Initial CTBT international monitoring system security findings and recommendations
An initial security evaluation of the proposed International Monitoring System (IMS) suggests safeguards at various points in the IMS to provide reliable information to the user community. Modeling the IMS as a network of information processing nodes provides a suitable architecture for assessing data surety needs of the system. The recommendations in this paper include the use of public-key authentication for data from monitoring stations and for commands issued to monitoring stations. Other monitoring station safeguards include tamper protection of sensor subsystems, preservation of data (i.e. short-term archival), and limiting the station`s network services. The recommendations for NDCs focus on the need to provide a backup to the IDC for data archival and data routing. Safeguards suggested for the IDC center on issues of reliability. The production of event bulletins should employ {open_quotes}two-man{close_quotes} procedures. As long as the data maintains its integrity, event bulletins can be produced by NDCs as well. The effective use of data authentication requires a sound key management system. Key management systems must be developed for the authentication of data, commands, and event bulletins if necessary. It is recommended that the trust placed in key management be distributed among multiple parties. The recommendations found in this paper offer safeguards for identified vulnerabilities in the IMS with regard to data surety. However, several outstanding security issues still exist. These issues include the need to formalize and obtain a consensus on a threat model and a trust model for the IMS. The final outstanding security issue that requires in-depth analysis concerns the IDC as a potential single point of failure in the current IMS design.
Year of publication: |
2010-02-18
|
---|---|
Authors: | Craft, R.L. ; Draelos, T.J. |
Subject: | military technology, weaponry, and national defense | NUCLEAR EXPLOSION DETECTION | DATA ACQUISITION SYSTEMS | PHYSICAL PROTECTION | RELIABILITY | SECURITY | NUCLEAR EXPLOSIONS | MONITORING |
Saved in:
Saved in favorites
Similar items by subject
-
International physical protection self-assessment tool for chemical facilities.
Tewell, Craig R., (2010)
-
Buehring, W. A., (2008)
-
Fisher, R. E., (2009)
- More ...
Similar items by person