人员–访问管理, 生物测定 物理–综合访问控制 管理–安全教育 网络-加密、配置控制 S/W & O/S --Testing, Evaluation, Certification H/W --TCB, Tamper-proof, Encryption 安全威胁 Security Threats threats e from a range of sources various surveys, with results of order: 55% human error 10% disgruntled employees 10% dishonest employees 10% outsider access also have "acts of god" (fire, flood etc) -security attacks 侦听(interception) –中途窃听,攻击机密性 服务中断(interruption) –攻击可用性 信息篡改(modification - of info) -攻击完整性 消息伪造(fabrication - of info)- 攻击认证性(attacks authentication ) Passive vs Active Attacks