| Previous | Table of Contents | Next |
Hackers and computer viruses in an AS/400? This cant be. These things happen only to Unix and PC systems. I remember seeing the movie Jurassic Park where near the end of the film the young girl comes upon the computer that was sabotaged and that allowed the dinosaurs to escape. Its a Unix! she squeals and immediately breaks into the system and fixes the problem. I thought to myself, Of course, what do you expect from Unix? Then there was the computer virus that was loaded into the alien spacecraft in the movie Independence Day. Most of us never before realized that aliens use Apple Macintosh computers. But they must, because the virus worked, and the entire world was saved. Numerous other films depict a computer nerd hacking into someones system, or some disgruntled employee planting a virus in the company computer, but none of this can happen to an AS/400. Or can it?
We are all very comfortable knowing that, like so many other functions on the AS/400, security was built in from the beginning, as a part of the original design. AS/400 security was not an afterthought, as it is on so many other computer systems. But the security features in an AS/400 are not much good unless they are used, and many AS/400 customers are not using enough of them. In a client/server environment, for example, you must take special care to safeguard AS/400 data against nonsecure clients such as Windows 95 and Windows NT. Furthermore, in todays networked world, many AS/400s are being connected to the Internet; again, certain security features must be used to protect the business information assets. Fortunately, the AS/400s integrated security provides a strong foundation for securing the system. In the following sections, we look at the AS/400s security features and identify how you can use them to protect the system.
In the past, securing a computer system was relatively simple. Putting a lock on the computer room door and making all end users enter a password before they could access the computer was usually enough. Todays world is not so simple. The biggest security exposures for AS/400s occur when they are connected in a network environment. The network itself may be a LAN within the business or a worldwide network such as the Internet. In either case, the AS/400 provides the tools to minimize or completely eliminate these exposures. Securing your computer system is very much like securing your house or car: It is a tradeoff between the cost and how much risk you are willing to take.
Obviously, though, not every AS/400 installation needs the same level of security. The customer must be able to select and configure the level of security for the system itself. The challenge of designing a good security system is to design it in such a way that the system can run without any security, with limited security, or with full security, while the underlying security functions are always active.
There are still systems locked away in rooms with very limited access. Such a system probably doesnt require the same high level of security as a system connected to the Internet. Over time, the security needs of a given system installation also may change. The AS/400s integrated security is sufficiently flexible to change as a systems security needs change.
AS/400 security is implemented as a combination of OS/400s security component and SLICs authority component. The levels of systemwide security are implemented in OS/400. OS/400 relies on the object-based security functions provided at the MI to enforce the security level. For example, as we saw in Chapter 5, the MI validates security whenever an object is accessed. SLIC implements these MI functions and provides the ongoing object security. Called authorization, this type of security is designed to protect objects from unauthorized access or modification.
Some parts of the AS/400s security implementation exist entirely above the MI in OS/400. An example is the definition of the system security values. Other parts of security exist entirely below the MI in SLIC. An example of this is object authorization. Still other parts exist partly above and partly below the MI. An example here is the privileged-instruction and special-authority support. In the following sections, we look at the components both above and below the MI.
The AS/400 is designed for businesses that require levels of security ranging from nothing at all to full government-certifiable security. By setting a system value, we can configure five increasing levels of security: no security, password security, resource security, operating-system security, and certifiable security. When an AS/400 is configured, four system values dealing with security must be specified. These values are QAUDJRL, QMAXSIGN, QRETSVRSEC, and QSECURITY.
The system value that determines the level of security enforcement is QSECURITY. The System/38 and the original AS/400 had only three levels of system security. At V1R3 of OS/400, we added a fourth level of security. We added an even higher level of security at V2R3, to bring the total number of levels to five. The valid values for QSECURITY are 10, 20, 30, 40, and 50.
The AS/400 also supports an optional security-auditing function. If this function is specified, certain security events are journaled. The specific events that are logged in the security audit journal are determined by the value specified in the QAUDJRL system value and the level of system security specified. Events that can be journaled include authorization failures, deleted objects, the identification of programs that use restricted instructions, and other security-related events. The security auditor in the business can analyze the contents of this journal.
You specify the maximum number of sign-on attempts with the QMAXSIGN system value. If the number of unsuccessful attempts to sign on to the system exceeds this number, the terminal or device that attempted the sign-on is varied off. A device that is varied off no longer has access to the system. This system value effectively disconnects anyone who attempts several different passwords to gain access to the system. The value is reset each time a valid sign-on occurs at the device.
| Previous | Table of Contents | Next |