Free Executive Summary
Total Page:16
File Type:pdf, Size:1020Kb
http://www.nap.edu/catalog/1581.html We ship printed books within 1 business day; personal PDFs are available immediately. Computers at Risk: Safe Computing in the Information Age System Security Study Committee, Commission on Physical Sciences, Mathematics, and Applications, National Research Council ISBN: 0-309-57460-9, 320 pages, 6 x 9, (1991) This PDF is available from the National Academies Press at: http://www.nap.edu/catalog/1581.html Visit the National Academies Press online, the authoritative source for all books from the National Academy of Sciences, the National Academy of Engineering, the Institute of Medicine, and the National Research Council: • Download hundreds of free books in PDF • Read thousands of books online for free • Explore our innovative research tools – try the “Research Dashboard” now! • Sign up to be notified when new books are published • Purchase printed books and selected PDF files Thank you for downloading this PDF. If you have comments, questions or just want more information about the books published by the National Academies Press, you may contact our customer service department toll- free at 888-624-8373, visit us online, or send an email to [email protected]. This book plus thousands more are available at http://www.nap.edu. Copyright © National Academy of Sciences. All rights reserved. Unless otherwise indicated, all materials in this PDF File are copyrighted by the National Academy of Sciences. Distribution, posting, or copying is strictly prohibited without written permission of the National Academies Press. Request reprint permission for this book. i e h t be ion. om r ibut f r t cannot r at not o f Computers at Risk however, version ng, i t paper book, at ive Safe Computing In the Information Age at rm o riginal horit ic f o e h t he aut t om r as ing-specif t ion ed f peset System Security Study Committee y Computer Science and Telecommunications Board http://www.nap.edu/catalog/1581.html Computers atRisk:SafeComputingintheInformationAge publicat her t iles creat is h Commission on Physical Sciences, Mathematics, and Applications t L f M of and ot National Research Council X om yles, r f st version print posed e h heading Copyright © National Academy ofSciences. Allrights reserved. recom use t breaks, ease l been P word has ed. hs, insert ally line lengt original work e h t he original; ion of t at o ue t r have been accident y t a represent m are l a errors age breaks P is new digit h pographic y iles. T t f e ile: ng i f t F D P peset and som is y h t NATIONAL ACADEMY PRESS ined, a bout 1991 A ret original t ii e h t be ion. om National Academy Press 2101 Constitution Avenue, N.W. Washington, D.C. 20418 r ibut f r t cannot NOTICE: The project that is the subject of this report was approved by the Governing Board of the r at not National Research Council, whose members are drawn from the councils of the National Academy o f of Sciences, the National Academy of Engineering, and the Institute of Medicine. The members of the committee responsible for the report were chosen for their special competences and with regard however, for appropriate balance. version ng, i This report has been reviewed by a group other than the authors according to procedures t paper book, at ive approved by a Report Review Committee consisting of members of the National Academy of Sci- at rm ences, the National Academy of Engineering, and the Institute of Medicine. o The National Academy of Sciences is a private, nonprofit, self-perpetuating society of distin- riginal horit ic f guished scholars engaged in scientific and engineering research, dedicated to the furtherance of o e science and technology and to their use for the general welfare. Upon the authority of the charter h t he aut granted to it by the Congress in 1863, the Academy has a mandate that requires it to advise the fed- t om eral government on scientific and technical matters. Dr. Frank Press is president of the National r as ing-specif t Academy of Sciences. ion ed f The National Academy of Engineering was established in 1964, under the charter of the peset National Academy of Sciences, as a parallel organization of outstanding engineers. It is autonomous y in its administration and in the selection of its members, sharing with the National Academy of Sci- http://www.nap.edu/catalog/1581.html Computers atRisk:SafeComputingintheInformationAge publicat ences the responsibility for advising the federal government. The National Academy of Engineering her t iles creat is also sponsors engineering programs aimed at meeting national needs, encourages education and h t L f research, and recognizes the superior achievements of engineers. Dr. Robert M. White is president M of and ot of the National Academy of Engineering. X The Institute of Medicine was established in 1970 by the National Academy of Sciences to om yles, r secure the services of eminent members of appropriate professions in the examination of policy mat- f st version ters pertaining to the health of the public. The Institute acts under the responsibility given to the National Academy of Sciences by its congressional charter to be an adviser to the federal govern- print posed ment and, upon its own initiative, to identify issues of medical care, research, and education. Dr. e h Samuel O. Thier is president of the Institute of Medicine. heading Copyright © National Academy ofSciences. Allrights reserved. The National Research Council was organized by the National Academy of Sciences in 1916 to recom use t associate the broad community of science and technology with the Academy's purposes of further- ing knowledge and advising the federal government. Functioning in accordance with general poli- breaks, ease cies determined by the Academy, the Council has become the principal operating agency of both the l been P National Academy of Sciences and the National Academy of Engineering in providing services to word has the government, the public, and the scientific and engineering communities. The Council is adminis- ed. hs, tered jointly by both Academies and the Institute of Medicine. Dr. Frank Press and Dr. Robert M. White are chairman and vice chairman, respectively, of the National Research Council. insert Support for this project was provided by the Defense Advanced Research Projects Agency ally under Contract No. N00014-89-J-1731. However, the content does not necessarily reflect the posi- line lengt tion or the policy of the Defense Advanced Research Projects Agency or the government, and no original work e official endorsement should be inferred. h t Library of Congress Cataloging-in-Publication Data Computers at risk: safe computing in the information age / System Security Study Committee, he original; Computer Science and Telecommunications Board, Commission on Physical Sciences, Mathemat- ion of t at o ics, and Applications, National Research Council. p. cm. ue t r have been accident Includes bibliographical references. y t a represent ISBN 0-309-04388-3 m are l a 1. Computer security. I. National Research Council (U.S.). errors Computer Science and Telecommunications Board. System Security Study Committee. QA76.9.A25C6663 1990 age breaks 005.8—dc20 90-22329 P CIP is new digit h pographic Copyright © 1991 by the National Academy of Sciences y iles. T t f e ile: No part of this book may be reproduced by any mechanical, photographic, or electronic pro- ng i f t cess, or in the form of a phonographic recording, nor may it be stored in a retrieval system, transmit- F D ted, or otherwise copied for public or private use, without written permission from the publisher, P peset except for the purposes of official use by the U.S. government. and som is y h t Printed in the United States of America First Printing, December 1990 Second Printing, March 1991 ined, a bout Third Printing, April 1992 Fourth Printing January 1992 Fifth Printing March 1994 A ret original t iii e h t be ion. om r ibut f r t cannot SYSTEM SECURITY STUDY COMMITTEE r at not o f DAVID D. CLARK, Massachusetts Institute of Technology, Chairman however, W. EARL BOEBERT, Secure Computing Technology Corporation version ng, i t paper book, SUSAN GERHART, Microelectronics and Computer Technology Corporation at ive at rm JOHN V. GUTTAG, Massachusetts Institute of Technology o riginal horit RICHARD A. KEMMERER, University of California at Santa Barbara ic f o e STEPHEN T. KENT, BBN Communications h t he aut SANDRA M. MANN LAMBERT, Security Pacific Corporation t om r as ing-specif BUTLER W. LAMPSON, Digital Equipment Corporation t ion JOHN J. LANE, Shearson, Lehman, Hutton, Inc. ed f peset M. DOUGLAS McILROY, AT&T Bell Laboratories y PETER G. NEUMANN, SRI International http://www.nap.edu/catalog/1581.html Computers atRisk:SafeComputingintheInformationAge publicat her t iles creat is MICHAEL O. RABIN, Harvard University h t L f WARREN SCHMITT, Sears Technology Services M of and ot X HAROLD F. TIPTON, Rockwell International om yles, STEPHEN T. WALKER, Trusted Information Systems, Inc. r f st version WILLIS H. WARE, The RAND Corporation MARJORY S. BLUMENTHAL, Staff Director print posed e h FRANK PITTELLI, CSTB Consultant heading Copyright © National Academy ofSciences. Allrights reserved. DAMIAN M. SACCOCIO, Staff Officer recom use t MARGARET A. KNEMEYER, Staff Associate breaks, DONNA F. ALLEN, Administrative Secretary ease l been P CATHERINE A. SPARKS, Senior Secretary word has ed. hs, insert ally line lengt original work e h t he original; ion of t at o ue t r have been accident y t a represent m are l a errors age breaks P is new digit h pographic y iles.