destroy than a few hundred gigabytes.
This may be a "soft" alternative or addition to a special device for the destruction of information, after-discharge media usually comes into disrepair.
Information security software on disks
The most obvious embodiment of the system of information security software with its centralized storage provides for a "transparent" encryption of data stored on hard drives. This means that all of the data when they are written to the disk is automatically encrypted, and reading - decrypted. Encryption is performed software driver-filter, the key is in RAM.
This system is installed on the server to which it is directly connected to the protected media information. It can be conventional hard drives (IDE or SCSI), RAID-arrays, storage, connected by Fibre Channel, etc.
Usually the core of the system consists of two drivers (Fig. 1). One is the filter input and output corresponding to the partition and the second kriptoyadro implements one or more encryption algorithms and can be a complete driver and dynamic library zero rings.
This architecture, first, allows the use of one common kriptoyadro for various applications, and second, providing greater flexibility in the difficult task of overcoming the statutory restrictions on the regulation of cryptographic tools. Individual modules provide the user interface to the core of the system, with the remote administration system from any workstation on the network or over the Internet.
It is also worth mentioning feature, without which none of the developers cost of such systems. We are talking about the possibility of an emergency shutdown system kernel and delete the encryption keys from the server memory to a special signal - "anxiety." This signal can also be made remotely, and the spectrum of devices and provides an alarm to dovolnoshirok - ranging from the usual buttons, closing two lines on the RS-232 port to the remote key, GSM-modem or alarm sensor.
A number of systems, working on the principle described above, the stress that Russian designers have achieved in this area the most success.
Below we consider the functionality of products in its class, as standard, are present in almost all foods, and unique, unparalleled.
Key Generation
Generation of encryption keys - this is the most delicate moment of any system of data encryption. From how to generate an encryption key depends resistance system: for any error or negligence in the implementation of this process can greatly simplify and reduce the resistance of cryptanalysis.
Best encryption key - it's completely random sequence of bits, and in digital devices random factor is usually kept to a minimum. The most expedient way to generate keys - a measurement interval between keystrokes in the user experience and the formation on the basis of their random sequence.
Quorum encryption keys
Quorum encryption keys - a new feature that is not present in all systems. It can be useful when you want to distribute the encryption key among multiple users, to reduce the risk of the "human factor". For example, the encryption key using a special formula is divided into n parts of equal size, so that is enough to restore any parts of k (k ≤ n). In this case we speak of a quorum of the keys k / n.
In practice, common scheme quorum keys 2/2, 2/3, 2/5 and 3/5. Example, in a 2/3 switch is divided into three parts, one is given a system administrator, security officer and the head of the company. To gain access to the encrypted data, you need to upload any two. This retains the flexibility of the system and significantly reduce the risk - a compromise of any one part of the key will not lead to the compromise of encrypted data.
Initial encoding disc
After installing the system and generate encryption keys to encrypt those disks on which the confidential information is stored. This is done once, immediately after installation, and key generation. Depending on the amount of the initial encoding of the encrypted partition can take a long time, in addition, some systems monopoly to block access to encrypted partitions, not allowing other processes to access it. It is not always convenient, because in today's business environment, even a simple server at night is not always acceptable.
In a more advanced product offers several features that reduce server downtime to a minimum. First, the so-called background encryption section. In this case the encryption section runs in the background, and access to the section is not blocked. Filter driver at a time knows where to draw the line between encrypted and unencrypted part of the section, and can correctly process the read-write.
Second, it's a quick format partition encryption. This feature is designed for those occasions when the encrypted partition does not contain any data, such as when the system is just bought a server. Surprisingly, some of the system even though the section is empty, you still force the user to encrypt it.
In other systems, you can just "turn on" transparent encryption mode for the selected partition, and then create a file system during routine tasks quickly format. Thus, we obtain a new encrypted partition with a file system. True, this method is suitable only for the empty, containing no useful information section.
Centralized Administration
For ease of management system administration console to provide simultaneous control of multiple servers from any workstation on the network or over the Internet. Thus all traffic sent over the network should be encrypted, as in the management of open channels can be transmitted to the encryption keys. For mutual authentication of client and server, and to exchange session keys, usually a special algorithm, for example, the Diffie - Hellman.
Is not very good approach when the high-level protocols, standard remote control, such as the MMC (Microsoft Management Console) or Remote Desktop. The reason is that these protocols do not provide built-in security features of communication channels, so that has to take care of it by itself, and the technology in general MMC protocol is based on RPC, which, first, requires for its work over a dozen ports of TCP / IP, and secondly, as the recent virus outbreaks, very unsafe.
Security software information on tapes
Despite the apparent differences, encryption of data in the backup process has much in common with the systems of protection discs. However, for some reason the information protection system on the tapes have not received such a development. In existence today, these systems can only be called a built-in the latest backup software BrightStor ARCserve Backup from CA (www.ca.com) encryption functionality and universal system of Zbackup SecurIT.
Note that the incorporation of functional data encryption, backup software - is a logical and expected the process because, unlike CDs, which can work with almost any application, record on tape in the backup process is performed by a single application that completely before recording can encrypt the data. However, this functionality is built in only one software package for backing up to tape, and the implementation itself, in the opinion of many experts, is not able to satisfy the most demanding users.
Why dwell on the universal system of protection of information when it was backed up to tape Zbackup. We emphasize that this is not a backup system, it only protects the data on magnetic tapes, recorded during normal operation of the backup software (eg, ARCserve Backup from CA or Veritas Backup Exec) to the servers, and components such backup software that directly interact with the backup device - tape drives. In other words, Zbackup installed on servers running services support tape (Tape Engine Service); on workstations with software - backup agents to install it is not required.
Encryption is performed at the level of physical sectors, formatting tapes and record them directly by the backup software. To start the encryption enough to upload the encryption key and link it to the backup device (tape drive).
After installation Zbackup in backup software does not change, but the data contained on the encrypted tapes are not available for simple reading of any programs, because the data is on the tape is encrypted, decrypted when read and encrypted recording. When you try to read encrypted tapes in the backup program without entering the appropriate decryption keys such tapes will be recognized as a tape of unknown format or empty.
Hardware data protection storage
Despite the versatility and convenience of software, there are situations in which they apply. We consider a number of such situations.
Bottlenecks
Despite the fact that the producers of modern software systems are paying a lot of attention to optimize critical sections of code, and the average loss of performance does not exceed 10-15%, sometimes it is not acceptable.
NAS devices
Typical devices NAS (network attached storage) is a data storage and network operating systems in a single device. Thus, the term "computer as a file server", which you can put any additional software, in fact, to what does not apply.
Some implementations of SAN architecture
In some cases, when a mass storage of data used architecture SAN, application software protection as possible. For example, in the procedure of serverless backup data is copied over the network directly to the SAN storage array to a tape library without any additional equipment or software.
In these and in other situations more appropriate use of hardware protection of data warehouses.
Development and production of defense equipment storage - quite a new area of information security. Yet designers and manufacturers of these devices have achieved impressive results and demonstrate their engineering.
For example, a data storage protection DataFort (Fig. 2), produced by Decru (www.decru.com), was included in the prestigious list of eWeek Top 10 Products of 2004. Consider its features in more detail.
Decru DataFort is a device in a rack format 1U or 2U, which can be connected to an Ethernet or Fibre Channel. The device can encrypt data stored on the NAS or SAN devices and tape.
The main component of the device - specially designed kriptoprotsessor SEP (Storage Encryption Processor), which provides encryption at several gigabits per second and secure storage of encryption keys.
Key Management Scheme DataFort deserves a more detailed description. To encrypt the data partitions, directories, and even individual files, you can use different keys, which are called by the workers. Working encryption keys are stored directly in a secure vault SEP and never leave it outside in the clear.
Backup of the keys stored on a dedicated workstation running Windows (see Figure 3), which installed the Lifetime Key Management (LKM). Back up through the protocol TCP / IP, and working keys encrypted with the master key devices DataFort. The master key is inserted into the unit when it is initialized, prior to use, and is stored on a smart card using the structure of the quorum keys 2/3, 2/5 or 3/5. The master key is only required if you initialize a new device for loading a configuration and working keys from LKM. The rest of the smart card with a master key is not needed and can be stored at the proxies in a safe place.
To protect the data on the SAN using the original idea of the partition storage on cryptographic sections Cryptainer, information which can be encrypted by different keys for different groups of users. It helps to solve one of the major problems of data protection and access control in the storage SAN, which is that the information for different user groups and different levels of confidentiality is stored on one device.
Thus, the device is fully transparent DataFort for data warehousing, and customers, and does not require any changes to the software on the client and server locations. In essence, DataFort acts as a sort of proxy, sounding data repository for customer and client data warehouse.
DataFort device may come with encryption turned off, while it only serves to restrict access.
In order to improve system reliability and performance multiple devices DataFort (up to 32) can be combined into a cluster.
Alas, hardware storage protection is one very serious drawback - very high cost. Compared to the software cost of hardware up to 10-20 times, and given the additional cost of the acquisition and implementation of such devices - if not more. Thus, to afford such a luxury can only fairly large companies, for which costs 100 thousand dollars just to protect the data warehouse will be justified.