EBA欧洲银行-Annex-8-Standard-on-Mobile-Code_13页_237kb
报告摘要
European Commission Information System Security Policy: Standard on Mobile Code
Core Content
This document outlines the European Commission's Standard on Mobile Code, adopted in 2011, to ensure the safe execution of mobile code within its information systems. It defines mobile code as any code that can be downloaded and executed on end user devices, often without the user's knowledge or intervention. Mobile code can be used for both legitimate purposes (e.g., rich user interfaces in web browsers) and malicious activities (e.g., spreading viruses).
The standard is designed to prevent unauthorized use, system exploitation, and malicious code propagation across the European Commission's network. It is structured into server-side and client-side rules to address the different aspects of mobile code implementation and execution.
Main Objectives
- To provide measures for the safe execution of legitimate mobile code.
- To prevent mobile code from exploiting system weaknesses and spreading across the EC network.
Scope
The standard applies to all European Commission information systems that use or execute mobile code. It covers all types of mobile code technologies, including those with potentially dangerous content.
Threats Covered
The standard addresses the following threats:
- T23 - Disclosure: Unauthorized exposure of sensitive information.
- T24 - Data from untrustworthy sources: Data received from unverified sources.
- T26 - Tampering with software: Unauthorized modification of software.
- T30 - Saturation of the information system: Overloading the system with excessive requests.
- T31 - Software malfunction: Malfunction of software due to malicious code.
- T36 - Corruption of data: Data being altered or destroyed.
- T39 - Abuse of rights: Unauthorized use of system privileges.
Terminology
Key terms defined in the document include:
- ActiveX: Microsoft interfaces for linking desktop apps to the web.
- Applet: Limited functionality application, often portable.
- Certificate: Electronic text verifying the owner's credentials.
- Code Signing: Digital signature to confirm software author and integrity.
- Flash: Multimedia platform for web content and applications.
- Java: Cross-platform programming language.
- JavaScript: Cross-platform scripting language in web browsers.
- LotusScript: IBM Lotus-based scripting language.
- Mobile Agent: Software that migrates between computers and continues execution.
- Runtime Environment: Environment where mobile code is executed, such as browsers or JRE.
- Script: Instructions executed by another program.
- Self-signed Certificate: Certificate signed by the creator, not a trusted CA.
- Shockwave: Adobe multimedia player for web content.
- Silverlight: Microsoft framework for rich internet applications.
- Unmediated Access: Full access to system resources without control.
- VBScript: Microsoft scripting language for IE and Windows Script Host.
- VBA: Visual Basic for Applications in Microsoft Office.
Risk Categories
Mobile code technologies are classified into two risk categories:
1. High Risk Mobile Code
- Characteristics: Full access to system resources via unmediated access.
- Examples: Binary executables, ActiveX, Java programs, Windows Scripting Host scripts, shell or batch scripts.
- Security Measures: Must be securely delivered (e.g., via encrypted connections or EC-signed certificates). Execution must be blocked unless from a trusted source.
2. Standard Risk Mobile Code
- Characteristics: Full or limited functionality via mediated or controlled access.
- Examples: Java applets, VBA, JavaScript, Shockwave, Flash, Silverlight.
- Security Measures: Code signing is recommended, but not mandatory. Execution must be controlled and monitored to prevent misuse.
Security Controls
Server Side
- Code Signing: Must be used for high risk mobile code. If not possible, commercial code signing may be used.
- Risk Assessment: Before implementing any mobile code, risks must be assessed and appropriate measures applied.
- Secure Configuration: Ensure secure setup of runtime environments and restrict unauthorized code execution.
- Data Validation: Input validation must be performed to prevent malicious data from affecting the system.
Client Side
- Runtime Environment Management: Minimize the number of runtime environments installed and ensure they are securely configured.
- Prevent Unauthorized Execution: Block high risk mobile code from external sources and prevent users from changing security settings.
- Patch Management: Ensure all runtime environments are up-to-date.
- Anti-Malware Software: All client devices must have up-to-date anti-malware.
- Application Lockdown: Restrict installation and execution of unauthorized software.
- User Prompting: Web browsers and other mobile code-enabled products must prompt the user for agreement before executing high risk mobile code.
References
- Commission Decision (2001/844/EC, ECSC, Euratom)
- Commission Decision C(2006) 3602
- Implementing rules for C(2006) 3602
- Standard on Information Security Risk Management
- Standard on Controls against Malicious Code
- Standard on Secure Systems Development
- Standard on Management of Technical Vulnerabilities
Related Documents
- ISO/IEC 27001 (2005-06-15)
- ISO/IEC 17799 (2005-06-15)
- NIST SP 800-28 Version 2 – Guidelines on Active Content and Mobile Code
- Model-Carrying Code (MCC) – A new paradigm for mobile-code security
Summary
The standard emphasizes the importance of controlling mobile code to protect the European Commission's information systems from potential security threats. It provides detailed guidelines for both server-side and client-side implementation, focusing on code signing, secure configuration, input validation, and user control. The classification of mobile code into high risk and standard risk helps in applying appropriate security measures. Overall, the goal is to enable legitimate use while blocking malicious code to maintain system integrity and security.
试读结束,高清完整版pdf/doc/ppt,请点下载