4949
INFORMATIONAL

Internet Security Glossary, Version 2

Authors: R. Shirey
Date: August 2007
Stream: INDEPENDENT
Obsoletes: RFC 2828

Abstract

This Glossary provides definitions, abbreviations, and explanations of terminology for information system security. The 334 pages of entries offer recommendations to improve the comprehensibility of written material that is generated in the Internet Standards Process (RFC 2026). The recommendations follow the principles that such writing should (a) use the same term or definition whenever the same concept is mentioned; (b) use terms in their plainest, dictionary sense; (c) use terms that are already well-established in open publications; and (d) avoid terms that either favor a particular vendor or favor a particular technology or mechanism over other, competing techniques that already exist or could be developed. This memo provides information for the Internet community.

Network Working Group                                          R. Shirey
Request for Comments: 4949                                   August 2007
FYI: 36
Obsoletes: <a href="./rfc2828">2828</a>
Category: Informational


                 <span class="h1">Internet Security Glossary, Version 2</span>

Status of This Memo

   This memo provides information for the Internet community.  It does
   not specify an Internet standard of any kind.  Distribution of this
   memo is unlimited.

Copyright Notice

   Copyright (C) The IETF Trust (2007).

RFC Editor Note

   This document is both a major revision and a major expansion of the
   Security Glossary in <a href="./rfc2828">RFC 2828</a>. This revised Glossary is an extensive
   reference that should help the Internet community to improve the
   clarity of documentation and discussion in an important area of
   Internet technology. However, readers should be aware of the
   following:

   (1) The recommendations and some particular interpretations in
   definitions are those of the author, not an official IETF position.
   The IETF has not taken a formal position either for or against
   recommendations made by this Glossary, and the use of <a href="./rfc2119">RFC 2119</a>
   language (e.g., SHOULD NOT) in the Glossary must be understood as
   unofficial. In other words, the usage rules, wording interpretations,
   and other recommendations that the Glossary offers are personal
   opinions of the Glossary's author. Readers must judge for themselves
   whether or not to follow his recommendations, based on their own
   knowledge combined with the reasoning presented in the Glossary.

   (2) The glossary is rich in the history of early network security
   work, but it may be somewhat incomplete in describing recent security
   work, which has been developing rapidly.









<span class="grey">Shirey                       Informational                      [Page 1]</span>

<span id="page-2" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


Abstract

   This Glossary provides definitions, abbreviations, and explanations
   of terminology for information system security. The 334 pages of
   entries offer recommendations to improve the comprehensibility of
   written material that is generated in the Internet Standards Process
   (<a href="./rfc2026">RFC 2026</a>). The recommendations follow the principles that such
   writing should (a) use the same term or definition whenever the same
   concept is mentioned; (b) use terms in their plainest, dictionary
   sense; (c) use terms that are already well-established in open
   publications; and (d) avoid terms that either favor a particular
   vendor or favor a particular technology or mechanism over other,
   competing techniques that already exist or could be developed.

Table of Contents

   <a href="#section-1">1</a>. Introduction ....................................................<a href="#page-3">3</a>
   <a href="#section-2">2</a>. Format of Entries ...............................................<a href="#page-4">4</a>
      <a href="#section-2.1">2.1</a>. Order of Entries ...........................................<a href="#page-4">4</a>
      <a href="#section-2.2">2.2</a>. Capitalization and Abbreviations ...........................<a href="#page-5">5</a>
      <a href="#section-2.3">2.3</a>. Support for Automated Searching ............................<a href="#page-5">5</a>
      <a href="#section-2.4">2.4</a>. Definition Type and Context ................................<a href="#page-5">5</a>
      <a href="#section-2.5">2.5</a>. Explanatory Notes ..........................................<a href="#page-6">6</a>
      <a href="#section-2.6">2.6</a>. Cross-References ...........................................<a href="#page-6">6</a>
      <a href="#section-2.7">2.7</a>. Trademarks .................................................<a href="#page-6">6</a>
      <a href="#section-2.8">2.8</a>. The New Punctuation ........................................<a href="#page-6">6</a>
   <a href="#section-3">3</a>. Types of Entries ................................................<a href="#page-7">7</a>
      <a href="#section-3.1">3.1</a>. Type "I": Recommended Definitions of Internet Origin .......<a href="#page-7">7</a>
      <a href="#section-3.2">3.2</a>. Type "N": Recommended Definitions of Non-Internet Origin ...<a href="#page-8">8</a>
      <a href="#section-3.3">3.3</a>. Type "O": Other Terms and Definitions To Be Noted ..........<a href="#page-8">8</a>
      <a href="#section-3.4">3.4</a>. Type "D": Deprecated Terms and Definitions .................<a href="#page-8">8</a>
      <a href="#section-3.5">3.5</a>. Definition Substitutions ...................................<a href="#page-8">8</a>
   <a href="#section-4">4</a>. Definitions .....................................................<a href="#page-9">9</a>
   <a href="#section-5">5</a>. Security Considerations .......................................<a href="#page-343">343</a>
   <a href="#section-6">6</a>. Normative Reference ...........................................<a href="#page-343">343</a>
   <a href="#section-7">7</a>. Informative References ........................................<a href="#page-343">343</a>
   <a href="#section-8">8</a>. Acknowledgments ...............................................<a href="#page-364">364</a>














<span class="grey">Shirey                       Informational                      [Page 2]</span>

<span id="page-3" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


<span class="h2"><a class="selflink" id="section-1" href="#section-1">1</a>. Introduction</span>

   This Glossary is *not* an Internet Standard, and its recommendations
   represent only the opinions of its author. However, this Glossary
   gives reasons for its recommendations -- especially for the SHOULD
   NOTs -- so that readers can judge for themselves what to do.

   This Glossary provides an internally consistent and self-contained
   set of terms, abbreviations, and definitions -- supported by
   explanations, recommendations, and references -- for terminology that
   concerns information system security. The intent of this Glossary is
   to improve the comprehensibility of written materials that are
   generated in the Internet Standards Process (<a href="./rfc2026">RFC 2026</a>) -- i.e., RFCs,
   Internet-Drafts, and other items of discourse -- which are referred
   to here as IDOCs. A few non-security, networking terms are included
   to make the Glossary self-contained, but more complete glossaries of
   such terms are available elsewhere [<a href="#ref-A1523" title=""American National Standard Telecom Glossary"">A1523</a>, <a href="#ref-F1037" title=""Glossary of Telecommunications Terms"">F1037</a>, <a href="#ref-R1208" title=""A Glossary of Networking Terms"">R1208</a>, <a href="#ref-R1983" title=""Internet Users' Glossary"">R1983</a>].

   This Glossary supports the goals of the Internet Standards Process:

   o  Clear, Concise, Easily Understood Documentation

      This Glossary seeks to improve comprehensibility of security-
      related content of IDOCs. That requires wording to be clear and
      understandable, and requires the set of security-related terms and
      definitions to be consistent and self-supporting. Also,
      terminology needs to be uniform across all IDOCs; i.e., the same
      term or definition needs to be used whenever and wherever the same
      concept is mentioned. Harmonization of existing IDOCs need not be
      done immediately, but it is desirable to correct and standardize
      terminology when new versions are issued in the normal course of
      standards development and evolution.

   o  Technical Excellence

      Just as Internet Standard (STD) protocols should operate
      effectively, IDOCs should use terminology accurately, precisely,
      and unambiguously to enable standards to be implemented correctly.

   o  Prior Implementation and Testing

      Just as STD protocols require demonstrated experience and
      stability before adoption, IDOCs need to use well-established
      language; and the robustness principle for protocols -- "be
      liberal in what you accept, and conservative in what you send" --
      is also applicable to the language used in IDOCs that describe
      protocols. Using terms in their plainest, dictionary sense (when
      appropriate) helps to make them more easily understood by



<span class="grey">Shirey                       Informational                      [Page 3]</span>

<span id="page-4" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      international readers. IDOCs need to avoid using private, newly
      invented terms in place of generally accepted terms from open
      publications. IDOCs need to avoid substituting new definitions
      that conflict with established ones. IDOCs need to avoid using
      "cute" synonyms (e.g., "Green Book"), because no matter how
      popular a nickname may be in one community, it is likely to cause
      confusion in another.

      However, although this Glossary strives for plain, internationally
      understood English language, its terms and definitions are biased
      toward English as used in the United States of America (U.S.).
      Also, with regard to terminology used by national governments and
      in national defense areas, the glossary addresses only U.S. usage.

   o  Openness, Fairness, and Timeliness

      IDOCs need to avoid using proprietary and trademarked terms for
      purposes other than referring to those particular systems. IDOCs
      also need to avoid terms that either favor a particular vendor or
      favor a particular security technology or mechanism over other,
      competing techniques that already exist or might be developed in
      the future. The set of terminology used across the set of IDOCs
      needs to be flexible and adaptable as the state of Internet
      security art evolves.

   In support of those goals, this Glossary offers guidance by marking
   terms and definitions as being either endorsed or deprecated for use
   in IDOCs. The key words "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY",
   and "OPTIONAL" are intended to be interpreted the same way as in an
   Internet Standard (i.e., as specified in <a href="./rfc2119">RFC 2119</a> [<a href="#ref-R2119" title=""Key words for use in RFCs to Indicate Requirement Levels"">R2119</a>]). Other
   glossaries (e.g., [<a href="#ref-Raym" title=""The On-Line Hacker Jargon File"">Raym</a>]) list additional terms that deal with
   Internet security but have not been included in this Glossary because
   they are not appropriate for IDOCs.

<span class="h2"><a class="selflink" id="section-2" href="#section-2">2</a>. Format of Entries</span>

   <a href="#section-4">Section 4</a> presents Glossary entries in the following manner:

<span class="h3"><a class="selflink" id="section-2.1" href="#section-2.1">2.1</a>. Order of Entries</span>

   Entries are sorted in lexicographic order, without regard to
   capitalization. Numeric digits are treated as preceding alphabetic
   characters, and special characters are treated as preceding digits.
   Blanks are treated as preceding non-blank characters, except that a
   hyphen or slash between the parts of a multiword entry (e.g.,
   "RED/BLACK separation") is treated like a blank.





<span class="grey">Shirey                       Informational                      [Page 4]</span>

<span id="page-5" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   If an entry has multiple definitions (e.g., "domain"), they are
   numbered beginning with "1", and any of those multiple definitions
   that are RECOMMENDED for use in IDOCs are presented before other
   definitions for that entry. If definitions are closely related (e.g.,
   "threat"), they are denoted by adding letters to a number, such as
   "1a" and "1b".

<span class="h3"><a class="selflink" id="section-2.2" href="#section-2.2">2.2</a>. Capitalization and Abbreviations</span>

   Entries that are proper nouns are capitalized (e.g., "Data Encryption
   Algorithm"), as are other words derived from proper nouns (e.g.,
   "Caesar cipher"). All other entries are not capitalized (e.g.,
   "certification authority"). Each acronym or other abbreviation that
   appears in this Glossary, either as an entry or in a definition or
   explanation, is defined in this Glossary, except items of common
   English usage, such as "a.k.a.", "e.g.", "etc.", "i.e.", "vol.",
   "pp.", and "U.S.".

<span class="h3"><a class="selflink" id="section-2.3" href="#section-2.3">2.3</a>. Support for Automated Searching</span>

   Each entry is preceded by a dollar sign ($) and a space. This makes
   it possible to find the defining entry for an item "X" by searching
   for the character string "$ X", without stopping at other entries in
   which "X" is used in explanations.

<span class="h3"><a class="selflink" id="section-2.4" href="#section-2.4">2.4</a>. Definition Type and Context</span>

   Each entry is preceded by a character -- I, N, O, or D -- enclosed in
   parentheses, to indicate the type of definition (as is explained
   further in <a href="#section-3">Section 3</a>):
   -  "I" for a RECOMMENDED term or definition of Internet origin.
   -  "N" if RECOMMENDED but not of Internet origin.
   -  "O" for a term or definition that is NOT recommended for use in
      IDOCs but is something that authors of Internet documents should
      know about.
   -  "D" for a term or definition that is deprecated and SHOULD NOT be
      used in Internet documents.

   If a definition is valid only in a specific context (e.g.,
   "baggage"), that context is shown immediately following the
   definition type and is enclosed by a pair of slash symbols (/). If
   the definition is valid only for specific parts of speech, that is
   shown in the same way (e.g., "archive").








<span class="grey">Shirey                       Informational                      [Page 5]</span>

<span id="page-6" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


<span class="h3"><a class="selflink" id="section-2.5" href="#section-2.5">2.5</a>. Explanatory Notes</span>

   Some entries have explanatory text that is introduced by one or more
   of the following keywords:
   -  Deprecated Abbreviation (e.g., "AA")
   -  Deprecated Definition (e.g., "digital certification")
   -  Deprecated Usage (e.g., "authenticate")
   -  Deprecated Term (e.g., "certificate authority")
   -  Pronunciation (e.g., "*-property")
   -  Derivation (e.g., "discretionary access control")
   -  Tutorial (e.g., "accreditation")
   -  Example (e.g., "back door")
   -  Usage (e.g., "access")

   Explanatory text in this Glossary MAY be reused in IDOCs. However,
   this text is not intended to authoritatively supersede text of an
   IDOC in which the Glossary entry is already used.

<span class="h3"><a class="selflink" id="section-2.6" href="#section-2.6">2.6</a>. Cross-References</span>

   Some entries contain a parenthetical remark of the form "(See: X.)",
   where X is a list of other, related terms. Some entries contain a
   remark of the form "(Compare: X)", where X is a list of terms that
   either are antonyms of the entry or differ in some other manner worth
   noting.

<span class="h3"><a class="selflink" id="section-2.7" href="#section-2.7">2.7</a>. Trademarks</span>

   All servicemarks and trademarks that appear in this Glossary are used
   in an editorial fashion and to the benefit of the mark owner, without
   any intention of infringement.

<span class="h3"><a class="selflink" id="section-2.8" href="#section-2.8">2.8</a>. The New Punctuation</span>

   This Glossary uses the "new" or "logical" punctuation style favored
   by computer programmers, as described by Raymond [<a href="#ref-Raym" title=""The On-Line Hacker Jargon File"">Raym</a>]: Programmers
   use pairs of quotation marks the same way they use pairs of
   parentheses, i.e., as balanced delimiters. For example, if "Alice
   sends" is a phrase, and so are "Bill receives" and "Eve listens",
   then a programmer would write the following sentence:

      "Alice sends", "Bill receives", and "Eve listens".

   According to standard American usage, the punctuation in that
   sentence is incorrect; the continuation commas and the final period
   should go inside the string quotes, like this:

      "Alice sends," "Bill receives," and "Eve listens."



<span class="grey">Shirey                       Informational                      [Page 6]</span>

<span id="page-7" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   However, a programmer would not include a character in a literal
   string if the character did not belong there, because that could
   cause an error. For example, suppose a sentence in a draft of a
   tutorial on the vi editing language looked like this:

      Then delete one line from the file by typing "dd".

   A book editor following standard usage might change the sentence to
   look like this:

      Then delete one line from the file by typing "dd."

   However, in the vi language, the dot character repeats the last
   command accepted. So, if a reader entered "dd.", two lines would be
   deleted instead of one.

   Similarly, use of standard American punctuation might cause
   misunderstanding in entries in this Glossary. Thus, the new
   punctuation is used here, and we recommend it for IDOCs.

<span class="h2"><a class="selflink" id="section-3" href="#section-3">3</a>. Types of Entries</span>

   Each entry in this Glossary is marked as type I, N, O, or D:

<span class="h3"><a class="selflink" id="section-3.1" href="#section-3.1">3.1</a>. Type "I": Recommended Definitions of Internet Origin</span>

   The marking "I" indicates two things:
   -  Origin: "I" (as opposed to "N") means either that the Internet
      Standards Process or Internet community is authoritative for the
      definition *or* that the term is sufficiently generic that this
      Glossary can freely state a definition without contradicting a
      non-Internet authority (e.g., "attack").
   -  Recommendation: "I" (as opposed to "O") means that the term and
      definition are RECOMMENDED for use in IDOCs. However, some "I"
      entries may be accompanied by a "Usage" note that states a
      limitation (e.g., "certification"), and IDOCs SHOULD NOT use the
      defined term outside that limited context.

   Many "I" entries are proper nouns (e.g., "Internet Protocol") for
   which the definition is intended only to provide basic information;
   i.e., the authoritative definition of such terms is found elsewhere.
   For a proper noun described as an "Internet protocol", please refer
   to the current edition of "Internet Official Protocol Standards"
   (Standard 1) for the standardization status of the protocol.







<span class="grey">Shirey                       Informational                      [Page 7]</span>

<span id="page-8" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


<span class="h3"><a class="selflink" id="section-3.2" href="#section-3.2">3.2</a>. Type "N": Recommended Definitions of Non-Internet Origin</span>

   The marking "N" indicates two things:
   -  Origin: "N" (as opposed to "I") means that the entry has a non-
      Internet basis or origin.
   -  Recommendation: "N" (as opposed to "O") means that the term and
      definition are RECOMMENDED for use in IDOCs, if they are needed at
      all in IDOCs. Many of these entries are accompanied by a label
      that states a context (e.g., "package") or a note that states a
      limitation (e.g., "data integrity"), and IDOCs SHOULD NOT use the
      defined term outside that context or limit. Some of the contexts
      are rarely if ever expected to occur in an IDOC (e.g., "baggage").
      In those cases, the listing exists to make Internet authors aware
      of the non-Internet usage so that they can avoid conflicts with
      non-Internet documents.

<span class="h3"><a class="selflink" id="section-3.3" href="#section-3.3">3.3</a>. Type "O": Other Terms and Definitions To Be Noted</span>

   The marking "O" means that the definition is of non-Internet origin
   and SHOULD NOT be used in IDOCs *except* in cases where the term is
   specifically identified as non-Internet.

   For example, an IDOC might mention "BCA" (see: brand certification
   authority) or "baggage" as an example of some concept; in that case,
   the document should specifically say "SET(trademark) BCA" or
   "SET(trademark) baggage" and include the definition of the term.

<span class="h3"><a class="selflink" id="section-3.4" href="#section-3.4">3.4</a>. Type "D": Deprecated Terms and Definitions</span>

   If this Glossary recommends that a term or definition SHOULD NOT be
   used in IDOCs, then the entry is marked as type "D", and an
   explanatory note -- "Deprecated Term", "Deprecated Abbreviation",
   "Deprecated Definition", or "Deprecated Usage" -- is provided.

<span class="h3"><a class="selflink" id="section-3.5" href="#section-3.5">3.5</a>. Definition Substitutions</span>

   Some terms have a definition published by a non-Internet authority --
   a government (e.g., "object reuse"), an industry (e.g., "Secure Data
   Exchange"), a national authority (e.g., "Data Encryption Standard"),
   or an international body (e.g., "data confidentiality") -- that is
   suitable for use in IDOCs. In those cases, this Glossary marks the
   definition "N", recommending its use in Internet documents.

   Other such terms have definitions that are inadequate or
   inappropriate for IDOCs. For example, a definition might be outdated
   or too narrow, or it might need clarification by substituting more
   careful wording (e.g., "authentication exchange") or explanations,
   using other terms that are defined in this Glossary. In those cases,



<span class="grey">Shirey                       Informational                      [Page 8]</span>

<span id="page-9" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   this Glossary marks the entry "O", and provides an "I" or "N" entry
   that precedes, and is intended to supersede, the "O" entry.

   In some cases where this Glossary provides a definition to supersede
   an "O" definition, the substitute is intended to subsume the meaning
   of the "O" entry and not conflict with it. For the term "security
   service", for example, the "O" definition deals narrowly with only
   communication services provided by layers in the OSIRM and is
   inadequate for the full range of IDOC usage, while the new "I"
   definition provided by this Glossary can be used in more situations
   and for more kinds of service. However, the "O" definition is also
   listed so that IDOC authors will be aware of the context in which the
   term is used more narrowly.

   When making substitutions, this Glossary attempts to avoid
   contradicting any non-Internet authority. Still, terminology differs
   between authorities such as the American Bar Association, OSI, SET,
   the U.S. DoD, and other authorities; and this Glossary probably is
   not exactly aligned with any of them.

<span class="h2"><a class="selflink" id="section-4" href="#section-4">4</a>. Definitions</span>

   $ *-property
      (N) Synonym for "confinement property" in the context of the Bell-
      LaPadula model. Pronunciation: star property.

   $ 3DES
      (N) See: Triple Data Encryption Algorithm.

   $ A1 computer system
      (O) /TCSEC/ See: Tutorial under "Trusted Computer System
      Evaluation Criteria". (Compare: beyond A1.)

   $ AA
      (D) See: Deprecated Usage under "attribute authority".

   $ ABA Guidelines
      (N) "American Bar Association (ABA) Digital Signature Guidelines"
      [<a href="#ref-DSG" title=""Digital Signature Guidelines: Legal Infrastructure for Certification Authorities and Secure Electronic Commerce"">DSG</a>], a framework of legal principles for using digital
      signatures and digital certificates in electronic commerce.

   $ Abstract Syntax Notation One (ASN.1)
      (N) A standard for describing data objects. [<a href="#ref-Larm" title=""ASN.1 Complete"">Larm</a>, <a href="#ref-X680" title=""Information Technology -- Abstract Syntax Notation One (ASN.1) -- Specification of Basic Notation"">X680</a>] (See:
      CMS.)

      Usage: IDOCs SHOULD use the term "ASN.1" narrowly to describe the
      notation or language called "Abstract Syntax Notation One". IDOCs
      MAY use the term more broadly to encompass the notation, its



<span class="grey">Shirey                       Informational                      [Page 9]</span>

<span id="page-10" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      associated encoding rules (see: BER), and software tools that
      assist in its use, when the context makes this meaning clear.

      Tutorial: OSIRM defines computer network functionality in layers.
      Protocols and data objects at higher layers are abstractly defined
      to be implemented using protocols and data objects from lower
      layers. A higher layer may define transfers of abstract objects
      between computers, and a lower layer may define those transfers
      concretely as strings of bits. Syntax is needed to specify data
      formats of abstract objects, and encoding rules are needed to
      transform abstract objects into bit strings at lower layers. OSI
      standards use ASN.1 for those specifications and use various
      encoding rules for those transformations. (See: BER.)

      In ASN.1, formal names are written without spaces, and separate
      words in a name are indicated by capitalizing the first letter of
      each word except the first word. For example, the name of a CRL is
      "certificateRevocationList".

   $ ACC
      (I) See: access control center.

   $ acceptable risk
      (I) A risk that is understood and tolerated by a system's user,
      operator, owner, or accreditor, usually because the cost or
      difficulty of implementing an effective countermeasure for the
      associated vulnerability exceeds the expectation of loss. (See:
      adequate security, risk, "second law" under "Courtney's laws".)

   $ access
      1a. (I) The ability and means to communicate with or otherwise
      interact with a system to use system resources either to handle
      information or to gain knowledge of the information the system
      contains. (Compare: handle.)

      Usage: The definition is intended to include all types of
      communication with a system, including one-way communication in
      either direction. In actual practice, however, passive users might
      be treated as not having "access" and, therefore, be exempt from
      most requirements of the system's security policy. (See: "passive
      user" under "user".)

      1b. (O) "Opportunity to make use of an information system (IS)
      resource." [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>]

      2. (O) /formal model/ "A specific type of interaction between a
      subject and an object that results in the flow of information from
      one to the other." [<a href="#ref-NCS04" title=""Glossary of Computer Security Terms"">NCS04</a>]



<span class="grey">Shirey                       Informational                     [Page 10]</span>

<span id="page-11" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ Access Certificate for Electronic Services (ACES)
      (O) A PKI operated by the U.S. Government's General Services
      Administration in cooperation with industry partners. (See: CAM.)

   $ access control
      1. (I) Protection of system resources against unauthorized access.

      2. (I) A process by which use of system resources is regulated
      according to a security policy and is permitted only by authorized
      entities (users, programs, processes, or other systems) according
      to that policy. (See: access, access control service, computer
      security, discretionary access control, mandatory access control,
      role-based access control.)

      3. (I) /formal model/ Limitations on interactions between subjects
      and objects in an information system.

      4. (O) "The prevention of unauthorized use of a resource,
      including the prevention of use of a resource in an unauthorized
      manner." [<a href="#ref-I7498-2" title=""Information Processing Systems -- Open Systems Interconnection Reference Model, Part 2: Security Architecture"">I7498-2</a>]

      5. (O) /U.S. Government/ A system using physical, electronic, or
      human controls to identify or admit personnel with properly
      authorized access to a SCIF.

   $ access control center (ACC)
      (I) A computer that maintains a database (possibly in the form of
      an access control matrix) defining the security policy for an
      access control service, and that acts as a server for clients
      requesting access control decisions.

      Tutorial: An ACC is sometimes used in conjunction with a key
      center to implement access control in a key-distribution system
      for symmetric cryptography. (See: BLACKER, Kerberos.)

   $ access control list (ACL)
      (I) /information system/ A mechanism that implements access
      control for a system resource by enumerating the system entities
      that are permitted to access the resource and stating, either
      implicitly or explicitly, the access modes granted to each entity.
      (Compare: access control matrix, access list, access profile,
      capability list.)

   $ access control matrix
      (I) A rectangular array of cells, with one row per subject and one
      column per object. The entry in a cell -- that is, the entry for a
      particular subject-object pair -- indicates the access mode that
      the subject is permitted to exercise on the object. Each column is



<span class="grey">Shirey                       Informational                     [Page 11]</span>

<span id="page-12" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      equivalent to an "access control list" for the object; and each
      row is equivalent to an "access profile" for the subject.

   $ access control service
      (I) A security service that protects against a system entity using
      a system resource in a way not authorized by the system's security
      policy. (See: access control, discretionary access control,
      identity-based security policy, mandatory access control, rule-
      based security policy.)

      Tutorial: This service includes protecting against use of a
      resource in an unauthorized manner by an entity (i.e., a
      principal) that is authorized to use the resource in some other
      manner. (See: insider.) The two basic mechanisms for implementing
      this service are ACLs and tickets.

   $ access level
      1. (D) Synonym for the hierarchical "classification level" in a
      security level. [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>] (See: security level.)

      2. (D) Synonym for "clearance level".

      Deprecated Definitions: IDOCs SHOULD NOT use this term with these
      definitions because they duplicate the meaning of more specific
      terms. Any IDOC that uses this term SHOULD provide a specific
      definition for it because access control may be based on many
      attributes other than classification level and clearance level.

   $ access list
      (I) /physical security/ Roster of persons who are authorized to
      enter a controlled area. (Compare: access control list.)

   $ access mode
      (I) A distinct type of data processing operation (e.g., read,
      write, append, or execute, or a combination of operations) that a
      subject can potentially perform on an object in an information
      system. [<a href="#ref-Huff" title=""Trusted Computer Systems -- Glossary"">Huff</a>] (See: read, write.)

   $ access policy
      (I) A kind of "security policy". (See: access, access control.)

   $ access profile
      (O) Synonym for "capability list".

      Usage: IDOCs that use this term SHOULD state a definition for it
      because the definition is not widely known.





<span class="grey">Shirey                       Informational                     [Page 12]</span>

<span id="page-13" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ access right
      (I) Synonym for "authorization"; emphasizes the possession of the
      authorization by a system entity.

   $ accountability
      (I) The property of a system or system resource that ensures that
      the actions of a system entity may be traced uniquely to that
      entity, which can then be held responsible for its actions. [<a href="#ref-Huff" title=""Trusted Computer Systems -- Glossary"">Huff</a>]
      (See: audit service.)

      Tutorial: Accountability (a.k.a. individual accountability)
      typically requires a system ability to positively associate the
      identity of a user with the time, method, and mode of the user's
      access to the system. This ability supports detection and
      subsequent investigation of security breaches. Individual persons
      who are system users are held accountable for their actions after
      being notified of the rules of behavior for using the system and
      the penalties associated with violating those rules.

   $ accounting See: COMSEC accounting.

   $ accounting legend code (ALC)
      (O) /U.S. Government/ Numeric system used to indicate the minimum
      accounting controls required for items of COMSEC material within
      the CMCS. [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>] (See: COMSEC accounting.)

   $ accreditation
      (N) An administrative action by which a designated authority
      declares that an information system is approved to operate in a
      particular security configuration with a prescribed set of
      safeguards. [<a href="#ref-FP102" title=""Guideline for Computer Security Certification and Accreditation"">FP102</a>, <a href="#ref-SP37" title=""Guide for the Security Certification and Accreditation of Federal Information Systems"">SP37</a>] (See: certification.)

      Tutorial: An accreditation is usually based on a technical
      certification of the system's security mechanisms. To accredit a
      system, the approving authority must determine that any residual
      risk is an acceptable risk. Although the terms "certification" and
      "accreditation" are used more in the U.S. DoD and other U.S.
      Government agencies than in commercial organizations, the concepts
      apply any place where managers are required to deal with and
      accept responsibility for security risks. For example, the
      American Bar Association is developing accreditation criteria for
      CAs.

   $ accreditation boundary
      (O) Synonym for "security perimeter". [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>]






<span class="grey">Shirey                       Informational                     [Page 13]</span>

<span id="page-14" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ accreditor
      (N) A management official who has been designated to have the
      formal authority to "accredit" an information system, i.e., to
      authorize the operation of, and the processing of sensitive data
      in, the system and to accept the residual risk associated with the
      system. (See: accreditation, residual risk.)

   $ ACES
      (O) See: Access Certificate for Electronic Services.

   $ ACL
      (I) See: access control list.

   $ acquirer
      1. (O) /SET/ "The financial institution that establishes an
      account with a merchant and processes payment card authorizations
      and payments." [<a href="#ref-SET1" title=""SET Secure Electronic Transaction Specification, Book 1: Business Description"">SET1</a>]

      2. (O) /SET/ "The institution (or its agent) that acquires from
      the card acceptor the financial data relating to the transaction
      and initiates that data into an interchange system." [<a href="#ref-SET2" title=""SET Secure Electronic Transaction Specification, Book 2: Programmer's Guide"">SET2</a>]

   $ activation data
      (N) Secret data, other than keys, that is required to access a
      cryptographic module. (See: CIK. Compare: initialization value.)

   $ active attack
      (I) See: secondary definition under "attack".

   $ active content
      1a. (I) Executable software that is bound to a document or other
      data file and that executes automatically when a user accesses the
      file, without explicit initiation by the user. (Compare: mobile
      code.)

      Tutorial: Active content can be mobile code when its associated
      file is transferred across a network.

      1b. (O) "Electronic documents that can carry out or trigger
      actions automatically on a computer platform without the
      intervention of a user. [This technology enables] mobile code
      associated with a document to execute as the document is
      rendered." [<a href="#ref-SP28" title=""Guidelines on Active Content and Mobile Code"">SP28</a>]

   $ active user
      (I) See: secondary definition under "system user".





<span class="grey">Shirey                       Informational                     [Page 14]</span>

<span id="page-15" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ active wiretapping
      (I) A wiretapping attack that attempts to alter data being
      communicated or otherwise affect data flow. (See: wiretapping.
      Compare: active attack, passive wiretapping.)

   $ add-on security
      (N) The retrofitting of protection mechanisms, implemented by
      hardware or software, in an information system after the system
      has become operational. [<a href="#ref-FP039" title=""Glossary for Computer Systems Security"">FP039</a>] (Compare: baked-in security.)

   $ adequate security
      (O) /U.S. DoD/ "Security commensurate with the risk and magnitude
      of harm resulting from the loss, misuse, or unauthorized access to
      or modification of information." (See: acceptable risk, residual
      risk.)

   $ administrative security
      1. (I) Management procedures and constraints to prevent
      unauthorized access to a system. (See: "third law" under
      "Courtney's laws", manager, operational security, procedural
      security, security architecture. Compare: technical security.)

      Examples: Clear delineation and separation of duties;
      configuration control.

      Usage: Administrative security is usually understood to consist of
      methods and mechanisms that are implemented and executed primarily
      by people, rather than by automated systems.

      2. (O) "The management constraints, operational procedures,
      accountability procedures, and supplemental controls established
      to provide an acceptable level of protection for sensitive data."
      [<a href="#ref-FP039" title=""Glossary for Computer Systems Security"">FP039</a>]

   $ administrator
      1. (O) /Common Criteria/ A person that is responsible for
      configuring, maintaining, and administering the TOE in a correct
      manner for maximum security. (See: administrative security.)

      2. (O) /ITSEC/ A person in contact with the TOE, who is
      responsible for maintaining its operational capability.

   $ Advanced Encryption Standard (AES)
      (N) A U.S. Government standard [<a href="#ref-FP197" title=""Advanced Encryption Standard"">FP197</a>] (the successor to DES) that
      (a) specifies "the AES algorithm", which is a symmetric block
      cipher that is based on Rijndael and uses key sizes of 128, 192,
      or 256 bits to operate on a 128-bit block, and (b) states policy
      for using that algorithm to protect unclassified, sensitive data.



<span class="grey">Shirey                       Informational                     [Page 15]</span>

<span id="page-16" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      Tutorial: Rijndael was designed to handle additional block sizes
      and key lengths that were not adopted in the AES. Rijndael was
      selected by NIST through a public competition that was held to
      find a successor to the DEA; the other finalists were MARS, RC6,
      Serpent, and Twofish.

   $ adversary
      1. (I) An entity that attacks a system. (Compare: cracker,
      intruder, hacker.)

      2. (I) An entity that is a threat to a system.

   $ AES
      (N) See: Advanced Encryption Standard.

   $ Affirm
      (O) A formal methodology, language, and integrated set of software
      tools developed at the University of Southern California's
      Information Sciences Institute for specifying, coding, and
      verifying software to produce correct and reliable programs.
      [<a href="#ref-Cheh" title=""Verifying Security"">Cheh</a>]

   $ aggregation
      (I) A circumstance in which a collection of information items is
      required to be classified at a higher security level than any of
      the items is classified individually. (See: classification.)

   $ AH
      (I) See: Authentication Header

   $ air gap
      (I) An interface between two systems at which (a) they are not
      connected physically and (b) any logical connection is not
      automated (i.e., data is transferred through the interface only
      manually, under human control). (See: sneaker net. Compare:
      gateway.)

      Example: Computer A and computer B are on opposite sides of a
      room. To move data from A to B, a person carries a disk across the
      room. If A and B operate in different security domains, then
      moving data across the air gap may involve an upgrade or downgrade
      operation.

   $ ALC
      (O) See: accounting legend code.






<span class="grey">Shirey                       Informational                     [Page 16]</span>

<span id="page-17" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ algorithm
      (I) A finite set of step-by-step instructions for a problem-
      solving or computation procedure, especially one that can be
      implemented by a computer. (See: cryptographic algorithm.)

   $ alias
      (I) A name that an entity uses in place of its real name, usually
      for the purpose of either anonymity or masquerade.

   $ Alice and Bob
      (I) The parties that are most often called upon to illustrate the
      operation of bipartite security protocols. These and other
      dramatis personae are listed by Schneier [<a href="#ref-Schn" title=""Applied Cryptography Second Edition"">Schn</a>].

   $ American National Standards Institute (ANSI)
      (N) A private, not-for-profit association that administers U.S.
      private-sector voluntary standards.

      Tutorial: ANSI has approximately 1,000 member organizations,
      including equipment users, manufacturers, and others. These
      include commercial firms, governmental agencies, and other
      institutions and international entities.

      ANSI is the sole U.S. representative to (a) ISO and (b) (via the
      U.S. National Committee) the International Electrotechnical
      Commission (IEC), which are the two major, non-treaty,
      international standards organizations.

      ANSI provides a forum for ANSI-accredited standards development
      groups. Among those groups, the following are especially relevant
      to Internet security:
      -  International Committee for Information Technology
         Standardization (INCITS) (formerly X3): Primary U.S. focus of
         standardization in information and communications technologies,
         encompassing storage, processing, transfer, display,
         management, organization, and retrieval of information.
         Example: [<a href="#ref-A3092" title=""American National Standard Data Encryption Algorithm"">A3092</a>].
      -  Accredited Standards Committee X9: Develops, establishes,
         maintains, and promotes standards for the financial services
         industry. Example: [<a href="#ref-A9009" title=""Financial Institution Message Authentication (Wholesale)"">A9009</a>].
      -  Alliance for Telecommunications Industry Solutions (ATIS):
         Develops standards, specifications, guidelines, requirements,
         technical reports, industry processes, and verification tests
         for interoperability and reliability of telecommunications
         networks, equipment, and software. Example: [<a href="#ref-A1523" title=""American National Standard Telecom Glossary"">A1523</a>].






<span class="grey">Shirey                       Informational                     [Page 17]</span>

<span id="page-18" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ American Standard Code for Information Interchange (ASCII)
      (N) A scheme that encodes 128 specified characters -- the numbers
      0-9, the letters a-z and A-Z, some basic punctuation symbols, some
      control codes that originated with Teletype machines, and a blank
      space -- into the 7-bit binary integers. Forms the basis of the
      character set representations used in most computers and many
      Internet standards. [<a href="#ref-FP001" title=""Code for Information Interchange"">FP001</a>] (See: code.)

   $ Anderson report
      (O) A 1972 study of computer security that was written by James P.
      Anderson for the U.S. Air Force [<a href="#ref-Ande" title=""Computer Security Technology Planning Study"">Ande</a>].

      Tutorial: Anderson collaborated with a panel of experts to study
      Air Force requirements for multilevel security. The study
      recommended research and development that was urgently needed to
      provide secure information processing for command and control
      systems and support systems. The report introduced the reference
      monitor concept and provided development impetus for computer and
      network security technology. However, many of the security
      problems that the 1972 report called "current" still plague
      information systems today.

   $ anomaly detection
      (I) An intrusion detection method that searches for activity that
      is different from the normal behavior of system entities and
      system resources. (See: IDS. Compare: misuse detection.)

   $ anonymity
      (I) The condition of an identity being unknown or concealed. (See:
      alias, anonymizer, anonymous credential, anonymous login,
      identity, onion routing, persona certificate. Compare: privacy.)

      Tutorial: An application may require security services that
      maintain anonymity of users or other system entities, perhaps to
      preserve their privacy or hide them from attack. To hide an
      entity's real name, an alias may be used; for example, a financial
      institution may assign account numbers. Parties to transactions
      can thus remain relatively anonymous, but can also accept the
      transactions as legitimate. Real names of the parties cannot be
      easily determined by observers of the transactions, but an
      authorized third party may be able to map an alias to a real name,
      such as by presenting the institution with a court order. In other
      applications, anonymous entities may be completely untraceable.

   $ anonymizer
      (I) An internetwork service, usually provided via a proxy server,
      that provides anonymity and privacy for clients. That is, the
      service enables a client to access servers (a) without allowing



<span class="grey">Shirey                       Informational                     [Page 18]</span>

<span id="page-19" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      anyone to gather information about which servers the client
      accesses and (b) without allowing the accessed servers to gather
      information about the client, such as its IP address.

   $ anonymous credential
      (D) /U.S. Government/ A credential that (a) can be used to
      authenticate a person as having a specific attribute or being a
      member of a specific group (e.g., military veterans or U.S.
      citizens) but (b) does not reveal the individual identity of the
      person that presents the credential. [<a href="#ref-M0404" title=""E-Authentication Guidance for Federal Agencies"">M0404</a>] (See: anonymity.)

      Deprecated Term: IDOCs SHOULD NOT use this term; it mixes concepts
      in a potentially misleading way. For example, when the credential
      is an X.509 certificate, the term could be misunderstood to mean
      that the certificate was signed by a CA that has a persona
      certificate. Instead, use "attribute certificate", "organizational
      certificate", or "persona certificate" depending on what is meant,
      and provide additional explanations as needed.

   $ anonymous login
      (I) An access control feature (actually, an access control
      vulnerability) in many Internet hosts that enables users to gain
      access to general-purpose or public services and resources of a
      host (such as allowing any user to transfer data using FTP)
      without having a pre-established, identity-specific account (i.e.,
      user name and password). (See: anonymity.)

      Tutorial: This feature exposes a system to more threats than when
      all the users are known, pre-registered entities that are
      individually accountable for their actions. A user logs in using a
      special, publicly known user name (e.g., "anonymous", "guest", or
      "ftp"). To use the public login name, the user is not required to
      know a secret password and may not be required to input anything
      at all except the name. In other cases, to complete the normal
      sequence of steps in a login protocol, the system may require the
      user to input a matching, publicly known password (such as
      "anonymous") or may ask the user for an e-mail address or some
      other arbitrary character string.

   $ ANSI
      (N) See: American National Standards Institute.

   $ anti-jam
      (N) "Measures ensuring that transmitted information can be
      received despite deliberate jamming attempts." [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>] (See:
      electronic security, frequency hopping, jam, spread spectrum.)





<span class="grey">Shirey                       Informational                     [Page 19]</span>

<span id="page-20" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ apex trust anchor
      (N) The trust anchor that is superior to all other trust anchors
      in a particular system or context. (See: trust anchor, top CA.)

   $ API
      (I) See: application programming interface.

   $ APOP
      (I) See: POP3 APOP.

   $ Application Layer
      See: Internet Protocol Suite, OSIRM.

   $ application program
      (I) A computer program that performs a specific function directly
      for a user (as opposed to a program that is part of a computer
      operating system and exists to perform functions in support of
      application programs).

   $ architecture
      (I) See: security architecture, system architecture.

   $ archive
      1a. (I) /noun/ A collection of data that is stored for a
      relatively long period of time for historical and other purposes,
      such as to support audit service, availability service, or system
      integrity service. (Compare: backup, repository.)

      1b. (I) /verb/ To store data in such a way as to create an
      archive. (Compare: back up.)

      Tutorial: A digital signature may need to be verified many years
      after the signing occurs. The CA -- the one that issued the
      certificate containing the public key needed to verify that
      signature -- may not stay in operation that long. So every CA
      needs to provide for long-term storage of the information needed
      to verify the signatures of those to whom it issues certificates.

   $ ARPANET
      (I) Advanced Research Projects Agency (ARPA) Network, a pioneer
      packet-switched network that (a) was designed, implemented,
      operated, and maintained by BBN from January 1969 until July 1975
      under contract to the U.S. Government; (b) led to the development
      of today's Internet; and (c) was decommissioned in June 1990.
      [<a href="#ref-B4799" title=""A History of the Arpanet: The First Decade"">B4799</a>, <a href="#ref-Hafn" title=""Where Wizards Stay Up Late: The Origins of the Internet"">Hafn</a>]

   $ ASCII
      (N) See: American Standard Code for Information Interchange.



<span class="grey">Shirey                       Informational                     [Page 20]</span>

<span id="page-21" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ ASN.1
      (N) See: Abstract Syntax Notation One.

   $ asset
      (I) A system resource that is (a) required to be protected by an
      information system's security policy, (b) intended to be protected
      by a countermeasure, or (c) required for a system's mission.

   $ association
      (I) A cooperative relationship between system entities, usually
      for the purpose of transferring information between them. (See:
      security association.)

   $ assurance See: security assurance.

   $ assurance level
      (N) A rank on a hierarchical scale that judges the confidence
      someone can have that a TOE adequately fulfills stated security
      requirements. (See: assurance, certificate policy, EAL, TCSEC.)

      Example: U.S. Government guidance [<a href="#ref-M0404" title=""E-Authentication Guidance for Federal Agencies"">M0404</a>] describes four assurance
      levels for identity authentication, where each level "describes
      the [U.S. Federal Government] agency's degree of certainty that
      the user has presented [a credential] that refers to [the user's]
      identity." In that guidance, assurance is defined as (a) "the
      degree of confidence in the vetting process used to establish the
      identity of the individual to whom the credential was issued" and
      (b) "the degree of confidence that the individual who uses the
      credential is the individual to whom the credential was issued."

      The four levels are described as follows:
      -  Level 1: Little or no confidence in the asserted identity.
      -  Level 2: Some confidence in the asserted identity.
      -  Level 3: High confidence in the asserted identity.
      -  Level 4: Very high confidence in the asserted identity.

      Standards for determining these levels are provided in a NIST
      publication [<a href="#ref-SP12" title=""An Introduction to Computer Security: The NIST Handbook"">SP12</a>]. However, as noted there, an assurance level is
      "a degree of confidence, not a true measure of how secure the
      system actually is. This distinction is necessary because it is
      extremely difficult -- and in many cases, virtually impossible --
      to know exactly how secure a system is."

   $ asymmetric cryptography
      (I) A modern branch of cryptography (popularly known as "public-
      key cryptography") in which the algorithms use a pair of keys (a
      public key and a private key) and use a different component of the
      pair for each of two counterpart cryptographic operations (e.g.,



<span class="grey">Shirey                       Informational                     [Page 21]</span>

<span id="page-22" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      encryption and decryption, or signature creation and signature
      verification). (See: key pair, symmetric cryptography.)

      Tutorial: Asymmetric algorithms have key management advantages
      over equivalently strong symmetric ones. First, one key of the
      pair need not be known by anyone but its owner; so it can more
      easily be kept secret. Second, although the other key is shared by
      all entities that use the algorithm, that key need not be kept
      secret from other, non-using entities; thus, the key-distribution
      part of key management can be done more easily.

      Asymmetric cryptography can be used to create algorithms for
      encryption, digital signature, and key agreement:
      -  In an asymmetric encryption algorithm (e.g., "RSA"), when Alice
         wants to ensure confidentiality for data she sends to Bob, she
         encrypts the data with a public key provided by Bob. Only Bob
         has the matching private key that is needed to decrypt the
         data. (Compare: seal.)
      -  In an asymmetric digital signature algorithm (e.g., "DSA"),
         when Alice wants to ensure data integrity or provide
         authentication for data she sends to Bob, she uses her private
         key to sign the data (i.e., create a digital signature based on
         the data). To verify the signature, Bob uses the matching
         public key that Alice has provided.
      -  In an asymmetric key-agreement algorithm (e.g., "Diffie-
         Hellman-Merkle"), Alice and Bob each send their own public key
         to the other party. Then each uses their own private key and
         the other's public key to compute the new key value.

   $ asymmetric key
      (I) A cryptographic key that is used in an asymmetric
      cryptographic algorithm. (See: asymmetric cryptography, private
      key, public key.)

   $ ATIS
      (N) See: "Alliance for Telecommunications Industry Solutions"
      under "ANSI".

   $ attack
      1. (I) An intentional act by which an entity attempts to evade
      security services and violate the security policy of a system.
      That is, an actual assault on system security that derives from an
      intelligent threat. (See: penetration, violation, vulnerability.)

      2. (I) A method or technique used in an assault (e.g.,
      masquerade). (See: blind attack, distributed attack.)





<span class="grey">Shirey                       Informational                     [Page 22]</span>

<span id="page-23" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      Tutorial: Attacks can be characterized according to intent:
      -  An "active attack" attempts to alter system resources or affect
         their operation.
      -  A "passive attack" attempts to learn or make use of information
         from a system but does not affect system resources of that
         system. (See: wiretapping.)

      The object of a passive attack might be to obtain data that is
      needed for an off-line attack.
      -  An "off-line attack" is one in which the attacker obtains data
         from the target system and then analyzes the data on a
         different system of the attacker's own choosing, possibly in
         preparation for a second stage of attack on the target.

      Attacks can be characterized according to point of initiation:
      -  An "inside attack" is one that is initiated by an entity inside
         the security perimeter (an "insider"), i.e., an entity that is
         authorized to access system resources but uses them in a way
         not approved by the party that granted the authorization.
      -  An "outside attack" is initiated from outside the security
         perimeter, by an unauthorized or illegitimate user of the
         system (an "outsider"). In the Internet, potential outside
         attackers range from amateur pranksters to organized criminals,
         international terrorists, and hostile governments.
      Attacks can be characterized according to method of delivery:
      -  In a "direct attack", the attacker addresses attacking packets
         to the intended victim(s).
      -  In an "indirect attack", the attacker addresses packets to a
         third party, and the packets either have the address(es) of the
         intended victim(s) as their source address(es) or indicate the
         intended victim(s) in some other way. The third party responds
         by sending one or more attacking packets to the intended
         victims. The attacker can use third parties as attack
         amplifiers by providing a broadcast address as the victim
         address (e.g., "smurf attack"). (See: reflector attack.
         Compare: reflection attack, replay attack.)















<span class="grey">Shirey                       Informational                     [Page 23]</span>

<span id="page-24" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      The term "attack" relates to some other basic security terms as
      shown in the following diagram:

      + - - - - - - - - - - - - +  + - - - - +  + - - - - - - - - - - -+
      | An Attack:              |  |Counter- |  | A System Resource:   |
      | i.e., A Threat Action   |  | measure |  | Target of the Attack |
      | +----------+            |  |         |  | +-----------------+  |
      | | Attacker |<==================||<=========                 |  |
      | |   i.e.,  |   Passive  |  |         |  | |  Vulnerability  |  |
      | | A Threat |<=================>||<========>                 |  |
      | |  Agent   |  or Active |  |         |  | +-------|||-------+  |
      | +----------+   Attack   |  |         |  |         VVV          |
      |                         |  |         |  | Threat Consequences  |
      + - - - - - - - - - - - - +  + - - - - +  + - - - - - - - - - - -+

   $ attack potential
      (I) The perceived likelihood of success should an attack be
      launched, expressed in terms of the attacker's ability (i.e.,
      expertise and resources) and motivation. (Compare: threat, risk.)

   $ attack sensing, warning, and response
      (I) A set of security services that cooperate with audit service
      to detect and react to indications of threat actions, including
      both inside and outside attacks. (See: indicator.)

   $ attack tree
      (I) A branching, hierarchical data structure that represents a set
      of potential approaches to achieving an event in which system
      security is penetrated or compromised in a specified way. [<a href="#ref-Moor" title=""Attack Modeling for Information Security and Survivability"">Moor</a>]

      Tutorial: Attack trees are special cases of fault trees. The
      security incident that is the goal of the attack is represented as
      the root node of the tree, and the ways that an attacker could
      reach that goal are iteratively and incrementally represented as
      branches and subnodes of the tree. Each subnode defines a subgoal,
      and each subgoal may have its own set of further subgoals, etc.
      The final nodes on the paths outward from the root, i.e., the leaf
      nodes, represent different ways to initiate an attack. Each node
      other than a leaf is either an AND-node or an OR-node. To achieve
      the goal represented by an AND-node, the subgoals represented by
      all of that node's subnodes must be achieved; and for an OR-node,
      at least one of the subgoals must be achieved. Branches can be
      labeled with values representing difficulty, cost, or other attack
      attributes, so that alternative attacks can be compared.







<span class="grey">Shirey                       Informational                     [Page 24]</span>

<span id="page-25" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ attribute
      (N) Information of a particular type concerning an identifiable
      system entity or object. An "attribute type" is the component of
      an attribute that indicates the class of information given by the
      attribute; and an "attribute value" is a particular instance of
      the class of information indicated by an attribute type. (See:
      attribute certificate.)

   $ attribute authority (AA)
      1. (N) A CA that issues attribute certificates.

      2. (O) "An authority [that] assigns privileges by issuing
      attribute certificates." [<a href="#ref-X509" title=""Information Technology -- Open Systems Interconnection -- The Directory: Authentication Framework"">X509</a>]

      Deprecated Usage: The abbreviation "AA" SHOULD NOT be used in an
      IDOC unless it is first defined in the IDOC.

   $ attribute certificate
      1. (I) A digital certificate that binds a set of descriptive data
      items, other than a public key, either directly to a subject name
      or to the identifier of another certificate that is a public-key
      certificate. (See: capability token.)

      2. (O) "A data structure, digitally signed by an [a]ttribute
      [a]uthority, that binds some attribute values with identification
      information about its holder." [<a href="#ref-X509" title=""Information Technology -- Open Systems Interconnection -- The Directory: Authentication Framework"">X509</a>]

      Tutorial: A public-key certificate binds a subject name to a
      public key value, along with information needed to perform certain
      cryptographic functions using that key. Other attributes of a
      subject, such as a security clearance, may be certified in a
      separate kind of digital certificate, called an attribute
      certificate. A subject may have multiple attribute certificates
      associated with its name or with each of its public-key
      certificates.

      An attribute certificate might be issued to a subject in the
      following situations:
      -  Different lifetimes: When the lifetime of an attribute binding
         is shorter than that of the related public-key certificate, or
         when it is desirable not to need to revoke a subject's public
         key just to revoke an attribute.
      -  Different authorities: When the authority responsible for the
         attributes is different than the one that issues the public-key
         certificate for the subject. (There is no requirement that an
         attribute certificate be issued by the same CA that issued the
         associated public-key certificate.)




<span class="grey">Shirey                       Informational                     [Page 25]</span>

<span id="page-26" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ audit
      See: security audit.

   $ audit log
      (I) Synonym for "security audit trail".

   $ audit service
      (I) A security service that records information needed to
      establish accountability for system events and for the actions of
      system entities that cause them. (See: security audit.)

   $ audit trail
      (I) See: security audit trail.

   $ AUTH
      (I) See: POP3 AUTH.

   $ authenticate
      (I) Verify (i.e., establish the truth of) an attribute value
      claimed by or for a system entity or system resource. (See:
      authentication, validate vs. verify, "relationship between data
      integrity service and authentication services" under "data
      integrity service".)

      Deprecated Usage: In general English usage, this term is used with
      the meaning "to prove genuine" (e.g., an art expert authenticates
      a Michelangelo painting); but IDOCs should restrict usage as
      follows:
      -  IDOCs SHOULD NOT use this term to refer to proving or checking
         that data has not been changed, destroyed, or lost in an
         unauthorized or accidental manner. Instead, use "verify".
      -  IDOCs SHOULD NOT use this term to refer to proving the truth or
         accuracy of a fact or value such as a digital signature.
         Instead, use "verify".
      -  IDOCs SHOULD NOT use this term to refer to establishing the
         soundness or correctness of a construct, such as a digital
         certificate. Instead, use "validate".

   $ authentication
      (I) The process of verifying a claim that a system entity or
      system resource has a certain attribute value. (See: attribute,
      authenticate, authentication exchange, authentication information,
      credential, data origin authentication, peer entity
      authentication, "relationship between data integrity service and
      authentication services" under "data integrity service", simple
      authentication, strong authentication, verification, X.509.)





<span class="grey">Shirey                       Informational                     [Page 26]</span>

<span id="page-27" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      Tutorial: Security services frequently depend on authentication of
      the identity of users, but authentication may involve any type of
      attribute that is recognized by a system. A claim may be made by a
      subject about itself (e.g., at login, a user typically asserts its
      identity) or a claim may be made on behalf of a subject or object
      by some other system entity (e.g., a user may claim that a data
      object originates from a specific source, or that a data object is
      classified at a specific security level).

      An authentication process consists of two basic steps:
      -  Identification step: Presenting the claimed attribute value
         (e.g., a user identifier) to the authentication subsystem.
      -  Verification step: Presenting or generating authentication
         information (e.g., a value signed with a private key) that acts
         as evidence to prove the binding between the attribute and that
         for which it is claimed. (See: verification.)

   $ authentication code
      (D) Synonym for a checksum based on cryptography. (Compare: Data
      Authentication Code, Message Authentication Code.)

      Deprecated Term: IDOCs SHOULD NOT use this uncapitalized term as a
      synonym for any kind of checksum, regardless of whether or not the
      checksum is cryptographic. Instead, use "checksum", "Data
      Authentication Code", "error detection code", "hash", "keyed
      hash", "Message Authentication Code", "protected checksum", or
      some other recommended term, depending on what is meant.

      The term mixes concepts in a potentially misleading way. The word
      "authentication" is misleading because the checksum may be used to
      perform a data integrity function rather than a data origin
      authentication function.

   $ authentication exchange
      1. (I) A mechanism to verify the identity of an entity by means of
      information exchange.

      2. (O) "A mechanism intended to ensure the identity of an entity
      by means of information exchange." [<a href="#ref-I7498-2" title=""Information Processing Systems -- Open Systems Interconnection Reference Model, Part 2: Security Architecture"">I7498-2</a>]

   $ Authentication Header (AH)
      (I) An Internet protocol [<a href="#ref-R2402" title=""IP Authentication Header"">R2402</a>, <a href="#ref-R4302" title=""IP Authentication Header"">R4302</a>] designed to provide
      connectionless data integrity service and connectionless data
      origin authentication service for IP datagrams, and (optionally)
      to provide partial sequence integrity and protection against
      replay attacks. (See: IPsec. Compare: ESP.)





<span class="grey">Shirey                       Informational                     [Page 27]</span>

<span id="page-28" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      Tutorial: Replay protection may be selected by the receiver when a
      security association is established. AH authenticates the upper-
      layer PDU that is carried as an IP SDU, and also authenticates as
      much of the IP PCI (i.e., the IP header) as possible. However,
      some IP header fields may change in transit, and the value of
      these fields, when the packet arrives at the receiver, may not be
      predictable by the sender. Thus, the values of such fields cannot
      be protected end-to-end by AH; protection of the IP header by AH
      is only partial when such fields are present.

      AH may be used alone, or in combination with the ESP, or in a
      nested fashion with tunneling. Security services can be provided
      between a pair of communicating hosts, between a pair of
      communicating security gateways, or between a host and a gateway.
      ESP can provide nearly the same security services as AH, and ESP
      can also provide data confidentiality service. The main difference
      between authentication services provided by ESP and AH is the
      extent of the coverage; ESP does not protect IP header fields
      unless they are encapsulated by AH.

   $ authentication information
      (I) Information used to verify an identity claimed by or for an
      entity. (See: authentication, credential, user. Compare:
      identification information.)

      Tutorial: Authentication information may exist as, or be derived
      from, one of the following: (a) Something the entity knows (see:
      password); (b) something the entity possesses (see: token); (c)
      something the entity is (see: biometric authentication).

   $ authentication service
      (I) A security service that verifies an identity claimed by or for
      an entity. (See: authentication.)

      Tutorial: In a network, there are two general forms of
      authentication service: data origin authentication service and
      peer entity authentication service.

   $ authenticity
      (I) The property of being genuine and able to be verified and be
      trusted. (See: authenticate, authentication, validate vs. verify.)

   $ authority
      (D) /PKI/ "An entity [that is] responsible for the issuance of
      certificates." [<a href="#ref-X509" title=""Information Technology -- Open Systems Interconnection -- The Directory: Authentication Framework"">X509</a>]






<span class="grey">Shirey                       Informational                     [Page 28]</span>

<span id="page-29" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      Deprecated Usage: IDOCs SHOULD NOT use this term as a synonym for
      attribute authority, certification authority, registration
      authority, or similar terms; the shortened form may cause
      confusion. Instead, use the full term at the first instance of
      usage and then, if it is necessary to shorten text, use AA, CA,
      RA, and other abbreviations defined in this Glossary.

   $ authority certificate
      (D) "A certificate issued to an authority (e.g. either to a
      certification authority or to an attribute authority)." [<a href="#ref-X509" title=""Information Technology -- Open Systems Interconnection -- The Directory: Authentication Framework"">X509</a>]
      (See: authority.)

      Deprecated Term: IDOCs SHOULD NOT use this term because it is
      ambiguous. Instead, use the full term "certification authority
      certificate", "attribute authority certificate", "registration
      authority certificate", etc. at the first instance of usage and
      then, if it is necessary to shorten text, use AA, CA, RA, and
      other abbreviations defined in this Glossary.

   $ Authority Information Access extension
      (I) The private extension defined by PKIX for X.509 certificates
      to indicate "how to access CA information and services for the
      issuer of the certificate in which the extension appears.
      Information and services may include on-line validation services
      and CA policy data." [<a href="#ref-R3280" title=""Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile"">R3280</a>] (See: private extension.)

   $ authorization
      1a. (I) An approval that is granted to a system entity to access a
      system resource. (Compare: permission, privilege.)

      Usage: Some synonyms are "permission" and "privilege". Specific
      terms are preferred in certain contexts:
      -  /PKI/ "Authorization" SHOULD be used, to align with
         "certification authority" in the standard [<a href="#ref-X509" title=""Information Technology -- Open Systems Interconnection -- The Directory: Authentication Framework"">X509</a>].
      -  /role-based access control/ "Permission" SHOULD be used, to
         align with the standard [<a href="#ref-ANSI" title=""Role Based Access Control"">ANSI</a>].
      -  /computer operating systems/ "Privilege" SHOULD be used, to
         align with the literature. (See: privileged process, privileged
         user.)

      Tutorial: The semantics and granularity of authorizations depend
      on the application and implementation (see: "first law" under
      "Courtney's laws"). An authorization may specify a particular
      access mode -- such as read, write, or execute -- for one or more
      system resources.

      1b. (I) A process for granting approval to a system entity to
      access a system resource.



<span class="grey">Shirey                       Informational                     [Page 29]</span>

<span id="page-30" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      2. (O) /SET/ "The process by which a properly appointed person or
      persons grants permission to perform some action on behalf of an
      organization. This process assesses transaction risk, confirms
      that a given transaction does not raise the account holder's debt
      above the account's credit limit, and reserves the specified
      amount of credit. (When a merchant obtains authorization, payment
      for the authorized amount is guaranteed -- provided, of course,
      that the merchant followed the rules associated with the
      authorization process.)" [<a href="#ref-SET2" title=""SET Secure Electronic Transaction Specification, Book 2: Programmer's Guide"">SET2</a>]

   $ authorization credential
      (I) See: /access control/ under "credential".

   $ authorize
      (I) Grant an authorization to a system entity.

   $ authorized user
      (I) /access control/ A system entity that accesses a system
      resource for which the entity has received an authorization.
      (Compare: insider, outsider, unauthorized user.)

      Deprecated Usage: IDOCs that use this term SHOULD state a
      definition for it because the term is used in many ways and could
      easily be misunderstood.

   $ automated information system
      See: information system.

   $ availability
      1. (I) The property of a system or a system resource being
      accessible, or usable or operational upon demand, by an authorized
      system entity, according to performance specifications for the
      system; i.e., a system is available if it provides services
      according to the system design whenever users request them. (See:
      critical, denial of service. Compare: precedence, reliability,
      survivability.)

      2. (O) "The property of being accessible and usable upon demand by
      an authorized entity." [<a href="#ref-I7498-2" title=""Information Processing Systems -- Open Systems Interconnection Reference Model, Part 2: Security Architecture"">I7498-2</a>]

      3. (D) "Timely, reliable access to data and information services
      for authorized users." [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>]

      Deprecated Definition: IDOCs SHOULD NOT use the term with
      definition 3; the definition mixes "availability" with
      "reliability", which is a different property. (See: reliability.)





<span class="grey">Shirey                       Informational                     [Page 30]</span>

<span id="page-31" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      Tutorial: Availability requirements can be specified by
      quantitative metrics, but sometimes are stated qualitatively, such
      as in the following:
      -  "Flexible tolerance for delay" may mean that brief system
         outages do not endanger mission accomplishment, but extended
         outages may endanger the mission.
      -  "Minimum tolerance for delay" may mean that mission
         accomplishment requires the system to provide requested
         services in a short time.

   $ availability service
      (I) A security service that protects a system to ensure its
      availability.

      Tutorial: This service addresses the security concerns raised by
      denial-of-service attacks. It depends on proper management and
      control of system resources, and thus depends on access control
      service and other security services.

   $ avoidance
      (I) See: secondary definition under "security".

   $ B1, B2, or B3 computer system
      (O) /TCSEC/ See: Tutorial under "Trusted Computer System
      Evaluation Criteria".

   $ back door
      1. (I) /COMPUSEC/ A computer system feature -- which may be (a) an
      unintentional flaw, (b) a mechanism deliberately installed by the
      system's creator, or (c) a mechanism surreptitiously installed by
      an intruder -- that provides access to a system resource by other
      than the usual procedure and usually is hidden or otherwise not
      well-known. (See: maintenance hook. Compare: Trojan Horse.)

      Example: A way to access a computer other than through a normal
      login. Such an access path is not necessarily designed with
      malicious intent; operating systems sometimes are shipped by the
      manufacturer with hidden accounts intended for use by field
      service technicians or the vendor's maintenance programmers.

      2. (I) /cryptography/ A feature of a cryptographic system that
      makes it easily possible to break or circumvent the protection
      that the system is designed to provide.

      Example: A feature that makes it possible to decrypt cipher text
      much more quickly than by brute-force cryptanalysis, without
      having prior knowledge of the decryption key.




<span class="grey">Shirey                       Informational                     [Page 31]</span>

<span id="page-32" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ back up
      (I) /verb/ Create a reserve copy of data or, more generally,
      provide alternate means to perform system functions despite loss
      of system resources. (See: contingency plan. Compare: archive.)

   $ backup
      (I) /noun or adjective/ Refers to alternate means of performing
      system functions despite loss of system resources. (See:
      contingency plan).

      Example: A reserve copy of data, preferably one that is stored
      separately from the original, for use if the original becomes lost
      or damaged. (Compare: archive.)

   $ bagbiter
      (D) /slang/ "An entity, such as a program or a computer, that
      fails to work or that works in a remarkably clumsy manner. A
      person who has caused some trouble, inadvertently or otherwise,
      typically by failing to program the computer properly." [<a href="#ref-NCSSG" title=""COMPUSECese: Computer Security Glossary"">NCSSG</a>]
      (See: flaw.)

      Deprecated Term: It is likely that other cultures use different
      metaphors for these concepts. Therefore, to avoid international
      misunderstanding, IDOCs SHOULD NOT use this term. (See: Deprecated
      Usage under "Green Book".)

   $ baggage
      (O) /SET/ An "opaque encrypted tuple, which is included in a SET
      message but appended as external data to the PKCS encapsulated
      data. This avoids superencryption of the previously encrypted
      tuple, but guarantees linkage with the PKCS portion of the
      message." [<a href="#ref-SET2" title=""SET Secure Electronic Transaction Specification, Book 2: Programmer's Guide"">SET2</a>]

      Deprecated Usage: IDOCs SHOULD NOT use this term to describe a
      data element, except in the form "SET(trademark) baggage" with the
      meaning given above.

   $ baked-in security
      (D) The inclusion of security mechanisms in an information system
      beginning at an early point in the system's lifecycle, i.e.,
      during the design phase, or at least early in the implementation
      phase. (Compare: add-on security.)

      Deprecated Term: It is likely that other cultures use different
      metaphors for this concept. Therefore, to avoid international
      misunderstanding, IDOCs SHOULD NOT use this term (unless they also
      provide a definition like this one). (See: Deprecated Usage under
      "Green Book".)



<span class="grey">Shirey                       Informational                     [Page 32]</span>

<span id="page-33" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ bandwidth
      (I) The total width of the frequency band that is available to or
      used by a communication channel; usually expressed in Hertz (Hz).
      (<a href="./rfc3753">RFC 3753</a>) (Compare: channel capacity.)

   $ bank identification number (BIN)
      1. (O) The digits of a credit card number that identify the
      issuing bank. (See: primary account number.)

      2. (O) /SET/ The first six digits of a primary account number.

   $ Basic Encoding Rules (BER)
      (I) A standard for representing ASN.1 data types as strings of
      octets. [<a href="#ref-X690" title=""Information Technology -- ASN.1 Encoding Rules -- Specification of Basic Encoding Rules (BER), Canonical Encoding Rules (CER) and Distinguished Encoding Rules (DER)"">X690</a>] (See: Distinguished Encoding Rules.)

      Deprecated Usage: Sometimes incorrectly treated as part of ASN.1.
      However, ASN.1 properly refers only to a syntax description
      language, and not to the encoding rules for the language.

   $ Basic Security Option
      (I) See: secondary definition under "IPSO".

   $ bastion host
      (I) A strongly protected computer that is in a network protected
      by a firewall (or is part of a firewall) and is the only host (or
      one of only a few) in the network that can be directly accessed
      from networks on the other side of the firewall. (See: firewall.)

      Tutorial: Filtering routers in a firewall typically restrict
      traffic from the outside network to reaching just one host, the
      bastion host, which usually is part of the firewall. Since only
      this one host can be directly attacked, only this one host needs
      to be very strongly protected, so security can be maintained more
      easily and less expensively. However, to allow legitimate internal
      and external users to access application resources through the
      firewall, higher-layer protocols and services need to be relayed
      and forwarded by the bastion host. Some services (e.g., DNS and
      SMTP) have forwarding built in; other services (e.g., TELNET and
      FTP) require a proxy server on the bastion host.

   $ BBN Technologies Corp. (BBN)
      (O) The research-and-development company (originally called Bolt
      Baranek and Newman, Inc.) that built the ARPANET.

   $ BCA
      (O) See: brand certification authority.





<span class="grey">Shirey                       Informational                     [Page 33]</span>

<span id="page-34" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ BCR
      (O) See: BLACK/Crypto/RED.

   $ BCI
      (O) See: brand CRL identifier.

   $ Bell-LaPadula model
      (N) A formal, mathematical, state-transition model of
      confidentiality policy for multilevel-secure computer systems
      [<a href="#ref-Bell" title=""Secure Computer Systems: Mathematical Foundations and Model"">Bell</a>]. (Compare: Biba model, Brewer-Nash model.)

      Tutorial: The model, devised by David Bell and Leonard LaPadula at
      The MITRE Corporation in 1973, characterizes computer system
      elements as subjects and objects. To determine whether or not a
      subject is authorized for a particular access mode on an object,
      the clearance of the subject is compared to the classification of
      the object. The model defines the notion of a "secure state", in
      which the only permitted access modes of subjects to objects are
      in accordance with a specified security policy. It is proven that
      each state transition preserves security by moving from secure
      state to secure state, thereby proving that the system is secure.
      In this model, a multilevel-secure system satisfies several rules,
      including the "confinement property" (a.k.a. the "*-property"),
      the "simple security property", and the "tranquility property".

   $ benign
      1. (N) /COMSEC/ "Condition of cryptographic data [such] that [the
      data] cannot be compromised by human access [to the data]."
      [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>]

      2. (O) /COMPUSEC/ See: secondary definition under "trust".

   $ benign fill
      (N) Process by which keying material is generated, distributed,
      and placed into an ECU without exposure to any human or other
      system entity, except the cryptographic module that consumes and
      uses the material. (See: benign.)

   $ BER
      (I) See: Basic Encoding Rules.

   $ beyond A1
      1. (O) /formal/ A level of security assurance that is beyond the
      highest level (level A1) of criteria specified by the TCSEC. (See:
      Tutorial under "Trusted Computer System Evaluation Criteria".)






<span class="grey">Shirey                       Informational                     [Page 34]</span>

<span id="page-35" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      2. (O) /informal/ A level of trust so high that it is beyond
      state-of-the-art technology; i.e., it cannot be provided or
      verified by currently available assurance methods, and especially
      not by currently available formal methods.

   $ Biba integrity
      (N) Synonym for "source integrity".

   $ Biba model
      (N) A formal, mathematical, state-transition model of integrity
      policy for multilevel-secure computer systems [<a href="#ref-Biba" title=""Integrity Considerations for Secure Computer Systems"">Biba</a>]. (See: source
      integrity. Compare: Bell-LaPadula model.)

      Tutorial: This model for integrity control is analogous to the
      Bell-LaPadula model for confidentiality control. Each subject and
      object is assigned an integrity level and, to determine whether or
      not a subject is authorized for a particular access mode on an
      object, the integrity level of the subject is compared to that of
      the object. The model prohibits the changing of information in an
      object by a subject with a lesser or incomparable level. The rules
      of the Biba model are duals of the corresponding rules in the
      Bell-LaPadula model.

   $ billet
      (N) "A personnel position or assignment that may be filled by one
      person." [JCP1] (Compare: principal, role, user.)

      Tutorial: In an organization, a "billet" is a populational
      position, of which there is exactly one instance; but a "role" is
      functional position, of which there can be multiple instances.
      System entities are in one-to-one relationships with their
      billets, but may be in many-to-one and one-to-many relationships
      with their roles.

   $ BIN
      (O) See: bank identification number.

   $ bind
      (I) To inseparably associate by applying some security mechanism.

      Example: A CA creates a public-key certificate by using a digital
      signature to bind together (a) a subject name, (b) a public key,
      and usually (c) some additional data items (e.g., "X.509 public-
      key certificate").

   $ biometric authentication
      (I) A method of generating authentication information for a person
      by digitizing measurements of a physical or behavioral



<span class="grey">Shirey                       Informational                     [Page 35]</span>

<span id="page-36" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      characteristic, such as a fingerprint, hand shape, retina pattern,
      voiceprint, handwriting style, or face.

   $ birthday attack
      (I) A class of attacks against cryptographic functions, including
      both encryption functions and hash functions. The attacks take
      advantage of a statistical property: Given a cryptographic
      function having an N-bit output, the probability is greater than
      1/2 that for 2**(N/2) randomly chosen inputs, the function will
      produce at least two outputs that are identical. (See: Tutorial
      under "hash function".)

      Derivation: From the somewhat surprising fact (often called the
      "birthday paradox") that although there are 365 days in a year,
      the probability is greater than 1/2 that two of more people share
      the same birthday in any randomly chosen group of 23 people.

      Birthday attacks enable an adversary to find two inputs for which
      a cryptographic function produces the same cipher text (or find
      two inputs for which a hash functions produces the same hash
      result) much faster than a brute-force attack can; and a clever
      adversary can use such a capability to create considerable
      mischief. However, no birthday attack can enable an adversary to
      decrypt a given cipher text (or find a hash input that results in
      a given hash result) any faster than a brute-force attack can.

   $ bit
      (I) A contraction of the term "binary digit"; the smallest unit of
      information storage, which has two possible states or values. The
      values usually are represented by the symbols "0" (zero) and "1"
      (one). (See: block, byte, nibble, word.)

   $ bit string
      (I) A sequence of bits, each of which is either "0" or "1".

   $ BLACK
      1. (N) Designation for data that consists only of cipher text, and
      for information system equipment items or facilities that handle
      only cipher text. Example: "BLACK key". (See: BCR, color change,
      RED/BLACK separation. Compare: RED.)

      2. (O) /U.S. Government/ "Designation applied to information
      systems, and to associated areas, circuits, components, and
      equipment, in which national security information is encrypted or
      is not processed." [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>]

      3. (D) Any data that can be disclosed without harm.




<span class="grey">Shirey                       Informational                     [Page 36]</span>

<span id="page-37" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      Deprecated Definition: IDOCs SHOULD NOT use the term with
      definition 3 because the definition is ambiguous with regard to
      whether or not the data is protected.

   $ BLACK/Crypto/RED (BCR)
      (N) An experimental, end-to-end, network packet encryption system
      developed in a working prototype form by BBN and the Collins Radio
      division of Rockwell Corporation in the 1975-1980 time frame for
      the U.S. DoD. BCR was the first network security system to support
      TCP/IP traffic, and it incorporated the first DES chips that were
      validated by the U.S. National Bureau of Standards (now called
      NIST). BCR also was the first to use a KDC and an ACC to manage
      connections.

   $ BLACK key
      (N) A key that is protected with a key-encrypting key and that
      must be decrypted before use. (See: BLACK. Compare: RED key.)

   $ BLACKER
      (O) An end-to-end encryption system for computer data networks
      that was developed by the U.S. DoD in the 1980s to provide host-
      to-host data confidentiality service for datagrams at OSIRM Layer
      3. [<a href="#ref-Weis" title=""Blacker: Security for the DDN: Examples of A1 Security Engineering Trades"">Weis</a>] (Compare: CANEWARE, IPsec.)

      Tutorial: Each user host connects to its own bump-in-the-wire
      encryption device called a BLACKER Front End (BFE, TSEC/KI-111),
      through which the host connects to the subnetwork. The system also
      includes two types of centralized devices: one or more KDCs
      connect to the subnetwork and communicate with assigned sets of
      BFEs, and one or more ACCs connect to the subnetwork and
      communicate with assigned KDCs. BLACKER uses only symmetric
      encryption. A KDC distributes session keys to BFE pairs as
      authorized by an ACC. Each ACC maintains a database for a set of
      BFEs, and the database determines which pairs from that set (i.e.,
      which pairs of user hosts behind the BFEs) are authorized to
      communicate and at what security levels.

      The BLACKER system is MLS in three ways: (a) The BFEs form a
      security perimeter around a subnetwork, separating user hosts from
      the subnetwork, so that the subnetwork can operate at a different
      security level (possibly a lower, less expensive level) than the
      hosts. (b) The BLACKER components are trusted to separate
      datagrams of different security levels, so that each datagram of a
      given security level can be received only by a host that is
      authorized for that security level; and thus BLACKER can separate
      host communities that operate at different security levels. (c)
      The host side of a BFE is itself MLS and can recognize a security
      label on each packet, so that an MLS user host can be authorized



<span class="grey">Shirey                       Informational                     [Page 37]</span>

<span id="page-38" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      to successively transmit datagrams that are labeled with different
      security levels.

   $ blind attack
      (I) A type of network-based attack method that does not require
      the attacking entity to receive data traffic from the attacked
      entity; i.e., the attacker does not need to "see" data packets
      sent by the victim. Example: SYN flood.

      Tutorial: If an attack method is blind, the attacker's packets can
      carry (a) a false IP source address (making it difficult for the
      victim to find the attacker) and (b) a different address on every
      packet (making it difficult for the victim to block the attack).
      If the attacker needs to receive traffic from the victim, the
      attacker must either (c) reveal its own IP address to the victim
      (which enables the victim to find the attacker or block the attack
      by filtering) or (d) provide a false address and also subvert
      network routing mechanisms to divert the returning packets to the
      attacker (which makes the attack more complex, more difficult, or
      more expensive). [<a href="#ref-R3552" title=""Guidelines for Writing RFC Text on Security Considerations"">R3552</a>]

   $ block
      (I) A bit string or bit vector of finite length. (See: bit, block
      cipher. Compare: byte, word.)

      Usage: An "N-bit block" contains N bits, which usually are
      numbered from left to right as 1, 2, 3, ..., N.

   $ block cipher
      (I) An encryption algorithm that breaks plain text into fixed-size
      segments and uses the same key to transform each plaintext segment
      into a fixed-size segment of cipher text. Examples: AES, Blowfish,
      DEA, IDEA, RC2, and SKIPJACK. (See: block, mode. Compare: stream
      cipher.)

      Tutorial: A block cipher can be adapted to have a different
      external interface, such as that of a stream cipher, by using a
      mode of cryptographic operation to package the basic algorithm.
      (See: CBC, CCM, CFB, CMAC, CTR, DEA, ECB, OFB.)

   $ Blowfish
      (N) A symmetric block cipher with variable-length key (32 to 448
      bits) designed in 1993 by Bruce Schneier as an unpatented,
      license-free, royalty-free replacement for DES or IDEA. [<a href="#ref-Schn" title=""Applied Cryptography Second Edition"">Schn</a>]
      (See: Twofish.)






<span class="grey">Shirey                       Informational                     [Page 38]</span>

<span id="page-39" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ brain-damaged
      (D) /slang/ "Obviously wrong: extremely poorly designed. Calling
      something brain-damaged is very extreme. The word implies that the
      thing is completely unusable, and that its failure to work is due
      to poor design, not accident." [<a href="#ref-NCSSG" title=""COMPUSECese: Computer Security Glossary"">NCSSG</a>] (See: flaw.)

      Deprecated Term: It is likely that other cultures use different
      metaphors for this concept. Therefore, to avoid international
      misunderstanding, IDOCs SHOULD NOT use this term. (See: Deprecated
      Usage under "Green Book".)

   $ brand
      1. (I) A distinctive mark or name that identifies a product or
      business entity.

      2. (O) /SET/ The name of a payment card. (See: BCA.)

      Tutorial: Financial institutions and other companies have founded
      payment card brands, protect and advertise the brands, establish
      and enforce rules for use and acceptance of their payment cards,
      and provide networks to interconnect the financial institutions.
      These brands combine the roles of issuer and acquirer in
      interactions with cardholders and merchants. [<a href="#ref-SET1" title=""SET Secure Electronic Transaction Specification, Book 1: Business Description"">SET1</a>]

   $ brand certification authority (BCA)
      (O) /SET/ A CA owned by a payment card brand, such as MasterCard,
      Visa, or American Express. [<a href="#ref-SET2" title=""SET Secure Electronic Transaction Specification, Book 2: Programmer's Guide"">SET2</a>] (See: certification hierarchy,
      SET.)

   $ brand CRL identifier (BCI)
      (O) /SET/ A digitally signed list, issued by a BCA, of the names
      of CAs for which CRLs need to be processed when verifying
      signatures in SET messages. [<a href="#ref-SET2" title=""SET Secure Electronic Transaction Specification, Book 2: Programmer's Guide"">SET2</a>]

   $ break
      (I) /cryptography/ To successfully perform cryptanalysis and thus
      succeed in decrypting data or performing some other cryptographic
      function, without initially having knowledge of the key that the
      function requires. (See: penetrate, strength, work factor.)

      Usage: This term applies to encrypted data or, more generally, to
      a cryptographic algorithm or cryptographic system. Also, while the
      most common use is to refer to completely breaking an algorithm,
      the term is also used when a method is found that substantially
      reduces the work factor.






<span class="grey">Shirey                       Informational                     [Page 39]</span>

<span id="page-40" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ Brewer-Nash model
      (N) A security model [<a href="#ref-BN89" title=""The Chinese wall security policy"">BN89</a>] to enforce the Chinese wall policy.
      (Compare: Bell-LaPadula model, Clark-Wilson model.)

      Tutorial: All proprietary information in the set of commercial
      firms F(1), F(2), ..., F(N) is categorized into mutually exclusive
      conflict-of-interest classes I(1), I(2), ..., I(M) that apply
      across all firms. Each firm belongs to exactly one class. The
      Brewer-Nash model has the following mandatory rules:
      -  Brewer-Nash Read Rule: Subject S can read information object O
         from firm F(i) only if either (a) O is from the same firm as
         some object previously read by S *or* (b) O belongs to a class
         I(i) from which S has not previously read any object. (See:
         object, subject.)
      -  Brewer-Nash Write Rule: Subject S can write information object
         O to firm F(i) only if (a) S can read O by the Brewer-Nash Read
         Rule *and* (b) no object can be read by S from a different firm
         F(j), no matter whether F(j) belongs to the same class as F(i)
         or to a different class.

   $ bridge
      (I) A gateway for traffic flowing at OSIRM Layer 2 between two
      networks (usually two LANs). (Compare: bridge CA, router.)

   $ bridge CA
      (I) A PKI consisting of only a CA that cross-certifies with CAs of
      some other PKIs. (See: cross-certification. Compare: bridge.)

      Tutorial: A bridge CA functions as a hub that enables a
      certificate user in any of the PKIs that attach to the bridge, to
      validate certificates issued in the other attached PKIs.

      For example, a bridge CA (BCA)                 CA1
      could cross-certify with four                   ^
      PKIs that have the roots CA1,                   |
      CA2, CA3, and CA4. The cross-                   v
      certificates that the roots            CA2 <-> BCA <-> CA3
      exchange with the BCA enable an                 ^
      end entity EE1 certified under                  |
      under CA1 in PK1 to construct                   v
      a certification path needed to                 CA4
      validate the certificate of
      end entity EE2 under CA2,           CA1 -> BCA -> CA2 -> EE2
      or vice versa.                     CA2 -> BCA -> CA1 -> EE1







<span class="grey">Shirey                       Informational                     [Page 40]</span>

<span id="page-41" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ British Standard 7799
      (N) Part 1 of the standard is a code of practice for how to secure
      an information system. Part 2 specifies the management framework,
      objectives, and control requirements for information security
      management systems. [<a href="#ref-BS7799" title=""Information Security Management, Part 1: Code of Practice for Information Security Management"">BS7799</a>] (See: ISO 17799.)

   $ browser
      (I) A client computer program that can retrieve and display
      information from servers on the World Wide Web. Examples: Netscape
      Navigator and Microsoft Internet Explorer.

   $ brute force
      (I) A cryptanalysis technique or other kind of attack method
      involving an exhaustive procedure that tries a large number of
      possible solutions to the problem. (See: impossible, strength,
      work factor.)

      Tutorial: In some cases, brute force involves trying all of the
      possibilities. For example, for cipher text where the analyst
      already knows the decryption algorithm, a brute-force technique
      for finding matching plain text is to decrypt the message with
      every possible key. In other cases, brute force involves trying a
      large number of possibilities but substantially fewer than all of
      them. For example, given a hash function that produces an N-bit
      hash result, the probability is greater than 1/2 that the analyst
      will find two inputs that have the same hash result after trying
      only 2**(N/2) randomly chosen inputs. (See: birthday attack.)

   $ BS7799
      (N) See: British Standard 7799.

   $ buffer overflow
      (I) Any attack technique that exploits a vulnerability resulting
      from computer software or hardware that does not check for
      exceeding the bounds of a storage area when data is written into a
      sequence of storage locations beginning in that area.

      Tutorial: By causing a normal system operation to write data
      beyond the bounds of a storage area, the attacker seeks to either
      disrupt system operation or cause the system to execute malicious
      software inserted by the attacker.

   $ buffer zone
      (I) A neutral internetwork segment used to connect other segments
      that each operate under a different security policy.






<span class="grey">Shirey                       Informational                     [Page 41]</span>

<span id="page-42" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      Tutorial: To connect a private network to the Internet or some
      other relatively public network, one could construct a small,
      separate, isolated LAN and connect it to both the private network
      and the public network; one or both of the connections would
      implement a firewall to limit the traffic that could pass through
      the buffer zone.

   $ bulk encryption
      1. (I) Encryption of multiple channels by aggregating them into a
      single transfer path and then encrypting that path. (See:
      channel.)

      2. (O) "Simultaneous encryption of all channels of a multichannel
      telecommunications link." [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>] (Compare: bulk keying material.)

      Usage: The use of "simultaneous" in definition 2 could be
      interpreted to mean that multiple channels are encrypted
      separately but at the same time. However, the common meaning of
      the term is that multiple data flows are combined into a single
      stream and then that stream is encrypted as a whole.

   $ bulk key
      (D) In a few published descriptions of hybrid encryption for SSH,
      Windows 2000, and other applications, this term refers to a
      symmetric key that (a) is used to encrypt a relatively large
      amount of data and (b) is itself encrypted with a public key.
      (Compare: bulk keying material, session key.)

      Example: To send a large file to Bob, Alice (a) generates a
      symmetric key and uses it to encrypt the file (i.e., encrypt the
      bulk of the information that is to be sent) and then (b) encrypts
      that symmetric key (the "bulk key") with Bob's public key.

      Deprecated Term: IDOCs SHOULD NOT use this term or definition; the
      term is not well-established and could be confused with the
      established term "bulk keying material". Instead, use "symmetric
      key" and carefully explain how the key is applied.

   $ bulk keying material
      (N) Refers to handling keying material in large quantities, e.g.,
      as a dataset that contains many items of keying material. (See:
      type 0. Compare: bulk key, bulk encryption.)

   $ bump-in-the-stack
      (I) An implementation approach that places a network security
      mechanism inside the system that is to be protected. (Compare:
      bump-in-the-wire.)




<span class="grey">Shirey                       Informational                     [Page 42]</span>

<span id="page-43" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      Example: IPsec can be implemented inboard, in the protocol stack
      of an existing system or existing system design, by placing a new
      layer between the existing IP layer and the OSIRM Layer 3 drivers.
      Source code access for the existing stack is not required, but the
      system that contains the stack does need to be modified [<a href="#ref-R4301" title=""Security Architecture for the Internet Protocol"">R4301</a>].

   $ bump-in-the-wire
      (I) An implementation approach that places a network security
      mechanism outside of the system that is to be protected. (Compare:
      bump-in-the-stack.)

      Example: IPsec can be implemented outboard, in a physically
      separate device, so that the system that receives the IPsec
      protection does not need to be modified at all [<a href="#ref-R4301" title=""Security Architecture for the Internet Protocol"">R4301</a>]. Military-
      grade link encryption has mainly been implemented as bump-in-the-
      wire devices.

   $ business-case analysis
      (N) An extended form of cost-benefit analysis that considers
      factors beyond financial metrics, including security factors such
      as the requirement for security services, their technical and
      programmatic feasibility, their qualitative benefits, and
      associated risks. (See: risk analysis.)

   $ byte
      (I) A fundamental unit of computer storage; the smallest
      addressable unit in a computer's architecture. Usually holds one
      character of information and, today, usually means eight bits.
      (Compare: octet.)

      Usage: Understood to be larger than a "bit", but smaller than a
      "word". Although "byte" almost always means "octet" today, some
      computer architectures have had bytes in other sizes (e.g., six
      bits, nine bits). Therefore, an STD SHOULD state the number of
      bits in a byte where the term is first used in the STD.

   $ C field
      (D) See: Compartments field.

   $ C1 or C2 computer system
      (O) /TCSEC/ See: Tutorial under "Trusted Computer System
      Evaluation Criteria".

   $ CA
      (I) See: certification authority.






<span class="grey">Shirey                       Informational                     [Page 43]</span>

<span id="page-44" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ CA certificate
      (D) "A [digital] certificate for one CA issued by another CA."
      [<a href="#ref-X509" title=""Information Technology -- Open Systems Interconnection -- The Directory: Authentication Framework"">X509</a>]

      Deprecated Definition: IDOCs SHOULD NOT use the term with this
      definition; the definition is ambiguous with regard to how the
      certificate is constructed and how it is intended to be used.
      IDOCs that use this term SHOULD provide a technical definition for
      it. (See: certificate profile.)

      Tutorial: There is no single, obvious choice for a technical
      definition of this term. Different PKIs can use different
      certificate profiles, and X.509 provides several choices of how to
      issue certificates to CAs. For example, one possible definition is
      the following: A v3 X.509 public-key certificate that has a
      "basicConstraints" extension containing a "cA" value of "TRUE".
      That would specifically indicate that "the certified public key
      may be used to verify certificate signatures", i.e., that the
      private key may be used by a CA.

      However, there also are other ways to indicate such usage. The
      certificate may have a "key Usage" extension that indicates the
      purposes for which the public key may be used, and one of the
      values that X.509 defines for that extension is "keyCertSign", to
      indicate that the certificate may be used for verifying a CA's
      signature on certificates. If "keyCertSign" is present in a
      certificate that also has a "basicConstraints" extension, then
      "cA" is set to "TRUE" in that extension. Alternatively, a CA could
      be issued a certificate in which "keyCertSign" is asserted without
      "basicConstraints" being present; and an entity that acts as a CA
      could be issued a certificate with "keyUsage" set to other values,
      either with or without "keyCertSign".

   $ CA domain
      (N) /PKI/ A security policy domain that "consists of a CA and its
      subjects [i.e., the entities named in the certificates issued by
      the CA]. Sometimes referred to as a PKI domain." [<a href="#ref-PAG" title=""PKI Assessment Guidelines"">PAG</a>] (See:
      domain.)

   $ Caesar cipher
      (I) A cipher that is defined for an alphabet of N characters,
      A(1), A(2), ..., A(N), and creates cipher text by replacing each
      plaintext character A(i) by A(i+K, mod N) for some 0<K<N+1. [<a href="#ref-Schn" title=""Applied Cryptography Second Edition"">Schn</a>]

      Examples: (a) During the Gallic wars, Julius Caesar used a cipher
      with K=3. In a Caesar cipher with K=3 for the English alphabet, A
      is replaced by D, B by E, C by F, ..., W by Z, X by A, Y by B, Z




<span class="grey">Shirey                       Informational                     [Page 44]</span>

<span id="page-45" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      by C. (b) UNIX systems sometimes include "ROT13" software that
      implements a Caesar cipher with K=13 (i.e., ROTate by 13).

   $ call back
      (I) An authentication technique for terminals that remotely access
      a computer via telephone lines; the host system disconnects the
      caller and then reconnects on a telephone number that was
      previously authorized for that terminal.

   $ CAM
      (O) See: Certificate Arbitrator Module.

   $ CANEWARE
      (O) An end-to-end encryption system for computer data networks
      that was developed by the U.S. DoD in the 1980s to provide host-
      to-host data confidentiality service for datagrams in OSIRM Layer
      3. [<a href="#ref-Roge" title=""An Overview of the CANEWARE Program"">Roge</a>] (Compare: BLACKER, IPsec.)

      Tutorial: Each user host connects to its own bump-in-the-wire
      encryption device called a CANEWARE Front End (CFE), through which
      the host connects to the subnetwork. CANEWARE uses symmetric
      encryption for CFE-to-CFE traffic, but also uses FIREFLY to
      establish those session keys. The public-key certificates issued
      by the FIREFLY system include credentials for mandatory access
      control. For discretionary access control, the system also
      includes one or more centralized CANEWARE Control Processors
      (CCPs) that connect to the subnetwork, maintain a database for
      discretionary access control authorizations, and communicate those
      authorizations to assigned sets of CFEs.

      The CANEWARE system is MLS in only two of the three ways that
      BLACKER is MLS: (a) Like BLACKER BFEs, CFEs form a security
      perimeter around a subnetwork, separating user hosts from the
      subnetwork, so that the subnetwork can operate at a different
      security level than the hosts. (b) Like BLACKER, the CANEWARE
      components are trusted to separate datagrams of different security
      levels, so that each datagram of a given security level can be
      received only by a host that is authorized for that security
      level; and thus CANEWARE can separate host communities that
      operate at different security levels. (c) Unlike a BFE, the host
      side of a CFE is not MLS, and treats all packets received from a
      user host as being at the same mandatory security level.

   $ capability list
      (I) /information system/ A mechanism that implements access
      control for a system entity by enumerating the system resources
      that the entity is permitted to access and, either implicitly or
      explicitly, the access modes granted for each resource. (Compare:



<span class="grey">Shirey                       Informational                     [Page 45]</span>

<span id="page-46" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      access control list, access control matrix, access profile,
      capability token.)

   $ capability token
      (I) A token (usually an unforgeable data object) that gives the
      bearer or holder the right to access a system resource. Possession
      of the token is accepted by a system as proof that the holder has
      been authorized to access the resource indicated by the token.
      (See: attribute certificate, capability list, credential, digital
      certificate, ticket, token.)

   $ Capability Maturity Model (CMM)
      (N) Method for judging the maturity of software processes in an
      organization and for identifying crucial practices needed to
      increase process maturity. [<a href="#ref-Chris" title=""SW-CMM [Capability Maturity Model for Software Version"">Chris</a>] (Compare: Common Criteria.)

      Tutorial: The CMM does not specify security evaluation criteria
      (see: assurance level), but its use may improve security
      assurance. The CMM describes principles and practices that can
      improve software processes in terms of evolving from ad hoc
      processes to disciplined processes. The CMM has five levels:
      -  Initial: Software processes are ad hoc or chaotic, and few are
         well-defined. Success depends on individual effort and heroics.
      -  Repeatable: Basic project management processes are established
         to track cost, schedule, and functionality. Necessary process
         discipline is in place to repeat earlier successes on projects
         with similar applications.
      -  Defined: Software process for both management and engineering
         activities is documented, standardized, and integrated into a
         standard software process for the organization. Each project
         uses an approved, tailored version of the organization's
         standard process for developing and maintaining software.
      -  Managed: Detailed measures of software process and product
         quality are collected. Both software process and products are
         quantitatively understood and controlled.
      -  Optimizing: Continuous process improvement is enabled by
         quantitative feedback from the process and from piloting
         innovative ideas and technologies.

   $ CAPI
      (I) See: cryptographic application programming interface.

   $ CAPSTONE
      (N) An integrated microcircuit (in MYK-8x series manufactured by
      Mykotronx, Inc.) that implements SKIPJACK, KEA, DSA, SHA, and
      basic mathematical functions needed to support asymmetric
      cryptography; has a non-deterministic random number generator; and
      supports key escrow. (See: FORTEZZA. Compare: CLIPPER.)



<span class="grey">Shirey                       Informational                     [Page 46]</span>

<span id="page-47" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ card
      See: cryptographic card, FORTEZZA, payment card, PC card, smart
      card, token.

   $ card backup
      See: token backup.

   $ card copy
      See: token copy.

   $ card restore
      See: token restore.

   $ cardholder
      1. (I) An entity to whom or to which a card has been issued.

      Usage: Usually refers to a living human being, but might refer (a)
      to a position (see: billet, role) in an organization or (b) to an
      automated process. (Compare: user.)

      2. (O) /SET/ "The holder of a valid payment card account and user
      of software supporting electronic commerce." [<a href="#ref-SET2" title=""SET Secure Electronic Transaction Specification, Book 2: Programmer's Guide"">SET2</a>] A cardholder
      is issued a payment card by an issuer. SET ensures that in the
      cardholder's interactions with merchants, the payment card account
      information remains confidential. [<a href="#ref-SET1" title=""SET Secure Electronic Transaction Specification, Book 1: Business Description"">SET1</a>]

   $ cardholder certificate
      (O) /SET/ A digital certificate that is issued to a cardholder
      upon approval of the cardholder's issuing financial institution
      and that is transmitted to merchants with purchase requests and
      encrypted payment instructions, carrying assurance that the
      account number has been validated by the issuing financial
      institution and cannot be altered by a third party. [<a href="#ref-SET1" title=""SET Secure Electronic Transaction Specification, Book 1: Business Description"">SET1</a>]

   $ cardholder certification authority (CCA)
      (O) /SET/ A CA responsible for issuing digital certificates to
      cardholders and operated on behalf of a payment card brand, an
      issuer, or another party according to brand rules. A CCA maintains
      relationships with card issuers to allow for the verification of
      cardholder accounts. A CCA does not issue a CRL but does
      distribute CRLs issued by root CAs, brand CAs, geopolitical CAs,
      and payment gateway CAs. [<a href="#ref-SET2" title=""SET Secure Electronic Transaction Specification, Book 2: Programmer's Guide"">SET2</a>]

   $ CAST
      (N) A design procedure for symmetric encryption algorithms, and a
      resulting family of algorithms, invented by Carlisle Adams (C.A.)
      and Stafford Tavares (S.T.). [<a href="#ref-R2144" title=""The CAST-128 Encryption Algorithm"">R2144</a>, <a href="#ref-R2612" title=""The CAST-256 Encryption Algorithm"">R2612</a>]




<span class="grey">Shirey                       Informational                     [Page 47]</span>

<span id="page-48" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ category
      (I) A grouping of sensitive information items to which a non-
      hierarchical restrictive security label is applied to increase
      protection of the data. (See: formal access approval. Compare:
      compartment, classification.)

   $ CAW
      (N) See: certification authority workstation.

   $ CBC
      (N) See: cipher block chaining.

   $ CCA
      (O) See: cardholder certification authority.

   $ CCEP
      (O) See: Commercial COMSEC Endorsement Program.

   $ CCI
      (O) See: Controlled Cryptographic Item.

   $ CCITT
      (N) Acronym for French translation of International Telephone and
      Telegraph Consultative Committee. Now renamed ITU-T.

   $ CCM
      (N) See: Counter with Cipher Block Chaining-Message Authentication
      Code.

   $ CERIAS
      (O) Purdue University's Center for Education and Research in
      Information Assurance and Security, which includes faculty from
      multiple schools and departments and takes a multidisciplinary
      approach to security problems ranging from technical to ethical,
      legal, educational, communicational, linguistic, and economic.

   $ CERT
      (I) See: computer emergency response team.

   $ certificate
      1. (I) /general English/ A document that attests to the truth of
      something or the ownership of something.

      2. (I) /general security/ See: capability token, digital
      certificate.

      3. (I) /PKI/ See: attribute certificate, public-key certificate.




<span class="grey">Shirey                       Informational                     [Page 48]</span>

<span id="page-49" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ Certificate Arbitrator Module (CAM)
      (O) An open-source software module that is designed to be
      integrated with an application for routing, replying to, and
      otherwise managing and meditating certificate validation requests
      between that application and the CAs in the ACES PKI.

   $ certificate authority
      (D) Synonym for "certification authority".

      Deprecated Term: IDOCs SHOULD NOT use this term; it suggests
      careless use of the term "certification authority", which is
      preferred in PKI standards (e.g., [<a href="#ref-X509" title=""Information Technology -- Open Systems Interconnection -- The Directory: Authentication Framework"">X509</a>, <a href="#ref-R3280" title=""Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile"">R3280</a>]).

   $ certificate chain
      (D) Synonym for "certification path". (See: trust chain.)

      Deprecated Term: IDOCs SHOULD NOT use this term; it duplicates the
      meaning of a standardized term. Instead, use "certification path".

   $ certificate chain validation
      (D) Synonym for "certificate validation" or "path validation".

      Deprecated Term: IDOCs SHOULD NOT use this term; it duplicates the
      meaning of standardized terms and mixes concepts in a potentially
      misleading way. Instead, use "certificate validation" or "path
      validation", depending on what is meant. (See: validate vs.
      verify.)

   $ certificate creation
      (I) The act or process by which a CA sets the values of a digital
      certificate's data fields and signs it. (See: issue.)

   $ certificate expiration
      (I) The event that occurs when a certificate ceases to be valid
      because its assigned lifetime has been exceeded. (See: certificate
      revocation, expire.)

      Tutorial: The assigned lifetime of an X.509 certificate is stated
      in the certificate itself. (See: validity period.)

   $ certificate extension
      (I) See: extension.

   $ certificate holder
      (D) Synonym for the "subject" of a digital certificate. (Compare:
      certificate owner, certificate user.)





<span class="grey">Shirey                       Informational                     [Page 49]</span>

<span id="page-50" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      Deprecated Definition: IDOCs SHOULD NOT use this term as a synonym
      for the subject of a digital certificate; the term is potentially
      ambiguous. For example, the term could be misunderstood as
      referring to a system entity or component, such as a repository,
      that simply has possession of a copy of the certificate.

   $ certificate management
      (I) The functions that a CA may perform during the lifecycle of a
      digital certificate, including the following:
      -  Acquire and verify data items to bind into the certificate.
      -  Encode and sign the certificate.
      -  Store the certificate in a directory or repository.
      -  Renew, rekey, and update the certificate.
      -  Revoke the certificate and issue a CRL.
      (See: archive management, certificate management, key management,
      security architecture, token management.)

   $ certificate management authority (CMA)
      (D) /U.S. DoD/ Used to mean either a CA or an RA. [<a href="#ref-DoD7" title=""X.509 Certificate Policy for the United States Department of Defense"">DoD7</a>, <a href="#ref-SP32" title=""Introduction to Public Key Technology and the Federal PKI Infrastructure "">SP32</a>]

      Deprecated Term: IDOCs SHOULD NOT use this term because it is
      potentially ambiguous, such as in a context involving ICRLs.
      Instead, use CA, RA, or both, depending on what is meant.

   $ certificate owner
      (D) Synonym for the "subject" of a digital certificate. (Compare:
      certificate holder, certificate user.)

      Deprecated Definition: IDOCs SHOULD NOT use this term as a synonym
      for the subject of a digital certificate; the term is potentially
      ambiguous. For example, the term could refer to a system entity,
      such as a corporation, that has purchased a certificate to operate
      equipment, such as a Web server.

   $ certificate path
      (D) Synonym for "certification path".

      Deprecated Term: IDOCs SHOULD NOT use this term; it suggests
      careless use of "certification path", which is preferred in PKI
      standards (e.g., [<a href="#ref-X509" title=""Information Technology -- Open Systems Interconnection -- The Directory: Authentication Framework"">X509</a>, <a href="#ref-R3280" title=""Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile"">R3280</a>]).

   $ certificate policy
      (I) "A named set of rules that indicates the applicability of a
      certificate to a particular community and/or class of application
      with common security requirements." [<a href="#ref-X509" title=""Information Technology -- Open Systems Interconnection -- The Directory: Authentication Framework"">X509</a>] (Compare: CPS, security
      policy.)





<span class="grey">Shirey                       Informational                     [Page 50]</span>

<span id="page-51" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      Example: U.S. DoD's certificate policy [<a href="#ref-DoD7" title=""X.509 Certificate Policy for the United States Department of Defense"">DoD7</a>] defined four classes
      (i.e., assurance levels) for X.509 public-key certificates and
      defines the applicability of those classes. (See: class 2.)

      Tutorial: A certificate policy can help a certificate user to
      decide whether a certificate should be trusted in a particular
      application. "For example, a particular certificate policy might
      indicate applicability of a type of certificate for the
      authentication of electronic data interchange transactions for the
      trading of goods within a given price range." [<a href="#ref-R3647" title=""Internet X.509 Public Key Infrastructure Certificate Policy and Certification Practices Framework"">R3647</a>]

      A v3 X.509 public-key certificate may have a "certificatePolicies"
      extension that lists certificate policies, recognized by the
      issuing CA, that apply to the certificate and govern its use. Each
      policy is denoted by an object identifier and may optionally have
      certificate policy qualifiers. (See: certificate profile.)

      Each SET certificate specifies at least one certificate policy,
      that of the SET root CA. SET uses certificate policy qualifiers to
      point to the actual policy statement and to add qualifying
      policies to the root policy. (See: SET qualifier.)

   $ certificate policy qualifier
      (I) Information that pertains to a certificate policy and is
      included in a "certificatePolicies" extension in a v3 X.509
      public-key certificate.

   $ certificate profile
      (I) A specification (e.g., [<a href="#ref-DoD7" title=""X.509 Certificate Policy for the United States Department of Defense"">DoD7</a>, <a href="#ref-R3280" title=""Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile"">R3280</a>]) of the format and
      semantics of public-key certificates or attribute certificates,
      constructed for use in a specific application context by selecting
      from among options offered by a broader standard. (Compare:
      protection profile.)

   $ certificate reactivation
      (I) The act or process by which a digital certificate, that a CA
      has designated for revocation but not yet listed on a CRL, is
      returned to the valid state.

   $ certificate rekey
      1. (I) The act or process by which an existing public-key
      certificate has its key value changed by issuing a new certificate
      with a different (usually new) public key. (See: certificate
      renewal, certificate update, rekey.)

      Tutorial: For an X.509 public-key certificate, the essence of
      rekey is that the subject stays the same and a new public key is
      bound to that subject. Other changes are made, and the old



<span class="grey">Shirey                       Informational                     [Page 51]</span>

<span id="page-52" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      certificate is revoked, only as required by the PKI and CPS in
      support of the rekey. If changes go beyond that, the process is a
      "certificate update".

      2. (O) /MISSI/ The act or process by which a MISSI CA creates a
      new X.509 public-key certificate that is identical to the old one,
      except the new one has (a) a new, different KEA key or (b) a new,
      different DSS key or (c) new, different KEA and DSS keys. The new
      certificate also has a different serial number and may have a
      different validity period. A new key creation date and maximum key
      lifetime period are assigned to each newly generated key. If a new
      KEA key is generated, that key is assigned a new KMID. The old
      certificate remains valid until it expires, but may not be further
      renewed, rekeyed, or updated.

   $ certificate renewal
      (I) The act or process by which the validity of the binding
      asserted by an existing public-key certificate is extended in time
      by issuing a new certificate. (See: certificate rekey, certificate
      update.)

      Tutorial: For an X.509 public-key certificate, this term means
      that the validity period is extended (and, of course, a new serial
      number is assigned) but the binding of the public key to the
      subject and to other data items stays the same. The other data
      items are changed, and the old certificate is revoked, only as
      required by the PKI and CPS to support the renewal. If changes go
      beyond that, the process is a "certificate rekey" or "certificate
      update".

   $ certificate request
      (D) Synonym for "certification request".

      Deprecated Term: IDOCs SHOULD NOT use this term; it suggests
      careless use of the term "certification request", which is
      preferred in PKI standards (e.g., see PKCS #10).

   $ certificate revocation
      (I) The event that occurs when a CA declares that a previously
      valid digital certificate issued by that CA has become invalid;
      usually stated with an effective date.

      Tutorial: In X.509, a revocation is announced to potential
      certificate users by issuing a CRL that mentions the certificate.
      Revocation and listing on a CRL is only necessary prior to the
      certificate's scheduled expiration.





<span class="grey">Shirey                       Informational                     [Page 52]</span>

<span id="page-53" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ certificate revocation list (CRL)
      1. (I) A data structure that enumerates digital certificates that
      have been invalidated by their issuer prior to when they were
      scheduled to expire. (See: certificate expiration, delta CRL,
      X.509 certificate revocation list.)

      2. (O) "A signed list indicating a set of certificates that are no
      longer considered valid by the certificate issuer. In addition to
      the generic term CRL, some specific CRL types are defined for CRLs
      that cover particular scopes." [<a href="#ref-X509" title=""Information Technology -- Open Systems Interconnection -- The Directory: Authentication Framework"">X509</a>]

   $ certificate revocation tree
      (N) A mechanism for distributing notices of certificate
      revocations; uses a tree of hash results that is signed by the
      tree's issuer. Offers an alternative to issuing a CRL, but is not
      supported in X.509. (See: certificate status responder.)

   $ certificate serial number
      1. (I) An integer value that (a) is associated with, and may be
      carried in, a digital certificate; (b) is assigned to the
      certificate by the certificate's issuer; and (c) is unique among
      all the certificates produced by that issuer.

      2. (O) "An integer value, unique within the issuing CA, [that] is
      unambiguously associated with a certificate issued by that CA."
      [<a href="#ref-X509" title=""Information Technology -- Open Systems Interconnection -- The Directory: Authentication Framework"">X509</a>]

   $ certificate status authority
      (D) /U.S. DoD/ "A trusted entity that provides on-line
      verification to a Relying Party of a subject certificate's
      trustworthiness [should instead say 'validity'], and may also
      provide additional attribute information for the subject
      certificate." [<a href="#ref-DoD7" title=""X.509 Certificate Policy for the United States Department of Defense"">DoD7</a>]

      Deprecated Term: IDOCs SHOULD NOT use this term because it is not
      widely accepted; instead, use "certificate status responder" or
      "OCSP server", or otherwise explain what is meant.

   $ certificate status responder
      (N) /FPKI/ A trusted online server that acts for a CA to provide
      authenticated certificate status information to certificate users
      [<a href="#ref-FPKI" title=""Public Key Infrastructure (PKI) Technical Specifications: Part A -- Technical Concept of Operations"">FPKI</a>]. Offers an alternative to issuing a CR. (See: certificate
      revocation tree, OCSP.)

   $ certificate update
      (I) The act or process by which non-key data items bound in an
      existing public-key certificate, especially authorizations granted




<span class="grey">Shirey                       Informational                     [Page 53]</span>

<span id="page-54" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      to the subject, are changed by issuing a new certificate. (See:
      certificate rekey, certificate renewal.)

      Usage: For an X.509 public-key certificate, the essence of this
      process is that fundamental changes are made in the data that is
      bound to the public key, such that it is necessary to revoke the
      old certificate. (Otherwise, the process is only a "certificate
      rekey" or "certificate renewal".)

   $ certificate user
      1. (I) A system entity that depends on the validity of information
      (such as another entity's public key value) provided by a digital
      certificate. (See: relying party. Compare: /digital certificate/
      subject.)

      Usage: The depending entity may be a human being or an
      organization, or a device or process controlled by a human or
      organization. (See: user.)

      2. (O) "An entity that needs to know, with certainty, the public
      key of another entity." [<a href="#ref-X509" title=""Information Technology -- Open Systems Interconnection -- The Directory: Authentication Framework"">X509</a>]

      3. (D) Synonym for "subject" of a digital certificate.

      Deprecated Definition: IDOCs SHOULD NOT use this term with
      definition 3; the term could be confused with one of the other two
      definitions given above.

   $ certificate validation
      1. (I) An act or process by which a certificate user establishes
      that the assertions made by a digital certificate can be trusted.
      (See: valid certificate, validate vs. verify.)

      2. (O) "The process of ensuring that a certificate was valid at a
      given time, including possibly the construction and processing of
      a certification path [<a href="#ref-R4158" title=""Internet X.509 Public Key Infrastructure: Certification Path Building"">R4158</a>], and ensuring that all certificates
      in that path were valid (i.e. were not expired or revoked) at that
      given time." [<a href="#ref-X509" title=""Information Technology -- Open Systems Interconnection -- The Directory: Authentication Framework"">X509</a>]

      Tutorial: To validate a certificate, a certificate user checks
      that the certificate is properly formed and signed and is
      currently in force:
      -  Checks the syntax and semantics: Parses the certificate's
         syntax and interprets its semantics, applying rules specified
         for and by its data fields, such as for critical extensions in
         an X.509 certificate.





<span class="grey">Shirey                       Informational                     [Page 54]</span>

<span id="page-55" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      -  Checks the signature: Uses the issuer's public key to verify
         the digital signature of the CA who issued the certificate in
         question. If the verifier obtains the issuer's public key from
         the issuer's own public-key certificate, that certificate
         should be validated, too. That validation may lead to yet
         another certificate to be validated, and so on. Thus, in
         general, certificate validation involves discovering and
         validating a certification path.
      -  Checks currency and revocation: Verifies that the certificate
         is currently in force by checking that the current date and
         time are within the validity period (if that is specified in
         the certificate) and that the certificate is not listed on a
         CRL or otherwise announced as invalid. (The CRLs also must be
         checked by a similar validation process.)

   $ certification
      1. (I) /information system/ Comprehensive evaluation (usually made
      in support of an accreditation action) of an information system's
      technical security features and other safeguards to establish the
      extent to which the system's design and implementation meet a set
      of specified security requirements. [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>, <a href="#ref-FP102" title=""Guideline for Computer Security Certification and Accreditation"">FP102</a>, <a href="#ref-SP37" title=""Guide for the Security Certification and Accreditation of Federal Information Systems"">SP37</a>] (See:
      accreditation. Compare: evaluation.)

      2. (I) /digital certificate/ The act or process of vouching for
      the truth and accuracy of the binding between data items in a
      certificate. (See: certify.)

      3. (I) /PKI/ The act or process of vouching for the ownership of a
      public key by issuing a public-key certificate that binds the key
      to the name of the entity that possesses the matching private key.
      Besides binding a key with a name, a public-key certificate may
      bind those items with other restrictive or explanatory data items.
      (See: X.509 public-key certificate.)

      4. (O) /SET/ "The process of ascertaining that a set of
      requirements or criteria has been fulfilled and attesting to that
      fact to others, usually with some written instrument. A system
      that has been inspected and evaluated as fully compliant with the
      SET protocol by duly authorized parties and process would be said
      to have been certified compliant." [<a href="#ref-SET2" title=""SET Secure Electronic Transaction Specification, Book 2: Programmer's Guide"">SET2</a>]

   $ certification authority (CA)
      1. (I) An entity that issues digital certificates (especially
      X.509 certificates) and vouches for the binding between the data
      items in a certificate.






<span class="grey">Shirey                       Informational                     [Page 55]</span>

<span id="page-56" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      2. (O) "An authority trusted by one or more users to create and
      assign certificates. Optionally the certification authority may
      create the user's keys." [<a href="#ref-X509" title=""Information Technology -- Open Systems Interconnection -- The Directory: Authentication Framework"">X509</a>]

      Tutorial: Certificate users depend on the validity of information
      provided by a certificate. Thus, a CA should be someone that
      certificate users trust and that usually holds an official
      position created and granted power by a government, a corporation,
      or some other organization. A CA is responsible for managing the
      life cycle of certificates (see: certificate management) and,
      depending on the type of certificate and the CPS that applies, may
      be responsible for the lifecycle of key pairs associated with the
      certificates (see: key management).

   $ certification authority workstation (CAW)
      (N) A computer system that enables a CA to issue digital
      certificates and supports other certificate management functions
      as required.

   $ certification hierarchy
      1. (I) A tree-structured (loop-free) topology of relationships
      between CAs and the entities to whom the CAs issue public-key
      certificates. (See: hierarchical PKI, hierarchy management.)

      Tutorial: In this structure, one CA is the top CA, the highest
      level of the hierarchy. (See: root, top CA.) The top CA may issue
      public-key certificates to one or more additional CAs that form
      the second-highest level. Each of these CAs may issue certificates
      to more CAs at the third-highest level, and so on. The CAs at the
      second-lowest level issue certificates only to non-CA entities
      that form the lowest level (see: end entity). Thus, all
      certification paths begin at the top CA and descend through zero
      or more levels of other CAs. All certificate users base path
      validations on the top CA's public key.

      2. (I) /PEM/ A certification hierarchy for PEM has three levels of
      CAs [<a href="#ref-R1422" title=""Privacy Enhancement for Internet Electronic Mail, Part II: Certificate-Based Key Management"">R1422</a>]:
      -  The highest level is the "Internet Policy Registration
         Authority".
      -  A CA at the second-highest level is a "policy certification
         authority".
      -  A CA at the third-highest level is a "certification authority".

      3. (O) /MISSI/ A certification hierarchy for MISSI has three or
      four levels of CAs:
      -  A CA at the highest level, the top CA, is a "policy approving
         authority".




<span class="grey">Shirey                       Informational                     [Page 56]</span>

<span id="page-57" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      -  A CA at the second-highest level is a "policy creation
         authority".
      -  A CA at the third-highest level is a local authority called a
         "certification authority".
      -  A CA at the fourth-highest (optional) level is a "subordinate
         certification authority".

      4. (O) /SET/ A certification hierarchy for SET has three or four
      levels of CAs:
      -  The highest level is a "SET root CA".
      -  A CA at the second-highest level is a "brand certification
         authority".
      -  A CA at the third-highest (optional) level is a "geopolitical
         certification authority".
      -  A CA at the fourth-highest level is a "cardholder CA", a
         "merchant CA", or a "payment gateway CA".

   $ certification path
      1. (I) A linked sequence of one or more public-key certificates,
      or one or more public-key certificates and one attribute
      certificate, that enables a certificate user to verify the
      signature on the last certificate in the path, and thus enables
      the user to obtain (from that last certificate) a certified public
      key, or certified attributes, of the system entity that is the
      subject of that last certificate. (See: trust anchor, certificate
      validation, valid certificate.)

      2. (O) "An ordered sequence of certificates of objects in the
      [X.500 Directory Information Tree] which, together with the public
      key of the initial object in the path, can be processed to obtain
      that of the final object in the path." [<a href="#ref-R3647" title=""Internet X.509 Public Key Infrastructure Certificate Policy and Certification Practices Framework"">R3647</a>, <a href="#ref-X509" title=""Information Technology -- Open Systems Interconnection -- The Directory: Authentication Framework"">X509</a>]

      Tutorial: The list is "linked" in the sense that the digital
      signature of each certificate (except possibly the first) is
      verified by the public key contained in the preceding certificate;
      i.e., the private key used to sign a certificate and the public
      key contained in the preceding certificate form a key pair that
      has previously been bound to the authority that signed.

      The path is the "list of certificates needed to [enable] a
      particular user to obtain the public key [or attributes] of
      another [user]." [<a href="#ref-X509" title=""Information Technology -- Open Systems Interconnection -- The Directory: Authentication Framework"">X509</a>] Here, the word "particular" points out
      that a certification path that can be validated by one certificate
      user might not be able to be validated by another. That is because
      either the first certificate needs to be a trusted certificate or
      the signature on the first certificate needs to be verifiable by a
      trusted key (e.g., a root key), but such trust is established only




<span class="grey">Shirey                       Informational                     [Page 57]</span>

<span id="page-58" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      relative to a "particular" (i.e., specific) user, not absolutely
      for all users.

   $ certification policy
      (D) Synonym for either "certificate policy" or "certification
      practice statement".

      Deprecated Term: IDOCs SHOULD NOT use this term as a synonym for
      either of those terms; that would be duplicative and would mix
      concepts in a potentially misleading way. Instead, use either
      "certificate policy" or "certification practice statement",
      depending on what is meant.

   $ certification practice statement (CPS)
      (I) "A statement of the practices which a certification authority
      employs in issuing certificates." [<a href="#ref-DSG" title=""Digital Signature Guidelines: Legal Infrastructure for Certification Authorities and Secure Electronic Commerce"">DSG</a>, <a href="#ref-R3647" title=""Internet X.509 Public Key Infrastructure Certificate Policy and Certification Practices Framework"">R3647</a>] (See: certificate
      policy.)

      Tutorial: A CPS is a published security policy that can help a
      certificate user to decide whether a certificate issued by a
      particular CA can be trusted enough to use in a particular
      application. A CPS may be (a) a declaration by a CA of the details
      of the system and practices it uses in its certificate management
      operations, (b) part of a contract between the CA and an entity to
      whom a certificate is issued, (c) a statute or regulation
      applicable to the CA, or (d) a combination of these types
      involving multiple documents. [<a href="#ref-DSG" title=""Digital Signature Guidelines: Legal Infrastructure for Certification Authorities and Secure Electronic Commerce"">DSG</a>]

      A CPS is usually more detailed and procedurally oriented than a
      certificate policy. A CPS applies to a particular CA or CA
      community, while a certificate policy applies across CAs or
      communities. A CA with its single CPS may support multiple
      certificate policies, which may be used for different application
      purposes or by different user communities. On the other hand,
      multiple CAs, each with a different CPS, may support the same
      certificate policy. [<a href="#ref-R3647" title=""Internet X.509 Public Key Infrastructure Certificate Policy and Certification Practices Framework"">R3647</a>]

   $ certification request
      (I) An algorithm-independent transaction format (e.g., PKCS #10,
      <a href="./rfc4211">RFC 4211</a>) that contains a DN, and a public key or, optionally, a
      set of attributes, collectively signed by the entity requesting
      certification, and sent to a CA, which transforms the request to
      an X.509 public-key certificate or another type of certificate.

   $ certify
      1. (I) Issue a digital certificate and thus vouch for the truth,
      accuracy, and binding between data items in the certificate (e.g.,
      "X.509 public-key certificate"), such as the identity of the



<span class="grey">Shirey                       Informational                     [Page 58]</span>

<span id="page-59" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      certificate's subject and the ownership of a public key. (See:
      certification.)

      Usage: To "certify a public key" means to issue a public-key
      certificate that vouches for the binding between the certificate's
      subject and the key.

      2. (I) The act by which a CA uses measures to verify the truth,
      accuracy, and binding between data items in a digital certificate.

      Tutorial: A description of the measures used for verification
      should be included in the CA's CPS.

   $ CFB
      (N) See: cipher feedback.

   $ chain
      (D) See: trust chain.

   $ Challenge Handshake Authentication Protocol (CHAP)
      (I) A peer entity authentication method (employed by PPP and other
      protocols, e.g., <a href="./rfc3720">RFC 3720</a>) that uses a randomly generated
      challenge and requires a matching response that depends on a
      cryptographic hash of some combination of the challenge and a
      secret key. [<a href="#ref-R1994" title=""PPP Challenge Handshake Authentication Protocol (CHAP)"">R1994</a>] (See: challenge-response, PAP.)

   $ challenge-response
      (I) An authentication process that verifies an identity by
      requiring correct authentication information to be provided in
      response to a challenge. In a computer system, the authentication
      information is usually a value that is required to be computed in
      response to an unpredictable challenge value, but it might be just
      a password.

   $ Challenge-Response Authentication Mechanism (CRAM)
      (I) /IMAP4/ A mechanism [<a href="#ref-R2195" title=""IMAP/POP AUTHorize Extension for Simple Challenge/Response"">R2195</a>], intended for use with IMAP4
      AUTHENTICATE, by which an IMAP4 client uses a keyed hash [<a href="#ref-R2104" title=""HMAC: Keyed- Hashing for Message Authentication"">R2104</a>]
      to authenticate itself to an IMAP4 server. (See: POP3 APOP.)

      Tutorial: The server includes a unique time stamp in its ready
      response to the client. The client replies with the client's name
      and the hash result of applying MD5 to a string formed from
      concatenating the time stamp with a shared secret that is known
      only to the client and the server.

   $ channel
      1. (I) An information transfer path within a system. (See: covert
      channel.)



<span class="grey">Shirey                       Informational                     [Page 59]</span>

<span id="page-60" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      2. (O) "A subdivision of the physical medium allowing possibly
      shared independent uses of the medium." (<a href="./rfc3753">RFC 3753</a>)

   $ channel capacity
      (I) The total capacity of a link to carry information; usually
      expressed in bits per second. (<a href="./rfc3753">RFC 3753</a>) (Compare: bandwidth.)

      Tutorial: Within a given bandwidth, the theoretical maximum
      channel capacity is given by Shannon's Law. The actual channel
      capacity is determined by the bandwidth, the coding system used,
      and the signal-to-noise ratio.

   $ CHAP
      (I) See: Challenge Handshake Authentication Protocol.

   $ checksum
      (I) A value that (a) is computed by a function that is dependent
      on the contents of a data object and (b) is stored or transmitted
      together with the object, for detecting changes in the data. (See:
      cyclic redundancy check, data integrity service, error detection
      code, hash, keyed hash, parity bit, protected checksum.)

      Tutorial: To gain confidence that a data object has not been
      changed, an entity that later uses the data can independently
      recompute the checksum value and compare the result with the value
      that was stored or transmitted with the object.

      Computer systems and networks use checksums (and other mechanisms)
      to detect accidental changes in data. However, active wiretapping
      that changes data could also change an accompanying checksum to
      match the changed data. Thus, some checksum functions by
      themselves are not good countermeasures for active attacks. To
      protect against active attacks, the checksum function needs to be
      well-chosen (see: cryptographic hash), and the checksum result
      needs to be cryptographically protected (see: digital signature,
      keyed hash).

   $ Chinese wall policy
      (I) A security policy to prevent conflict of interest caused by an
      entity (e.g., a consultant) interacting with competing firms.
      (See: Brewer-Nash model.)

      Tutorial: All information is categorized into mutually exclusive
      conflict-of-interest classes I(1), I(2), ..., I(M), and each firm
      F(1), F(2), ..., F(N) belongs to exactly one class. The policy
      states that if a consultant has access to class I(i) information
      from a firm in that class, then the consultant may not access
      information from another firm in that same class, but may access



<span class="grey">Shirey                       Informational                     [Page 60]</span>

<span id="page-61" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      information from another firm that is in a different class. Thus,
      the policy creates a barrier to communication between firms that
      are in the same conflict-of-interest class. Brewer and Nash
      modeled enforcement of this policy [<a href="#ref-BN89" title=""The Chinese wall security policy"">BN89</a>], including dealing with
      policy violations that could occur because two or more consultants
      work for the same firm.

   $ chosen-ciphertext attack
      (I) A cryptanalysis technique in which the analyst tries to
      determine the key from knowledge of plain text that corresponds to
      cipher text selected (i.e., dictated) by the analyst.

   $ chosen-plaintext attack
      (I) A cryptanalysis technique in which the analyst tries to
      determine the key from knowledge of cipher text that corresponds
      to plain text selected (i.e., dictated) by the analyst.

   $ CIAC
      (O) See: Computer Incident Advisory Capability.

   $ CIK
      (N) See: cryptographic ignition key.

   $ cipher
      (I) A cryptographic algorithm for encryption and decryption.

   $ cipher block chaining (CBC)
      (N) A block cipher mode that enhances ECB mode by chaining
      together blocks of cipher text it produces. [<a href="#ref-FP081" title=""DES Modes of Operation"">FP081</a>] (See: block
      cipher, [<a href="#ref-R1829" title=""The ESP DES-CBC Transform"">R1829</a>], [<a href="#ref-R2405" title=""The ESP DES-CBC Cipher Algorithm With Explicit IV"">R2405</a>], [<a href="#ref-R2451" title=""The ESP CBC-Mode Cipher Algorithms"">R2451</a>], [<a href="#ref-SP38A" title=""Recommendation for Block Cipher Modes of Operation: Methods and Techniques"">SP38A</a>].)

      Tutorial: This mode operates by combining (exclusive OR-ing) the
      algorithm's ciphertext output block with the next plaintext block
      to form the next input block for the algorithm.

   $ cipher feedback (CFB)
      (N) A block cipher mode that enhances ECB mode by chaining
      together the blocks of cipher text it produces and operating on
      plaintext segments of variable length less than or equal to the
      block length. [<a href="#ref-FP081" title=""DES Modes of Operation"">FP081</a>] (See: block cipher, [<a href="#ref-SP38A" title=""Recommendation for Block Cipher Modes of Operation: Methods and Techniques"">SP38A</a>].)

      Tutorial: This mode operates by using the previously generated
      ciphertext segment as the algorithm's input (i.e., by "feeding
      back" the cipher text) to generate an output block, and then
      combining (exclusive OR-ing) that output block with the next
      plaintext segment (block length or less) to form the next
      ciphertext segment.




<span class="grey">Shirey                       Informational                     [Page 61]</span>

<span id="page-62" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ cipher text
      1. (I) /noun/ Data that has been transformed by encryption so that
      its semantic information content (i.e., its meaning) is no longer
      intelligible or directly available. (See: ciphertext. Compare:
      clear text, plain text.)

      2. (O) "Data produced through the use of encipherment. The
      semantic content of the resulting data is not available."
      [<a href="#ref-I7498-2" title=""Information Processing Systems -- Open Systems Interconnection Reference Model, Part 2: Security Architecture"">I7498-2</a>]

   $ ciphertext
      1. (O) /noun/ Synonym for "cipher text" [<a href="#ref-I7498-2" title=""Information Processing Systems -- Open Systems Interconnection Reference Model, Part 2: Security Architecture"">I7498-2</a>].

      2. (I) /adjective/ Referring to cipher text. Usage: Commonly used
      instead of "cipher-text". (Compare: cleartext, plaintext.)

   $ ciphertext auto-key (CTAK)
      (D) "Cryptographic logic that uses previous cipher text to
      generate a key stream." [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>, <a href="#ref-A1523" title=""American National Standard Telecom Glossary"">A1523</a>] (See: KAK.)

      Deprecated Term: IDOCs SHOULD NOT use this term; it is neither
      well-known nor precisely defined. Instead, use terms associated
      with modes that are defined in standards, such as CBC, CFB, and
      OFB.

   $ ciphertext-only attack
      (I) A cryptanalysis technique in which the analyst tries to
      determine the key solely from knowledge of intercepted cipher text
      (although the analyst may also know other clues, such as the
      cryptographic algorithm, the language in which the plain text was
      written, the subject matter of the plain text, and some probable
      plaintext words.)

   $ ciphony
      (O) The process of encrypting audio information.

   $ CIPSO
      (I) See: Common IP Security Option.

   $ CKL
      (I) See: compromised key list.

   $ Clark-Wilson model
      (N) A security model [<a href="#ref-Clark" title=""A Comparison of Commercial and Military computer Security Policies"">Clark</a>] to maintain data integrity in the
      commercial world. (Compare: Bell-LaPadula model.)






<span class="grey">Shirey                       Informational                     [Page 62]</span>

<span id="page-63" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ class 2, 3, 4, 5
      (O) /U.S. DoD/ Assurance levels for PKIs, and for X.509 public-key
      certificates issued by a PKI. [<a href="#ref-DoD7" title=""X.509 Certificate Policy for the United States Department of Defense"">DoD7</a>] (See: "first law" under
      "Courtney's laws".)
      -  "Class 2": Intended for applications handling unclassified,
         low-value data in minimally or moderately protected
         environments.
      -  "Class 3": Intended for applications handling unclassified,
         medium-value data in moderately protected environments, or
         handling unclassified or high-value data in highly protected
         environments, and for discretionary access control of
         classified data in highly protected environments.
      -  "Class 4": Intended for applications handling unclassified,
         high-value data in minimally protected environments.
      -  "Class 5": Intended for applications handling classified data
         in minimally protected environments, and for authentication of
         material that would affect the security of classified systems.

      The environments are defined as follows:
      -  "Highly protected environment": Networks that are protected
         either with encryption devices approved by NSA for protection
         of classified data or via physical isolation, and that are
         certified for processing system-high classified data, where
         exposure of unencrypted data is limited to U.S. citizens
         holding appropriate security clearances.
      -  "Moderately protected environment":
         -- Physically isolated unclassified, unencrypted networks in
            which access is restricted based on legitimate need.
         -- Networks protected by NSA-approved, type 1 encryption,
            accessible by U.S.-authorized foreign nationals.
      -  "Minimally protected environments": Unencrypted networks
         connected to either the Internet or NIPRNET, either directly or
         via a firewall.

   $ Class A1, B3, B2, B1, C2, or C1 computer system
      (O) /TCSEC/ See: Tutorial under "Trusted Computer System
      Evaluation Criteria".

   $ classification
      1. (I) A grouping of classified information to which a
      hierarchical, restrictive security label is applied to increase
      protection of the data from unauthorized disclosure. (See:
      aggregation, classified, data confidentiality service. Compare:
      category, compartment.)

      2. (I) An authorized process by which information is determined to
      be classified and assigned to a security level. (Compare:
      declassification.)



<span class="grey">Shirey                       Informational                     [Page 63]</span>

<span id="page-64" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      Usage: Usually understood to involve data confidentiality, but
      IDOCs SHOULD make this clear when data also is sensitive in other
      ways and SHOULD use other terms for those other sensitivity
      concepts. (See: sensitive information, data integrity.)

   $ classification label
      (I) A security label that tells the degree of harm that will
      result from unauthorized disclosure of the labeled data, and may
      also tell what countermeasures are required to be applied to
      protect the data from unauthorized disclosure. Example: IPSO.
      (See: classified, data confidentiality service. Compare: integrity
      label.)

      Usage: Usually understood to involve data confidentiality, but
      IDOCs SHOULD make this clear when data also is sensitive in other
      ways and SHOULD use other terms for those other sensitivity
      concepts. (See: sensitive information, data integrity.)

   $ classification level
      (I) A hierarchical level of protection (against unauthorized
      disclosure) that is required to be applied to certain classified
      data. (See: classified. Compare: security level.)

      Usage: Usually understood to involve data confidentiality, but
      IDOCs SHOULD make this clear when data also is sensitive in other
      ways and SHOULD use other terms for those other sensitivity
      concepts. (See: sensitive information, data integrity.)

   $ classified
      1. (I) Refers to information (stored or conveyed, in any form)
      that is formally required by a security policy to receive data
      confidentiality service and to be marked with a security label
      (which, in some cases, might be implicit) to indicate its
      protected status. (See: classify, collateral information, SAP,
      security level. Compare: unclassified.)

      Usage: Usually understood to involve data confidentiality, but
      IDOCs SHOULD make this clear when data also is sensitive in other
      ways and SHOULD use other terms for those other sensitivity
      concepts. (See: sensitive information, data integrity.)

      Mainly used by national governments, especially by the military,
      but the underlying concept also applies outside of governments.

      2. (O) /U.S. Government/ "Information that has been determined
      pursuant to Executive Order 12958 or any predecessor Order, or by
      the Atomic Energy Act of 1954, as amended, to require protection




<span class="grey">Shirey                       Informational                     [Page 64]</span>

<span id="page-65" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      against unauthorized disclosure and is marked to indicate its
      classified status." [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>]

   $ classify
      (I) To officially designate an information item or type of
      information as being classified and assigned to a specific
      security level. (See: classified, declassify, security level.)

   $ clean system
      (I) A computer system in which the operating system and
      application system software and files have been freshly installed
      from trusted software distribution media. (Compare: secure state.)

   $ clear
      (D) /verb/ Synonym for "erase". [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>]

      Deprecated Definition: IDOCs SHOULD NOT use the term with this
      definition; that could be confused with "clear text" in which
      information is directly recoverable.

   $ clear text
      1. (I) /noun/ Data in which the semantic information content
      (i.e., the meaning) is intelligible or is directly available,
      i.e., not encrypted. (See: cleartext, in the clear. Compare:
      cipher text, plain text.)

      2. (O) /noun/ "Intelligible data, the semantic content of which is
      available." [<a href="#ref-I7498-2" title=""Information Processing Systems -- Open Systems Interconnection Reference Model, Part 2: Security Architecture"">I7498-2</a>]

      3. (D) /noun/ Synonym for "plain text".

      Deprecated Definition: IDOCs SHOULD NOT use this term as a synonym
      for "plain text", because the plain text that is input to an
      encryption operation may itself be cipher text that was output
      from a previous encryption operation. (See: superencryption.)

   $ clearance
      See: security clearance.

   $ clearance level
      (I) The security level of information to which a security
      clearance authorizes a person to have access.

   $ cleartext
      1. (O) /noun/ Synonym for "clear text" [<a href="#ref-I7498-2" title=""Information Processing Systems -- Open Systems Interconnection Reference Model, Part 2: Security Architecture"">I7498-2</a>].

      2. (I) /adjective/ Referring to clear text. Usage: Commonly used
      instead of "clear-text". (Compare: ciphertext, plaintext.)



<span class="grey">Shirey                       Informational                     [Page 65]</span>

<span id="page-66" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      3. (D) /adjective/ Synonym for "plaintext".

      Deprecated Definition: IDOCs SHOULD NOT use this term as a synonym
      for "plaintext", because the plaintext data that is input to an
      encryption operation may itself be ciphertext data that was output
      from a previous encryption operation. (See: superencryption.)

   $ CLEF
      (N) See: commercially licensed evaluation facility.

   $ client
      (I) A system entity that requests and uses a service provided by
      another system entity, called a "server". (See: server.)

      Tutorial: Usually, it is understood that the client and server are
      automated components of the system, and the client makes the
      request on behalf of a human user. In some cases, the server may
      itself be a client of some other server.

   $ client-server system
      (I) A distributed system in which one or more entities, called
      clients, request a specific service from one or more other
      entities, called servers, that provide the service to the clients.

      Example: The Word Wide Web, in which component servers provide
      information that is requested by component clients called
      "browsers".

   $ CLIPPER
      (N) An integrated microcircuit (in MYK-7x series manufactured by
      Mykotronx, Inc.) that implements SKIPJACK, has a non-deterministic
      random number generator, and supports key escrow. (See: Escrowed
      Encryption Standard. Compare: CLIPPER.)

      Tutorial: The chip was mainly intended for protecting
      telecommunications over the public switched network. The key
      escrow scheme for the chip involves a SKIPJACK key that is common
      to all chips and that protects the unique serial number of the
      chip, and a second SKIPJACK key unique to the chip that protects
      all data encrypted by the chip. The second key is escrowed as
      split key components held by NIST and the U.S. Treasury
      Department.

   $ closed security environment
      (O) /U.S. DoD/ A system environment that meets both of the
      following conditions: (a) Application developers (including
      maintainers) have sufficient clearances and authorizations to
      provide an acceptable presumption that they have not introduced



<span class="grey">Shirey                       Informational                     [Page 66]</span>

<span id="page-67" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      malicious logic. (b) Configuration control provides sufficient
      assurance that system applications and the equipment they run on
      are protected against the introduction of malicious logic prior to
      and during the operation of applications. [<a href="#ref-NCS04" title=""Glossary of Computer Security Terms"">NCS04</a>] (See: "first
      law" under "Courtney's laws". Compare: open security environment.)

   $ CMA
      (D) See: certificate management authority.

   $ CMAC
      (N) A message authentication code [<a href="#ref-SP38B" title=""Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication"">SP38B</a>] that is based on a
      symmetric block cipher. (See: block cipher.)

      Derivation: Cipher-based MAC. (Compare: HMAC.)

      Tutorial: Because CMAC is based on approved, symmetric-key block
      ciphers, such as AES, CMAC can be considered a mode of operation
      for those block ciphers. (See: mode of operation.)

   $ CMCS
      (O) See: COMSEC Material Control System.

   $ CMM
      (N) See: Capability Maturity Model.

   $ CMS
      (I) See: Cryptographic Message Syntax.

   $ code
      1. (I) A system of symbols used to represent information, which
      might originally have some other representation. Examples: ASCII,
      BER, country code, Morse code. (See: encode, object code, source
      code.)

      Deprecated Abbreviation: To avoid confusion with definition 1,
      IDOCs SHOULD NOT use "code" as an abbreviation of "country code",
      "cyclic redundancy code", "Data Authentication Code", "error
      detection code", or "Message Authentication Code". To avoid
      misunderstanding, use the fully qualified term in these other
      cases, at least at the point of first usage.

      2. (I) /cryptography/ An encryption algorithm based on
      substitution; i.e., a system for providing data confidentiality by
      using arbitrary groups (called "code groups") of letters, numbers,
      or symbols to represent units of plain text of varying length.
      (See: codebook, cryptography.)





<span class="grey">Shirey                       Informational                     [Page 67]</span>

<span id="page-68" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      Deprecated Usage: To avoid confusion with definition 1, IDOCs
      SHOULD NOT use "code" as a synonym for any of the following terms:
      (a) "cipher", "hash", or other words that mean "a cryptographic
      algorithm"; (b) "cipher text"; or (c) "encrypt", "hash", or other
      words that refer to applying a cryptographic algorithm.

      3. (I) An algorithm based on substitution, but used to shorten
      messages rather than to conceal their content.

      4. (I) /computer programming/ To write computer software. (See:
      object code, source code.)

      Deprecated Abbreviation: To avoid confusion with definition 1,
      IDOCs SHOULD NOT use "code" as an abbreviation of "object code" or
      "source code". To avoid misunderstanding, use the fully qualified
      term in these other cases, at least at the point of first usage.

   $ code book
      1. (I) Document containing a systematically arranged list of
      plaintext units and their ciphertext equivalents. [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>]

      2. (I) An encryption algorithm that uses a word substitution
      technique. [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>] (See: code, ECB.)

   $ code signing
      (I) A security mechanism that uses a digital signature to provide
      data integrity and data origin authentication for software that is
      being distributed for use. (See: mobile code, trusted
      distribution.)

      Tutorial: In some cases, the signature on a software module may
      imply some assertion that the signer makes about the software. For
      example, a signature may imply that the software has been
      designed, developed, or tested according to some criterion.

   $ code word
      (O) /U.S. Government/ A single word that is used as a security
      label (usually applied to classified information) but which itself
      has a classified meaning. (See: classified, /U.S. Government/
      security label.)

   $ COI
      (I) See: community of interest.

   $ cold start
      (N) /cryptographic module/ A procedure for initially keying
      cryptographic equipment. [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>]




<span class="grey">Shirey                       Informational                     [Page 68]</span>

<span id="page-69" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ collateral information
      (O) /U.S. Government/ Information that is classified but is not
      required to be protected by an SAP. (See: /U.S. Government/
      classified.)

   $ color change
      (I) In a system being operated in periods-processing mode, the act
      of purging all information from one processing period and then
      changing over to the next processing period. (See: BLACK, RED.)

   $ Commercial COMSEC Evaluation Program (CCEP)
      (O) "Relationship between NSA and industry in which NSA provides
      the COMSEC expertise (i.e., standards, algorithms, evaluations,
      and guidance) and industry provides design, development, and
      production capabilities to produce a type 1 or type 2 product."
      [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>]

   $ commercially licensed evaluation facility (CLEF)
      (N) An organization that has official approval to evaluate the
      security of products and systems under the Common Criteria, ITSEC,
      or some other standard. (Compare: KLIF.)

   $ Committee on National Security Systems (CNSS)
      (O) /U.S. Government/ A Government, interagency, standing
      committee of the President's Critical Infrastructure Protection
      Board. The CNSS is chaired by the Secretary of Defense and
      provides a forum for the discussion of policy issues, sets
      national policy, and promulgates direction, operational
      procedures, and guidance for the security of national security
      systems. The Secretary of Defense and the Director of Central
      Intelligence are responsible for developing and overseeing the
      implementation of Government-wide policies, principles, standards,
      and guidelines for the security of systems that handle national
      security information.

   $ Common Criteria for Information Technology Security
      (N) A standard for evaluating information technology (IT) products
      and systems. It states requirements for security functions and for
      assurance measures. [<a href="#ref-CCIB" title=""Common Criteria for Information Technology Security Evaluation, Part 1: Introduction and General Model"">CCIB</a>] (See: CLEF, EAL, packages, protection
      profile, security target, TOE. Compare: CMM.)

      Tutorial: Canada, France, Germany, the Netherlands, the United
      Kingdom, and the United States (NIST and NSA) began developing
      this standard in 1993, based on the European ITSEC, the Canadian
      Trusted Computer Product Evaluation Criteria (CTCPEC), and the
      U.S. "Federal Criteria for Information Technology Security" and
      its precursor, the TCSEC. Work was done in cooperation with
      ISO/IEC Joint Technical Committee 1 (Information Technology),



<span class="grey">Shirey                       Informational                     [Page 69]</span>

<span id="page-70" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      Subcommittee 27 (Security Techniques), Working Group 3 (Security
      Criteria). Version 2.0 of the Criteria has been issued as ISO's
      International Standard 15408. The U.S. Government intends this
      standard to supersede both the TCSEC and FIPS PUB 140. (See:
      NIAP.)

      The standard addresses data confidentiality, data integrity, and
      availability and may apply to other aspects of security. It
      focuses on threats to information arising from human activities,
      malicious or otherwise, but may apply to non-human threats. It
      applies to security measures implemented in hardware, firmware, or
      software. It does not apply to (a) administrative security not
      related directly to technical security, (b) technical physical
      aspects of security such as electromagnetic emanation control, (c)
      evaluation methodology or administrative and legal framework under
      which the criteria may be applied, (d) procedures for use of
      evaluation results, or (e) assessment of inherent qualities of
      cryptographic algorithms.

      Part 1, Introduction and General Model, defines general concepts
      and principles of IT security evaluation; presents a general model
      of evaluation; and defines constructs for expressing IT security
      objectives, for selecting and defining IT security requirements,
      and for writing high-level specifications for products and
      systems.

      Part 2, Security Functional Requirements, contains a catalog of
      well-defined and well-understood functional requirement statements
      that are intended to be used as a standard way of expressing the
      security requirements for IT products and systems.

      Part 3, Security Assurance Requirements, contains a catalog of
      assurance components for use as a standard way of expressing such
      requirements for IT products and systems, and defines evaluation
      criteria for protection profiles and security targets.

   $ Common IP Security Option (CIPSO)
      (I) See: secondary definition under "IPSO".

   $ common name
      (N) A character string that (a) may be a part of the X.500 DN of a
      Directory object ("commonName" attribute), (b) is a (possibly
      ambiguous) name by which the object is commonly known in some
      limited scope (such as an organization), and (c) conforms to the
      naming conventions of the country or culture with which it is
      associated. [<a href="#ref-X520" title=""Information Technology -- Open Systems Interconnection -- The Directory: Selected Attribute Types"">X520</a>] (See: "subject" and "issuer" under "X.509
      public-key certificate".)




<span class="grey">Shirey                       Informational                     [Page 70]</span>

<span id="page-71" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      Examples: "Dr. Albert Einstein", "The United Nations", and "12-th
      Floor Laser Printer".

   $ communications cover
      (N) "Concealing or altering of characteristic communications
      patterns to hide information that could be of value to an
      adversary." [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>] (See: operations security, traffic-flow
      confidentiality, TRANSEC.)

   $ communication security (COMSEC)
      (I) Measures that implement and assure security services in a
      communication system, particularly those that provide data
      confidentiality and data integrity and that authenticate
      communicating entities.

      Usage: COMSEC is usually understood to include (a) cryptography
      and its related algorithms and key management methods and
      processes, devices that implement those algorithms and processes,
      and the lifecycle management of the devices and keying material.
      Also, COMSEC is sometimes more broadly understood as further
      including (b) traffic-flow confidentiality, (c) TRANSEC, and (d)
      steganography [<a href="#ref-Kahn" title=""The Codebreakers: The Story of Secret Writing"">Kahn</a>]. (See: cryptology, signal security.)

   $ community of interest (COI)
      1. (I) A set of entities that operate under a common security
      policy. (Compare: domain.)

      2. (I) A set of entities that exchange information collaboratively
      for some purpose.

   $ community risk
      (N) Probability that a particular vulnerability will be exploited
      within an interacting population and adversely affect some members
      of that population. [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>] (See: Morris worm, risk.)

   $ community string
      (I) A community name in the form of an octet string that serves as
      a cleartext password in SNMP version 1 (<a href="./rfc1157">RFC 1157</a>) and version 2
      (<a href="./rfc1901">RFC 1901</a>). (See: password, Simple Network Management Protocol.)

      Tutorial: The SNMPv1 and SNMPv2 protocols have been declared
      "historic" and have been replaced by the more secure SNMPv3
      standard (RFCs 3410-3418), which does not use cleartext passwords.








<span class="grey">Shirey                       Informational                     [Page 71]</span>

<span id="page-72" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ compartment
      1. (I) A grouping of sensitive information items that require
      special access controls beyond those normally provided for the
      basic classification level of the information. (See: compartmented
      security mode. Compare: category, classification.)

      Usage: The term is usually understood to include the special
      handling procedures to be used for the information.

      2. (I) Synonym for "category".

      Deprecated Usage: This Glossary defines "category" with a slightly
      narrower meaning than "compartment". That is, a security label is
      assigned to a category because the data owner needs to handle the
      data as a compartment. However, a compartment could receive
      special protection in a system without being assigned a category
      label.

   $ compartmented security mode
      (N) A mode of system operation wherein all users having access to
      the system have the necessary security clearance for the single,
      hierarchical classification level of all data handled by the
      system, but some users do not have the clearance for a non-
      hierarchical category of some data handled by the system. (See:
      category, /system operation/ under "mode", protection level,
      security clearance.)

      Usage: Usually abbreviated as "compartmented mode". This term was
      defined in U.S. Government policy on system accreditation. In this
      mode, a system may handle (a) a single hierarchical classification
      level and (b) multiple non-hierarchical categories within that
      level.

   $ Compartments field
      (I) A 16-bit field (the "C field") that specifies compartment
      values in the security option (option type 130) of version 4 IP's
      datagram header format. The valid field values are assigned by the
      U.S. Government, as specified in <a href="./rfc791">RFC 791</a>.

      Deprecated Abbreviation: IDOCs SHOULD NOT use the abbreviation "C
      field"; the abbreviation is potentially ambiguous. Instead, use
      "Compartments field".

   $ component
      See: system component.






<span class="grey">Shirey                       Informational                     [Page 72]</span>

<span id="page-73" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ compression
      (I) A process that encodes information in a way that minimizes the
      number of resulting code symbols and thus reduces storage space or
      transmission time.

      Tutorial: A data compression algorithm may be "lossless", i.e.,
      retain all information that was encoded in the data, so that
      decompression can recover all the information; or an algorithm may
      be "lossy". Text usually needs to be compressed losslessly, but
      images are often compressed with lossy schemes.

      Not all schemes that encode information losslessly for machine
      processing are efficient in terms of minimizing the number of
      output bits. For example, ASCII encoding is lossless, but ASCII
      data can often be losslessly reencoded in fewer bits with other
      schemes. These more efficient schemes take advantage of some sort
      of inherent imbalance, redundancy, or repetition in the data, such
      as by replacing a character string in which all characters are the
      same by a shorter string consisting of only the single character
      and a character count.

      Lossless compression schemes cannot effectively reduce the number
      of bits in cipher text produced by a strong encryption algorithm,
      because the cipher text is essentially a pseudorandom bit string
      that does not contain patterns susceptible to reencoding.
      Therefore, protocols that offer both encryption and compression
      services (e.g., SSL) need to perform the compression operation
      before the encryption operation.

   $ compromise
      See: data compromise, security compromise.

   $ compromise recovery
      (I) The process of regaining a secure state for a system after
      detecting that the system has experienced a security compromise.

   $ compromised key list (CKL)
      (N) /MISSI/ A list that identifies keys for which unauthorized
      disclosure or alteration may have occurred. (See: compromise.)

      Tutorial: A CKL is issued by a CA, like a CRL is issued. But a CKL
      lists only KMIDs, not subjects that hold the keys, and not
      certificates in which the keys are bound.

   $ COMPUSEC
      (I) See: computer security.





<span class="grey">Shirey                       Informational                     [Page 73]</span>

<span id="page-74" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ computer emergency response team (CERT)
      (I) An organization that studies computer and network INFOSEC in
      order to provide incident response services to victims of attacks,
      publish alerts concerning vulnerabilities and threats, and offer
      other information to help improve computer and network security.
      (See: CSIRT, security incident.)

      Examples: CERT Coordination Center at Carnegie Mellon University
      (sometimes called "the" CERT); CIAC.

   $ Computer Incident Advisory Capability (CIAC)
      (O) The centralized CSIRT of the U.S. Department of Energy; a
      member of FIRST.

   $ computer network
      (I) A collection of host computers together with the subnetwork or
      internetwork through which they can exchange data.

      Usage: This definition is intended to cover systems of all sizes
      and types, ranging from the complex Internet to a simple system
      composed of a personal computer dialing in as a remote terminal of
      another computer.

   $ computer platform
      (I) A combination of computer hardware and an operating system
      (which may consist of software, firmware, or both) for that
      hardware. (Compare: computer system.)

   $ computer security (COMPUSEC)
      1. (I) Measures to implement and assure security services in a
      computer system, particularly those that assure access control
      service.

      Usage: Usually refers to internal controls (functions, features,
      and technical characteristics) that are implemented in software
      (especially in operating systems); sometimes refers to internal
      controls implemented in hardware; rarely used to refer to external
      controls.

      2. (O) "The protection afforded to an automated information system
      in order to attain the applicable objectives of preserving the
      integrity, availability and confidentiality of information system
      resources (includes hardware, software, firmware,
      information/data, and telecommunications)." [<a href="#ref-SP12" title=""An Introduction to Computer Security: The NIST Handbook"">SP12</a>]







<span class="grey">Shirey                       Informational                     [Page 74]</span>

<span id="page-75" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ computer security incident response team (CSIRT)
      (I) An organization "that coordinates and supports the response to
      security incidents that involve sites within a defined
      constituency." [<a href="#ref-R2350" title=""Expectations for Computer Security Incident Response"">R2350</a>] (See: CERT, FIRST, security incident.)

      Tutorial: To be considered a CSIRT, an organization must do as
      follows: (a) Provide a (secure) channel for receiving reports
      about suspected security incidents. (b) Provide assistance to
      members of its constituency in handling the incidents. (c)
      Disseminate incident-related information to its constituency and
      other involved parties.

   $ computer security object
      (I) The definition or representation of a resource, tool, or
      mechanism used to maintain a condition of security in computerized
      environments. Includes many items referred to in standards that
      are either selected or defined by separate user communities.
      [<a href="#ref-CSOR" title=""General Procedures for Registering Computer Security Objects"">CSOR</a>] (See: object identifier, Computer Security Objects
      Register.)

   $ Computer Security Objects Register (CSOR)
      (N) A service operated by NIST is establishing a catalog for
      computer security objects to provide stable object definitions
      identified by unique names. The use of this register will enable
      the unambiguous specification of security parameters and
      algorithms to be used in secure data exchanges. (See: object
      identifier.)

      Tutorial: The CSOR follows registration guidelines established by
      the international standards community and ANSI. Those guidelines
      establish minimum responsibilities for registration authorities
      and assign the top branches of an international registration
      hierarchy. Under that international registration hierarchy, the
      CSOR is responsible for the allocation of unique identifiers under
      the branch: {joint-iso-ccitt(2) country(16) us(840)
      organization(1) gov(101) csor(3)}.

   $ computer system
      (I) Synonym for "information system", or a component thereof.
      (Compare: computer platform.)

   $ Computers At Risk
      (O) The 1991 report [<a href="#ref-NRC91" title=""Computers At Risk: Safe Computing in the Information Age"">NRC91</a>] of the System Security Study
      Committee, sponsored by the U.S. National Academy of Sciences and
      supported by the Defense Advanced Research Projects Agency of the
      U.S. DoD. It made many recommendations for industry and
      governments to improve computer security and trustworthiness. Some
      of the most important recommendations (e.g., establishing an



<span class="grey">Shirey                       Informational                     [Page 75]</span>

<span id="page-76" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      Information Security Foundation chartered by the U.S. Government)
      have not been implemented at all, and others (e.g., codifying
      Generally Accepted System Security Principles similar to
      accounting principles) have been implemented but not widely
      adopted [<a href="#ref-SP14" title=""Generally Accepted Principles and Practices for Security Information Technology Systems"">SP14</a>, <a href="#ref-SP27" title=""Engineering Principles for Information Technology Security (A Baseline for Achieving Security)"">SP27</a>].

   $ COMSEC
      (I) See: communication security.

   $ COMSEC account
      (O) /U.S. Government/ "Administrative entity, identified by an
      account number, used to maintain accountability, custody, and
      control of COMSEC material." [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>] (See: COMSEC custodian.)

   $ COMSEC accounting
      (O) /U.S. Government/ The process of creating, collecting, and
      maintaining data records that describe the status and custody of
      designated items of COMSEC material. (See: accounting legend
      code.)

      Tutorial: Almost any secure information system needs to record a
      security audit trail, but a system that manages COMSEC material
      needs to record additional data about the status and custody of
      COMSEC items.
      -  COMSEC tracking: The process of automatically collecting,
         recording, and managing information that describes the status
         of designated items of COMSEC material at all times during each
         product's lifecycle.
      -  COMSEC controlling: The process of supplementing tracking data
         with custody data, which consists of explicit acknowledgements
         of system entities that they (a) have received specific COMSEC
         items and (b) are responsible for preventing exposure of those
         items.

      For example, a key management system that serves a large customer
      base needs to record tracking data for the same reasons that a
      national parcel delivery system does, i.e., to answer the question
      "Where is that thing now?". If keys are encrypted immediately upon
      generation and handled only in BLACK form between the point of
      generation and the point of use, then tracking may be all that is
      needed. However, in cases where keys are handled at least partly
      in RED form and are potentially subject to exposure, then tracking
      needs to be supplemented by controlling.

      Data that is used purely for tracking need be retained only
      temporarily, until an item's status changes. Data that is used for
      controlling is retained indefinitely to ensure accountability and
      support compromise recovery.



<span class="grey">Shirey                       Informational                     [Page 76]</span>

<span id="page-77" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ COMSEC boundary
      (N) "Definable perimeter encompassing all hardware, firmware, and
      software components performing critical COMSEC functions, such as
      key generation and key handling and storage." [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>] (Compare:
      cryptographic boundary.)

   $ COMSEC custodian
      (O) /U.S. Government/ "Individual designated by proper authority
      to be responsible for the receipt, transfer, accounting,
      safeguarding, and destruction of COMSEC material assigned to a
      COMSEC account." [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>]

   $ COMSEC material
      (N) /U.S. Government/ Items designed to secure or authenticate
      communications or information in general; these items include (but
      are not limited to) keys; equipment, devices, documents, firmware,
      and software that embodies or describes cryptographic logic; and
      other items that perform COMSEC functions. [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>] (Compare:
      keying material.)

   $ COMSEC Material Control System (CMCS)
      (O) /U.S. Government/ "Logistics and accounting system through
      which COMSEC material marked 'CRYPTO' is distributed, controlled,
      and safeguarded." [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>] (See: COMSEC account, COMSEC custodian.)

   $ confidentiality
      See: data confidentiality.

   $ concealment system
      (O) "A method of achieving confidentiality in which sensitive
      information is hidden by embedding it in irrelevant data." [<a href="#ref-NCS04" title=""Glossary of Computer Security Terms"">NCS04</a>]
      (Compare: steganography.)

   $ configuration control
      (I) The process of regulating changes to hardware, firmware,
      software, and documentation throughout the development and
      operational life of a system. (See: administrative security,
      harden, trusted distribution.)

      Tutorial: Configuration control helps protect against unauthorized
      or malicious alteration of a system and thus provides assurance of
      system integrity. (See: malicious logic.)

   $ confinement property
      (N) /formal model/ Property of a system whereby a subject has
      write access to an object only if the classification of the object
      dominates the clearance of the subject. (See: *-property, Bell-
      LaPadula model.)



<span class="grey">Shirey                       Informational                     [Page 77]</span>

<span id="page-78" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ constraint
      (I) /access control/ A limitation on the function of an identity,
      role, or privilege. (See: rule-based access control.)

      Tutorial: In effect, a constraint is a form of security policy and
      may be either static or dynamic:
      -  "Static constraint": A constraint that must be satisfied at the
         time the policy is defined, and then continues to be satisfied
         until the constraint is removed.
      -  "Dynamic constraint": A constraint that may be defined to apply
         at various times that the identity, role, or other object of
         the constraint is active in the system.

   $ content filter
      (I) /World Wide Web/ Application software used to prevent access
      to certain Web servers, such as by parents who do not want their
      children to access pornography. (See: filter, guard.)

      Tutorial: The filter is usually browser-based, but could be part
      of an intermediate cache server. The two basic content filtering
      techniques are (a) to block a specified list of URLs and (b) to
      block material that contains specified words and phrases.

   $ contingency plan
      (I) A plan for emergency response, backup operations, and post-
      disaster recovery in a system as part of a security program to
      ensure availability of critical system resources and facilitate
      continuity of operations in a crisis. [<a href="#ref-NCS04" title=""Glossary of Computer Security Terms"">NCS04</a>] (See: availability.)

   $ control zone
      (O) "The space, expressed in feet of radius, surrounding equipment
      processing sensitive information, that is under sufficient
      physical and technical control to preclude an unauthorized entry
      or compromise." [<a href="#ref-NCSSG" title=""COMPUSECese: Computer Security Glossary"">NCSSG</a>] (Compare: inspectable space, TEMPEST
      zone.)

   $ controlled access protection
      (O) /TCSEC/ The level of evaluation criteria for a C2 computer
      system.

      Tutorial: The major features of the C2 level are individual
      accountability, audit, access control, and object reuse.

   $ controlled cryptographic item (CCI)
      (O) /U.S. Government/ "Secure telecommunications or information
      handling equipment, or associated cryptographic component, that is
      unclassified but governed by a special set of control
      requirements." [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>] (Compare: EUCI.)



<span class="grey">Shirey                       Informational                     [Page 78]</span>

<span id="page-79" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      Tutorial: This category of equipment was established in 1985 to
      promote broad use of secure equipment for protecting both
      classified and unclassified information in the national interest.
      CCI equipment uses a classified cryptographic logic, but the
      hardware or firmware embodiment of that logic is unclassified.
      Drawings, software implementations, and other descriptions of that
      logic remain classified. [<a href="#ref-N4001" title=""Controlled Cryptographic Items"">N4001</a>]

   $ controlled interface
      (I) A mechanism that facilitates the adjudication of the different
      security policies of interconnected systems. (See: domain, guard.)

   $ controlled security mode
      (D) /U.S. DoD/ A mode of system operation wherein (a) two or more
      security levels of information are allowed to be handled
      concurrently within the same system when some users having access
      to the system have neither a security clearance nor need-to-know
      for some of the data handled by the system, but (b) separation of
      the users and the classified material on the basis, respectively,
      of clearance and classification level are not dependent only on
      operating system control (like they are in multilevel security
      mode). (See: /system operation/ under "mode", protection level.)

      Deprecated Term: IDOCs SHOULD NOT use this term. It was defined in
      a U.S. Government policy regarding system accreditation and was
      subsumed by "partitioned security mode" in a later policy. Both
      terms were dropped in still later policies.

      Tutorial: Controlled mode was intended to encourage ingenuity in
      meeting data confidentiality requirements in ways less restrictive
      than "dedicated security mode" and "system-high security mode",
      but at a level of risk lower than that generally associated with
      true "multilevel security mode". This was intended to be
      accomplished by implementation of explicit augmenting measures to
      reduce or remove a substantial measure of system software
      vulnerability together with specific limitation of the security
      clearance levels of users having concurrent access to the system.

   $ controlling authority
      (O) /U.S. Government/ "Official responsible for directing the
      operation of a cryptonet and for managing the operational use and
      control of keying material assigned to the cryptonet." [C4009,
      N4006]

   $ cookie
      1. (I) /HTTP/ Data exchanged between an HTTP server and a browser
      (a client of the server) to store state information on the client
      side and retrieve it later for server use.



<span class="grey">Shirey                       Informational                     [Page 79]</span>

<span id="page-80" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      Tutorial: An HTTP server, when sending data to a client, may send
      along a cookie, which the client retains after the HTTP connection
      closes. A server can use this mechanism to maintain persistent
      client-side state information for HTTP-based applications,
      retrieving the state information in later connections. A cookie
      may include a description of the range of URLs for which the state
      is valid. Future requests made by the client in that range will
      also send the current value of the cookie to the server. Cookies
      can be used to generate profiles of web usage habits, and thus may
      infringe on personal privacy.

      2. (I) /IPsec/ Data objects exchanged by ISAKMP to prevent certain
      denial-of-service attacks during the establishment of a security
      association.

      3. (D) /access control/ Synonym for "capability token" or
      "ticket".

      Deprecated Definition: IDOCs SHOULD NOT use this term with
      definition 3; that would duplicate the meaning of better-
      established terms and mix concepts in a potentially misleading
      way.

   $ Coordinated Universal Time (UTC)
      (N) UTC is derived from International Atomic Time (TAI) by adding
      a number of leap seconds. The International Bureau of Weights and
      Measures computes TAI once each month by averaging data from many
      laboratories. (See: GeneralizedTime, UTCTime.)

   $ correction
      (I) /security/ A system change made to eliminate or reduce the
      risk of reoccurrence of a security violation or threat
      consequence. (See: secondary definition under "security".)

   $ correctness
      (I) "The property of a system that is guaranteed as the result of
      formal verification activities." [<a href="#ref-Huff" title=""Trusted Computer Systems -- Glossary"">Huff</a>] (See: correctness proof,
      verification.)

   $ correctness integrity
      (I) The property that the information represented by data is
      accurate and consistent. (Compare: data integrity, source
      integrity.)

      Tutorial: IDOCs SHOULD NOT use this term without providing a
      definition; the term is neither well-known nor precisely defined.
      Data integrity refers to the constancy of data values, and source
      integrity refers to confidence in data values. However,



<span class="grey">Shirey                       Informational                     [Page 80]</span>

<span id="page-81" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      correctness integrity refers to confidence in the underlying
      information that data values represent, and this property is
      closely related to issues of accountability and error handling.

   $ correctness proof
      (I) A mathematical proof of consistency between a specification
      for system security and the implementation of that specification.
      (See: correctness, formal specification.)

   $ corruption
      (I) A type of threat action that undesirably alters system
      operation by adversely modifying system functions or data. (See:
      disruption.)

      Usage: This type of threat action includes the following subtypes:
      -  "Tampering": /corruption/ Deliberately altering a system's
         logic, data, or control information to interrupt or prevent
         correct operation of system functions. (See: misuse, main entry
         for "tampering".)
      -  "Malicious logic": /corruption/ Any hardware, firmware, or
         software (e.g., a computer virus) intentionally introduced into
         a system to modify system functions or data. (See:
         incapacitation, main entry for "malicious logic", masquerade,
         misuse.)
      -  "Human error": /corruption/ Human action or inaction that
         unintentionally results in the alteration of system functions
         or data.
      -  "Hardware or software error": /corruption/ Error that results
         in the alteration of system functions or data.
      -  "Natural disaster": /corruption/ Any "act of God" (e.g., power
         surge caused by lightning) that alters system functions or
         data. [FP031 <a href="#section-2">Section 2</a>]

   $ counter
      1. (N) /noun/ See: counter mode.

      2. (I) /verb/ See: countermeasure.

   $ counter-countermeasure
      (I) An action, device, procedure, or technique used by an attacker
      to offset a defensive countermeasure.

      Tutorial: For every countermeasure devised to protect computers
      and networks, some cracker probably will be able to devise a
      counter-countermeasure. Thus, systems must use "defense in depth".






<span class="grey">Shirey                       Informational                     [Page 81]</span>

<span id="page-82" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ counter mode (CTR)
      (N) A block cipher mode that enhances ECB mode by ensuring that
      each encrypted block is different from every other block encrypted
      under the same key. [<a href="#ref-SP38A" title=""Recommendation for Block Cipher Modes of Operation: Methods and Techniques"">SP38A</a>] (See: block cipher.)

      Tutorial: This mode operates by first encrypting a generated
      sequence of blocks, called "counters", that are separate from the
      input sequence of plaintext blocks which the mode is intended to
      protect. The resulting sequence of encrypted counters is
      exclusive-ORed with the sequence of plaintext blocks to produce
      the final ciphertext output blocks. The sequence of counters must
      have the property that each counter is different from every other
      counter for all of the plain text that is encrypted under the same
      key.

   $ Counter with Cipher Block Chaining-Message Authentication Code
      (CCM)
      (N) A block cipher mode [<a href="#ref-SP38C" title=""Recommendation for Block Cipher Modes of Operation: The CCM Mode for Authentication and Confidentiality"">SP38C</a>] that provides both data
      confidentiality and data origin authentication, by combining the
      techniques of CTR and a CBC-based message authentication code.
      (See: block cipher.)

   $ countermeasure
      (I) An action, device, procedure, or technique that meets or
      opposes (i.e., counters) a threat, a vulnerability, or an attack
      by eliminating or preventing it, by minimizing the harm it can
      cause, or by discovering and reporting it so that corrective
      action can be taken.

      Tutorial: In an Internet protocol, a countermeasure may take the
      form of a protocol feature, a component function, or a usage
      constraint.

   $ country code
      (I) An identifier that is defined for a nation by ISO. [<a href="#ref-I3166" title=""Codes for the Representation of Names of Countries and Their Subdivisions, Part 1: Country Codes"">I3166</a>]

      Tutorial: For each nation, ISO Standard 3166 defines a unique two-
      character alphabetic code, a unique three-character alphabetic
      code, and a three-digit code. Among many uses of these codes, the
      two-character codes are used as top-level domain names.

   $ Courtney's laws
      (N) Principles for managing system security that were stated by
      Robert H. Courtney, Jr.







<span class="grey">Shirey                       Informational                     [Page 82]</span>

<span id="page-83" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      Tutorial: Bill Murray codified Courtney's laws as follows: [<a href="#ref-Murr" title=""Courtney's Laws of Security"">Murr</a>]
      -  Courtney's first law: You cannot say anything interesting
         (i.e., significant) about the security of a system except in
         the context of a particular application and environment.
      -  Courtney's second law: Never spend more money eliminating a
         security exposure than tolerating it will cost you. (See:
         acceptable risk, risk analysis.)
         -- First corollary: Perfect security has infinite cost.
         -- Second corollary: There is no such thing as zero risk.
      -  Courtney's third law: There are no technical solutions to
         management problems, but there are management solutions to
         technical problems.

   $ covert action
      (I) An operation that is planned and executed in a way that
      conceals the identity of the operator.

   $ covert channel
      1. (I) An unintended or unauthorized intra-system channel that
      enables two cooperating entities to transfer information in a way
      that violates the system's security policy but does not exceed the
      entities' access authorizations. (See: covert storage channel,
      covert timing channel, out-of-band, tunnel.)

      2. (O) "A communications channel that allows two cooperating
      processes to transfer information in a manner that violates the
      system's security policy." [<a href="#ref-NCS04" title=""Glossary of Computer Security Terms"">NCS04</a>]

      Tutorial: The cooperating entities can be either two insiders or
      an insider and an outsider. Of course, an outsider has no access
      authorization at all. A covert channel is a system feature that
      the system architects neither designed nor intended for
      information transfer.

   $ covert storage channel
      (I) A system feature that enables one system entity to signal
      information to another entity by directly or indirectly writing a
      storage location that is later directly or indirectly read by the
      second entity. (See: covert channel.)

   $ covert timing channel
      (I) A system feature that enables one system entity to signal
      information to another by modulating its own use of a system
      resource in such a way as to affect system response time observed
      by the second entity. (See: covert channel.)

   $ CPS
      (I) See: certification practice statement.



<span class="grey">Shirey                       Informational                     [Page 83]</span>

<span id="page-84" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ cracker
      (I) Someone who tries to break the security of, and gain
      unauthorized access to, someone else's system, often with
      malicious intent. (See: adversary, intruder, packet monkey, script
      kiddy. Compare: hacker.)

      Usage: Was sometimes spelled "kracker". [<a href="#ref-NCSSG" title=""COMPUSECese: Computer Security Glossary"">NCSSG</a>]

   $ CRAM
      (I) See: Challenge-Response Authentication Mechanism.

   $ CRC
      (I) See: cyclic redundancy check.

   $ credential
      1. (I) /authentication/ "identifier credential": A data object
      that is a portable representation of the association between an
      identifier and a unit of authentication information, and that can
      be presented for use in verifying an identity claimed by an entity
      that attempts to access a system. Example: X.509 public-key
      certificate. (See: anonymous credential.)

      2. (I) /access control/ "authorization credential": A data object
      that is a portable representation of the association between an
      identifier and one or more access authorizations, and that can be
      presented for use in verifying those authorizations for an entity
      that attempts such access. Example: X.509 attribute certificate.
      (See: capability token, ticket.)

      3. (D) /OSIRM/ "Data that is transferred to establish the claimed
      identity of an entity." [<a href="#ref-I7498-2" title=""Information Processing Systems -- Open Systems Interconnection Reference Model, Part 2: Security Architecture"">I7498-2</a>]

      Deprecated Definition: IDOCs SHOULD NOT use the term with
      definition 3. As explained in the tutorial below, an
      authentication process can involve the transfer of multiple data
      objects, and not all of those are credentials.

      4. (D) /U.S. Government/ "An object that is verified when
      presented to the verifier in an authentication transaction."
      [<a href="#ref-M0404" title=""E-Authentication Guidance for Federal Agencies"">M0404</a>]

      Deprecated Definition: IDOCs SHOULD NOT use the term with
      definition 4; it mixes concepts in a potentially misleading way.
      For example, in an authentication process, it is the identity that
      is "verified", not the credential; the credential is "validated".
      (See: validate vs. verify.)





<span class="grey">Shirey                       Informational                     [Page 84]</span>

<span id="page-85" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      Tutorial: In general English, "credentials" are evidence or
      testimonials that (a) support a claim of identity or authorization
      and (b) usually are intended to be used more than once (i.e., a
      credential's life is long compared to the time needed for one
      use). Some examples are a policeman's badge, an automobile
      driver's license, and a national passport. An authentication or
      access control process that uses a badge, license, or passport is
      outwardly simple: the holder just shows the thing.

      The problem with adopting this term in Internet security is that
      an automated process for authentication or access control usually
      requires multiple steps using multiple data objects, and it might
      not be immediately obvious which of those objects should get the
      name "credential".

      For example, if the verification step in a user authentication
      process employs public-key technology, then the process involves
      at least three data items: (a) the user's private key, (b) a
      signed value -- signed with that private key and passed to the
      system, perhaps in response to a challenge from the system -- and
      (c) the user's public-key certificate, which is validated by the
      system and provides the public key needed to verify the signature.
      -  Private key: The private key is *not* a credential, because it
         is never transferred or presented. Instead, the private key is
         "authentication information", which is associated with the
         user's identifier for a specified period of time and can be
         used in multiple authentications during that time.
      -  Signed value: The signed value is *not* a credential; the
         signed value is only ephemeral, not long lasting. The OSIRM
         definition could be interpreted to call the signed value a
         credential, but that would conflict with general English.
      -  Certificate: The user's certificate *is* a credential. It can
         be "transferred" or "presented" to any person or process that
         needs it at any time. A public-key certificate may be used as
         an "identity credential", and an attribute certificate may be
         used as an "authorization credential".

   $ critical
      1. (I) /system resource/ A condition of a system resource such
      that denial of access to, or lack of availability of, that
      resource would jeopardize a system user's ability to perform a
      primary function or would result in other serious consequences,
      such as human injury or loss of life. (See: availability,
      precedence. Compare: sensitive.)

      2. (N) /extension/ An indication that an application is not
      permitted to ignore an extension. [<a href="#ref-X509" title=""Information Technology -- Open Systems Interconnection -- The Directory: Authentication Framework"">X509</a>]




<span class="grey">Shirey                       Informational                     [Page 85]</span>

<span id="page-86" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      Tutorial: Each extension of an X.509 certificate or CRL is flagged
      as either "critical" or "non-critical". In a certificate, if a
      computer program does not recognize an extension's type (i.e.,
      does not implement its semantics), then if the extension is
      critical, the program is required to treat the certificate as
      invalid; but if the extension is non-critical, the program is
      permitted to ignore the extension.

      In a CRL, if a program does not recognize a critical extension
      that is associated with a specific certificate, the program is
      required to assume that the listed certificate has been revoked
      and is no longer valid, and then take whatever action is required
      by local policy.

      When a program does not recognize a critical extension that is
      associated with the CRL as a whole, the program is required to
      assume that all listed certificates have been revoked and are no
      longer valid. However, since failing to process the extension may
      mean that the list has not been completed, the program cannot
      assume that other certificates are valid, and the program needs to
      take whatever action is therefore required by local policy.

   $ critical information infrastructure
      (I) Those systems that are so vital to a nation that their
      incapacity or destruction would have a debilitating effect on
      national security, the economy, or public health and safety.

   $ CRL
      (I) See: certificate revocation list.

   $ CRL distribution point
      (I) See: distribution point.

   $ CRL extension
      (I) See: extension.

   $ cross-certificate
      (I) A public-key certificate issued by a CA in one PKI to a CA in
      another PKI. (See: cross-certification.)

   $ cross-certification
      (I) The act or process by which a CA in one PKI issues a public-
      key certificate to a CA in another PKI. [<a href="#ref-X509" title=""Information Technology -- Open Systems Interconnection -- The Directory: Authentication Framework"">X509</a>] (See: bridge CA.)

      Tutorial: X.509 says that a CA (say, CA1) may issue a "cross-
      certificate" in which the subject is another CA (say, CA2). X.509
      calls CA2 the "subject CA" and calls CA1 an "intermediate CA", but




<span class="grey">Shirey                       Informational                     [Page 86]</span>

<span id="page-87" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      this Glossary deprecates those terms. (See: intermediate CA,
      subject CA).

      Cross-certification of CA2 by CA1 appears similar to certification
      of a subordinate CA by a superior CA, but cross-certification
      involves a different concept. The "subordinate CA" concept applies
      when both CAs are in the same PKI, i.e., when either (a) CA1 and
      CA2 are under the same root or (b) CA1 is itself a root. The
      "cross-certification" concept applies in other cases:

      First, cross-certification applies when two CAs are in different
      PKIs, i.e., when CA1 and CA2 are under different roots, or perhaps
      are both roots themselves. Issuing the cross-certificate enables
      end entities certified under CA1 in PK1 to construct the
      certification paths needed to validate the certificates of end
      entities certified under CA2 in PKI2. Sometimes, a pair of cross-
      certificates is issued -- by CA1 to CA2, and by CA2 to CA1 -- so
      that an end entity in either PKI can validate certificates issued
      in the other PKI.

      Second, X.509 says that two CAs in some complex, multi-CA PKI can
      cross-certify one another to shorten the certification paths
      constructed by end entities. Whether or not a CA may perform this
      or any other form of cross-certification, and how such
      certificates may be used by end entities, should be addressed by
      the local certificate policy and CPS.

   $ cross-domain solution
      1. (D) Synonym for "guard".

      Deprecated Term: IDOCs SHOULD NOT use this term as a synonym for
      "guard"; this term unnecessarily (and verbosely) duplicates the
      meaning of the long-established "guard".

      2. (O) /U.S. Government/ A process or subsystem that provides a
      capability (which could be either manual or automated) to access
      two or more differing security domains in a system, or to transfer
      information between such domains. (See: domain, guard.)

   $ cryptanalysis
      1. (I) The mathematical science that deals with analysis of a
      cryptographic system to gain knowledge needed to break or
      circumvent the protection that the system is designed to provide.
      (See: cryptology, secondary definition under "intrusion".)

      2. (O) "The analysis of a cryptographic system and/or its inputs
      and outputs to derive confidential variables and/or sensitive data
      including cleartext." [<a href="#ref-I7498-2" title=""Information Processing Systems -- Open Systems Interconnection Reference Model, Part 2: Security Architecture"">I7498-2</a>]



<span class="grey">Shirey                       Informational                     [Page 87]</span>

<span id="page-88" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      Tutorial: Definition 2 states the traditional goal of
      cryptanalysis, i.e., convert cipher text to plain text (which
      usually is clear text) without knowing the key; but that
      definition applies only to encryption systems. Today, the term is
      used with reference to all kinds of cryptographic algorithms and
      key management, and definition 1 reflects that. In all cases,
      however, a cryptanalyst tries to uncover or reproduce someone
      else's sensitive data, such as clear text, a key, or an algorithm.
      The basic cryptanalytic attacks on encryption systems are
      ciphertext-only, known-plaintext, chosen-plaintext, and chosen-
      ciphertext; and these generalize to the other kinds of
      cryptography.

   $ crypto, CRYPTO
      1. (N) A prefix ("crypto-") that means "cryptographic".

      Usage: IDOCs MAY use this prefix when it is part of a term listed
      in this Glossary. Otherwise, IDOCs SHOULD NOT use this prefix;
      instead, use the unabbreviated adjective, "cryptographic".

      2. (D) In lower case, "crypto" is an abbreviation for the
      adjective "cryptographic", or for the nouns "cryptography" or
      "cryptographic component".

      Deprecated Abbreviation: IDOCs SHOULD NOT use this abbreviation
      because it could easily be misunderstood in some technical sense.

      3. (O) /U.S. Government/ In upper case, "CRYPTO" is a marking or
      designator that identifies "COMSEC keying material used to secure
      or authenticate telecommunications carrying classified or
      sensitive U.S. Government or U.S. Government-derived information."
      [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>] (See: security label, security marking.)

   $ cryptographic
      (I) An adjective that refers to cryptography.

   $ cryptographic algorithm
      (I) An algorithm that uses the science of cryptography, including
      (a) encryption algorithms, (b) cryptographic hash algorithms, (c)
      digital signature algorithms, and (d) key-agreement algorithms.

   $ cryptographic application programming interface (CAPI)
      (I) The source code formats and procedures through which an
      application program accesses cryptographic services, which are
      defined abstractly compared to their actual implementation.
      Example, see: PKCS #11, [<a href="#ref-R2628" title=""Simple Cryptographic Program Interface (Crypto API)"">R2628</a>].





<span class="grey">Shirey                       Informational                     [Page 88]</span>

<span id="page-89" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ cryptographic association
      (I) A security association that involves the use of cryptography
      to provide security services for data exchanged by the associated
      entities. (See: ISAKMP.)

   $ cryptographic boundary
      (I) See: secondary definition under "cryptographic module".

   $ cryptographic card
      (I) A cryptographic token in the form of a smart card or a PC
      card.

   $ cryptographic component
      (I) A generic term for any system component that involves
      cryptography. (See: cryptographic module.)

   $ cryptographic hash
      (I) See: secondary definition under "hash function".

   $ cryptographic ignition key (CIK)
      1. (N) A physical (usually electronic) token used to store,
      transport, and protect cryptographic keys and activation data.
      (Compare: dongle, fill device.)

      Tutorial: A key-encrypting key could be divided (see: split key)
      between a CIK and a cryptographic module, so that it would be
      necessary to combine the two to regenerate the key, use it to
      decrypt other keys and data contained in the module, and thus
      activate the module.

      2. (O) "Device or electronic key used to unlock the secure mode of
      cryptographic equipment." [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>] Usage: Abbreviated as "crypto-
      ignition key".

   $ cryptographic key
      (I) See: key. Usage: Usually shortened to just "key".

   $ Cryptographic Message Syntax (CMS)
      (I) An encapsulation syntax (<a href="./rfc3852">RFC 3852</a>) for digital signatures,
      hashes, and encryption of arbitrary messages.

      Tutorial: CMS derives from PKCS #7. CMS values are specified with
      ASN.1 and use BER encoding. The syntax permits multiple
      encapsulation with nesting, permits arbitrary attributes to be
      signed along with message content, and supports a variety of
      architectures for digital certificate-based key management.





<span class="grey">Shirey                       Informational                     [Page 89]</span>

<span id="page-90" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ cryptographic module
      (I) A set of hardware, software, firmware, or some combination
      thereof that implements cryptographic logic or processes,
      including cryptographic algorithms, and is contained within the
      module's "cryptographic boundary", which is an explicitly defined
      contiguous perimeter that establishes the physical bounds of the
      module. [<a href="#ref-FP140" title=""Security Requirements for Cryptographic Modules"">FP140</a>]

   $ cryptographic system
      1. (I) A set of cryptographic algorithms together with the key
      management processes that support use of the algorithms in some
      application context.

      Usage: IDOCs SHOULD use definition 1 because it covers a wider
      range of algorithms than definition 2.

      2. (O) "A collection of transformations from plain text into
      cipher text and vice versa [which would exclude digital signature,
      cryptographic hash, and key-agreement algorithms], the particular
      transformation(s) to be used being selected by keys. The
      transformations are normally defined by a mathematical algorithm."
      [<a href="#ref-X509" title=""Information Technology -- Open Systems Interconnection -- The Directory: Authentication Framework"">X509</a>]

   $ cryptographic token
      1. (I) A portable, user-controlled, physical device (e.g., smart
      card or PCMCIA card) used to store cryptographic information and
      possibly also perform cryptographic functions. (See: cryptographic
      card, token.)

      Tutorial: A smart token might implement some set of cryptographic
      algorithms and might incorporate related key management functions,
      such as a random number generator. A smart cryptographic token may
      contain a cryptographic module or may not be explicitly designed
      that way.

   $ cryptography
      1. (I) The mathematical science that deals with transforming data
      to render its meaning unintelligible (i.e., to hide its semantic
      content), prevent its undetected alteration, or prevent its
      unauthorized use. If the transformation is reversible,
      cryptography also deals with restoring encrypted data to
      intelligible form. (See: cryptology, steganography.)

      2. (O) "The discipline which embodies principles, means, and
      methods for the transformation of data in order to hide its
      information content, prevent its undetected modification and/or
      prevent its unauthorized use.... Cryptography determines the
      methods used in encipherment and decipherment." [<a href="#ref-I7498-2" title=""Information Processing Systems -- Open Systems Interconnection Reference Model, Part 2: Security Architecture"">I7498-2</a>]



<span class="grey">Shirey                       Informational                     [Page 90]</span>

<span id="page-91" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      Tutorial: Comprehensive coverage of applied cryptographic
      protocols and algorithms is provided by Schneier [<a href="#ref-Schn" title=""Applied Cryptography Second Edition"">Schn</a>].
      Businesses and governments use cryptography to make data
      incomprehensible to outsiders; to make data incomprehensible to
      both outsiders and insiders, the data is sent to lawyers for a
      rewrite.

   $ Cryptoki
      (N) A CAPI defined in PKCS #11. Pronunciation: "CRYPTO-key".
      Derivation: Abbreviation of "cryptographic token interface".

   $ cryptology
      (I) The science of secret communication, which includes both
      cryptography and cryptanalysis.

      Tutorial: Sometimes the term is used more broadly to denote
      activity that includes both rendering signals secure (see: signal
      security) and extracting information from signals (see: signal
      intelligence) [<a href="#ref-Kahn" title=""The Codebreakers: The Story of Secret Writing"">Kahn</a>].

   $ cryptonet
      (I) A network (i.e., a communicating set) of system entities that
      share a secret cryptographic key for a symmetric algorithm. (See:
      controlling authority.)

      (O) "Stations holding a common key." [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>]

   $ cryptoperiod
      (I) The time span during which a particular key value is
      authorized to be used in a cryptographic system. (See: key
      management.)

      Usage: This term is long-established in COMPUSEC usage. In the
      context of certificates and public keys, "key lifetime" and
      "validity period" are often used instead.

      Tutorial: A cryptoperiod is usually stated in terms of calendar or
      clock time, but sometimes is stated in terms of the maximum amount
      of data permitted to be processed by a cryptographic algorithm
      using the key. Specifying a cryptoperiod involves a tradeoff
      between the cost of rekeying and the risk of successful
      cryptoanalysis.

   $ cryptosystem
      (I) Contraction of "cryptographic system".

   $ cryptovariable
      (D) Synonym for "key".



<span class="grey">Shirey                       Informational                     [Page 91]</span>

<span id="page-92" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      Deprecated Usage: In contemporary COMSEC usage, the term "key" has
      replaced the term "cryptovariable".

   $ CSIRT
      (I) See: computer security incident response team.

   $ CSOR
      (N) See: Computer Security Objects Register.

   $ CTAK
      (D) See: ciphertext auto-key.

   $ CTR
      (N) See: counter mode.

   $ cut-and-paste attack
      (I) An active attack on the data integrity of cipher text,
      effected by replacing sections of cipher text with other cipher
      text, such that the result appears to decrypt correctly but
      actually decrypts to plain text that is forged to the satisfaction
      of the attacker.

   $ cyclic redundancy check (CRC)
      (I) A type of checksum algorithm that is not a cryptographic hash
      but is used to implement data integrity service where accidental
      changes to data are expected. Sometimes called "cyclic redundancy
      code".

   $ DAC
      (N) See: Data Authentication Code, discretionary access control.

      Deprecated Usage: IDOCs that use this term SHOULD state a
      definition for it because this abbreviation is ambiguous.

   $ daemon
      (I) A computer program that is not invoked explicitly but waits
      until a specified condition occurs, and then runs with no
      associated user (principal), usually for an administrative
      purpose. (See: zombie.)

   $ dangling threat
      (O) A threat to a system for which there is no corresponding
      vulnerability and, therefore, no implied risk.

   $ dangling vulnerability
      (O) A vulnerability of a system for which there is no
      corresponding threat and, therefore, no implied risk.




<span class="grey">Shirey                       Informational                     [Page 92]</span>

<span id="page-93" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ DASS
      (I) See: Distributed Authentication Security Service.

   $ data
      (I) Information in a specific representation, usually as a
      sequence of symbols that have meaning.

      Usage: Refers to both (a) representations that can be recognized,
      processed, or produced by a computer or other type of machine, and
      (b) representations that can be handled by a human.

   $ Data Authentication Algorithm, data authentication algorithm
      1. (N) /capitalized/ The ANSI standard for a keyed hash function
      that is equivalent to DES cipher block chaining with IV = 0.
      [<a href="#ref-A9009" title=""Financial Institution Message Authentication (Wholesale)"">A9009</a>]

      2. (D) /not capitalized/ Synonym for some kind of "checksum".

      Deprecated Term: IDOCs SHOULD NOT use the uncapitalized form "data
      authentication algorithm" as a synonym for any kind of checksum,
      regardless of whether or not the checksum is based on a hash.
      Instead, use "checksum", "Data Authentication Code", "error
      detection code", "hash", "keyed hash", "Message Authentication
      Code", "protected checksum", or some other specific term,
      depending on what is meant.

      The uncapitalized term can be confused with the Data
      Authentication Code and also mixes concepts in a potentially
      misleading way. The word "authentication" is misleading because
      the checksum may be used to perform a data integrity function
      rather than a data origin authentication function.

   $ Data Authentication Code, data authentication code
      1. (N) /capitalized/ A specific U.S. Government standard [<a href="#ref-FP113" title=""Computer Data Authentication"">FP113</a>]
      for a checksum that is computed by the Data Authentication
      Algorithm. Usage: a.k.a. Message Authentication Code [<a href="#ref-A9009" title=""Financial Institution Message Authentication (Wholesale)"">A9009</a>].)
      (See: DAC.)

      2. (D) /not capitalized/ Synonym for some kind of "checksum".

      Deprecated Term: IDOCs SHOULD NOT use the uncapitalized form "data
      authentication code" as a synonym for any kind of checksum,
      regardless of whether or not the checksum is based on the Data
      Authentication Algorithm. The uncapitalized term can be confused
      with the Data Authentication Code and also mixes concepts in a
      potentially misleading way (see: authentication code).





<span class="grey">Shirey                       Informational                     [Page 93]</span>

<span id="page-94" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ data compromise
      1. (I) A security incident in which information is exposed to
      potential unauthorized access, such that unauthorized disclosure,
      alteration, or use of the information might have occurred.
      (Compare: security compromise, security incident.)

      2. (O) /U.S. DoD/ A "compromise" is a "communication or physical
      transfer of information to an unauthorized recipient." [<a href="#ref-DoD5" title=""DoD Information Security Program"">DoD5</a>]

      3. (O) /U.S. Government/ "Type of [security] incident where
      information is disclosed to unauthorized individuals or a
      violation of the security policy of a system in which unauthorized
      intentional or unintentional disclosure, modification,
      destruction, or loss of an object may have occurred." [<a href="#ref-C4009" title=""National Information Assurance (IA) Glossary"">C4009</a>]

   $ data confidentiality
      1. (I) The property that data is not disclosed to system entities
      unless they have been authorized to know the data. (See: Bell-
      LaPadula model, classification, data confidentiality service,
      secret. Compare: privacy.)

      2. (D) "The property that information is not made available or
      disclosed to unauthorized individuals, entities, or processes
      [i.e., to any unauthorized system entity]." [<a href="#ref-I7498-2" title=""Information Processing Systems -- Open Systems Interconnection Reference Model, Part 2: Security Architecture"">I7498-2</a>].

      Deprecated Definition: The phrase "made available" might be
      interpreted to mean that the data could be altered, and that would
      confuse this term with the concept of "data integrity".

   $ data confidentiality service
      (I) A security service that protects data against unauthorized
      disclosure. (See: access control, data confidentiality, datagram
      confidentiality service, flow control, inference control.)

      Deprecated Usage: IDOCs SHOULD NOT use this term as a synonym for
      "privacy", which is a different concept.

   $ Data Encryption Algorithm (DEA)
      (N) A symmetric block cipher, defined in the U.S. Government's
      DES. DEA uses a 64-bit key, of which 56 bits are independently
      chosen and 8 are parity bits, and maps a 64-bit block into another
      64-bit block. [<a href="#ref-FP046" title=""Data Encryption Standard (DES)"">FP046</a>] (See: AES, symmetric cryptography.)

      Usage: This algorithm is usually referred to as "DES". The
      algorithm has also been adopted in standards outside the
      Government (e.g., [<a href="#ref-A3092" title=""American National Standard Data Encryption Algorithm"">A3092</a>]).





<span class="grey">Shirey                       Informational                     [Page 94]</span>

<span id="page-95" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ data encryption key (DEK)
      (I) A cryptographic key that is used to encipher application data.
      (Compare: key-encrypting key.)

   $ Data Encryption Standard (DES)
      (N) A U.S. Government standard [<a href="#ref-FP046" title=""Data Encryption Standard (DES)"">FP046</a>] that specifies the DEA and
      states policy for using the algorithm to protect unclassified,
      sensitive data. (See: AES.)

   $ data integrity
      1. (I) The property that data has not been changed, destroyed, or
      lost in an unauthorized or accidental manner. (See: data integrity
      service. Compare: correctness integrity, source integrity.)

      2. (O) "The property that information has not been modified or
      destroyed in an unauthorized manner." [<a href="#ref-I7498-2" title=""Information Processing Systems -- Open Systems Interconnection Reference Model, Part 2: Security Architecture"">I7498-2</a>]

      Usage: Deals with (a) constancy of and confidence in data values,
      and not with either (b) information that the values represent
      (see: correctness integrity) or (c) the trustworthiness of the
      source of the values (see: source integrity).

   $ data integrity service
      (I) A security service that protects against unauthorized changes
      to data, including both intentional change or destruction and
      accidental change or loss, by ensuring that changes to data are
      detectable. (See: data integrity, checksum, datagram integrity
      service.)

      Tutorial: A data integrity service can only detect a change and
      report it to an appropriate system entity; changes cannot be
      prevented unless the system is perfect (error-free) and no
      malicious user has access. However, a system that offers data
      integrity service might also attempt to correct and recover from
      changes.

      The ability of this service to detect changes is limited by the
      technology of the mechanisms used to implement the service. For
      example, if the mechanism were a one-bit parity check across each
      entire SDU, then changes to an odd number of bits in an SDU would
      be detected, but changes to an even number of bits would not.

      Relationship between data integrity service and authentication
      services: Although data integrity service is defined separately
      from data origin authentication service and peer entity
      authentication service, it is closely related to them.
      Authentication services depend, by definition, on companion data
      integrity services. Data origin authentication service provides



<span class="grey">Shirey                       Informational                     [Page 95]</span>

<span id="page-96" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      verification that the identity of the original source of a
      received data unit is as claimed; there can be no such
      verification if the data unit has been altered. Peer entity
      authentication service provides verification that the identity of
      a peer entity in a current association is as claimed; there can be
      no such verification if the claimed identity has been altered.

   $ data origin authentication
      (I) "The corroboration that the source of data received is as
      claimed." [<a href="#ref-I7498-2" title=""Information Processing Systems -- Open Systems Interconnection Reference Model, Part 2: Security Architecture"">I7498-2</a>] (See: authentication.)

   $ data origin authentication service
      (I) A security service that verifies the identity of a system
      entity that is claimed to be the original source of received data.
      (See: authentication, authentication service.)

      Tutorial: This service is provided to any system entity that
      receives or holds the data. Unlike peer entity authentication
      service, this service is independent of any association between
      the originator and the recipient, and the data in question may
      have originated at any time in the past.

      A digital signature mechanism can be used to provide this service,
      because someone who does not know the private key cannot forge the
      correct signature. However, by using the signer's public key,
      anyone can verify the origin of correctly signed data.

      This service is usually bundled with connectionless data integrity
      service. (See: "relationship between data integrity service and
      authentication services" under "data integrity service".

   $ data owner
      (N) The organization that has the final statutory and operational
      authority for specified information.

   $ data privacy
      (D) Synonym for "data confidentiality".

      Deprecated Term: IDOCs SHOULD NOT use this term; it mixes concepts
      in a potentially misleading way. Instead, use either "data
      confidentiality" or "privacy" or both, depending on what is meant.

   $ data recovery
      1. (I) /cryptanalysis/ A process for learning, from some cipher
      text, the plain text that was previously encrypted to produce the
      cipher text. (See: recovery.)





<span class="grey">Shirey                       Informational                     [Page 96]</span>

<span id="page-97" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      2. (I) /system integrity/ The process of restoring information
      following damage or destruction.

   $ data security
      (I) The protection of data from disclosure, alteration,
      destruction, or loss that either is accidental or is intentional
      but unauthorized.

      Tutorial: Both data confidentiality service and data integrity
      service are needed to achieve data security.

   $ datagram
      (I) "A self-contained, independent entity of data [i.e., a packet]
      carrying sufficient information to be routed from the source
      [computer] to the destination computer without reliance on earlier
      exchanges between this source and destination computer and the
      transporting network." [<a href="#ref-R1983" title=""Internet Users' Glossary"">R1983</a>] Example: A PDU of IP.

   $ datagram confidentiality service
      (I) A data confidentiality service that preserves the
      confidentiality of data in a single, independent, packet; i.e.,
      the service applies to datagrams one-at-a-time. Example: ESP.
      (See: data confidentiality.)

      Usage: When a protocol is said to provide data confidentiality
      service, this is usually understood to mean that only the SDU is
      protected in each packet. IDOCs that use the term to mean that the
      entire PDU is protected should include a highlighted definition.

      Tutorial: This basic form of network confidentiality service
      suffices for protecting the data in a stream of packets in both
      connectionless and connection-oriented protocols. Except perhaps
      for traffic flow confidentiality, nothing further is needed to
      protect the confidentiality of data carried by a packet stream.
      The OSIRM distinguishes between connection confidentiality and
      connectionless confidentiality. The IPS need not make that
      distinction, because those services are just instances of the same
      service (i.e., datagram confidentiality) being offered in two
      different protocol contexts. (For data integrity service, however,
      additional effort is needed to protect a stream, and the IPS does
      need to distinguish between "datagram integrity service" and
      "stream integrity service".)

   $ datagram integrity service
      (I) A data integrity service that preserves the integrity of data
      in a single, independent, packet; i.e., the service applies to
      datagrams one-at-a-time. (See: data integrity. Compare: stream
      integrity service.)



<span class="grey">Shirey                       Informational                     [Page 97]</span>

<span id="page-98" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      Tutorial: The ability to provide appropriate data integrity is
      important in many Internet security situations, and so there are
      different kinds of data integrity services suited to different
      applications. This service is the simplest kind; it is suitable
      for connectionless data transfers.

      Datagram integrity service usually is designed only to attempt to
      detect changes to the SDU in each packet, but it might also
      attempt to detect changes to some or all of the PCI in each packet
      (see: selective field integrity). In contrast to this simple,
      one-at-a-time service, some security situations demand a more
      complex service that also attempts to detect deleted, inserted, or
      reordered datagrams within a stream of datagrams (see: stream
      integrity service).

   $ DEA
      (N) See: Data Encryption Algorithm.

   $ deception
      (I) A circumstance or event that may result in an authorized
      entity receiving false data and believing it to be true. (See:
      authentication.)

      Tutorial: This is a type of threat consequence, and it can be
      caused by the following types of threat actions: masquerade,
      falsification, and repudiation.

   $ decipher
      (D) Synonym for "decrypt".

      Deprecated Definition: IDOCs SHOULD NOT use this term as a synonym
      for "decrypt". However, see usage note under "encryption".

   $ decipherment
      (D) Synonym for "decryption".

      Deprecated Definition: IDOCs SHOULD NOT use this term as a synonym
      for "decryption". However, see the Usage note under "encryption".

   $ declassification
      (I) An authorized process by which information is declassified.
      (Compare: classification.)

   $ declassify
      (I) To officially remove the security level designation of a
      classified information item or information type, such that the
      information is no longer classified (i.e., becomes unclassified).
      (See: classified, classify, security level. Compare: downgrade.)



<span class="grey">Shirey                       Informational                     [Page 98]</span>

<span id="page-99" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


   $ decode
      1. (I) Convert encoded data back to its original form of
      representation. (Compare: decrypt.)

      2. (D) Synonym for "decrypt".

      Deprecated Definition: Encoding is not usually meant to conceal
      meaning. Therefore, IDOCs SHOULD NOT use this term as a synonym
      for "decrypt", because that would mix concepts in a potentially
      misleading way.

   $ decrypt
      (I) Cryptographically restore cipher text to the plaintext form it
      had before encryption.

   $ decryption
      (I) See: secondary definition under "encryption".

   $ dedicated security mode
      (I) A mode of system operation wherein all users having access to
      the system possess, for all data handled by the system, both (a)
      all necessary authorizations (i.e., security clearance and formal
      access approval) and (b) a need-to-know. (See: /system operation/
      under "mode", formal access approval, need to know, protection
      level, security clearance.)

      Usage: Usually abbreviated as "dedicated mode". This mode was
      defined in U.S. Government policy on system accreditation, but the
      term is also used outside the Government. In this mode, the system
      may handle either (a) a single classification level or category of
      information or (b) a range of levels and categories.

   $ default account
      (I) A system login account (usually accessed with a user
      identifier and password) that has been predefined in a
      manufactured system to permit initial access when the system is
      first put into service. (See: harden.)

      Tutorial: A default account becomes a serious vulnerability if not
      properly administered. Sometimes, the default identifier and
      password are well-known because they are the same in each copy of
      the system. In any case, when a system is put into service, any
      default password should immediately be changed or the default
      account should be disabled.

   $ defense in depth
      (N) "The siting of mutually supporting defense positions designed
      to absorb and progressively weaken attack, prevent initial



<span class="grey">Shirey                       Informational                     [Page 99]</span>

<span id="page-100" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      observations of the whole position by the enemy, and [enable] the
      commander to maneuver the reserve." [<a href="#ref-JP1" title=""Department of Defense Dictionary of Military and Associated Terms"">JP1</a>]

      Tutorial: In information systems, defense in depth means
      constructing a system's security architecture with layered and
      complementary security mechanisms and countermeasures, so that if
      one security mechanism is defeated, one or more other mechanisms
      (which are "behind" or "beneath" the first mechanism) still
      provide protection.

      This architectural concept is appealing because it aligns with
      traditional warfare doctrine, which applies defense in depth to
      physical, geospatial structures; but applying the concept to
      logical, cyberspace structures of computer networks is more
      difficult. The concept assumes that networks have a spatial or
      topological representation. It also assumes that there can be
      implemented -- from the "outer perimeter" of a network, through
      its various "layers" of components, to its "center" (i.e., to the
      subscriber application systems supported by the network) -- a
      varied series of countermeasures that together provide adequate
      protection. However, it is more difficult to map the topology of
      networks and make certain that no path exists by which an attacker
      could bypass all defensive layers.

   $ Defense Information Infrastructure (DII)
      (O) /U.S. DoD/ The U.S. DoD's shared, interconnected system of
      computers, communications, data, applications, security, people,
      training, and support structures, serving information needs
      worldwide. (See: DISN.) Usage: Has evolved to be called the GIG.

      Tutorial: The DII connects mission support, command and control,
      and intelligence computers and users through voice, data, imagery,
      video, and multimedia services, and provides information
      processing and value-added services to subscribers over the DISN.
      Users' own data and application software are not considered part
      of the DII.

   $ Defense Information Systems Network (DISN)
      (O) /U.S. DoD/ The U.S. DoD's consolidated, worldwide, enterprise
      level telecommunications infrastructure that provides end-to-end
      information transfer for supporting military operations; a part of
      the DII. (Compare: GIG.)

   $ degauss
      1a. (N) Apply a magnetic field to permanently remove data from a
      magnetic storage medium, such as a tape or disk [<a href="#ref-NCS25" title=""A Guide to Understanding Data Remanence in Automated Information Systems"">NCS25</a>]. (Compare:
      erase, purge, sanitize.)




<span class="grey">Shirey                       Informational                    [Page 100]</span>

<span id="page-101" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      1b. (N) Reduce magnetic flux density to zero by applying a
      reversing magnetic field. (See: magnetic remanence.)

   $ degausser
      (N) An electrical device that can degauss magnetic storage media.

   $ DEK
      (I) See: data encryption key.

   $ delay
      (I) /packet/ See: secondary definition under "stream integrity
      service".

   $ deletion
      (I) /packet/ See: secondary definition under "stream integrity
      service".

   $ deliberate exposure
      (I) /threat action/ See: secondary definition under "exposure".

   $ delta CRL
      (I) A partial CRL that only contains entries for certificates that
      have been revoked since the issuance of a prior, base CRL [<a href="#ref-X509" title=""Information Technology -- Open Systems Interconnection -- The Directory: Authentication Framework"">X509</a>].
      This method can be used to partition CRLs that become too large
      and unwieldy. (Compare: CRL distribution point.)

   $ demilitarized zone (DMZ)
      (D) Synonym for "buffer zone".

      Deprecated Term: IDOCs SHOULD NOT use this term because it mixes
      concepts in a potentially misleading way. (See: Deprecated Usage
      under "Green Book".)

   $ denial of service
      (I) The prevention of authorized access to a system resource or
      the delaying of system operations and functions. (See:
      availability, critical, flooding.)

      Tutorial: A denial-of-service attack can prevent the normal
      conduct of business on the Internet. There are four types of
      solutions to this security problem:
      -  Awareness: Maintaining cognizance of security threats and
         vulnerabilities. (See: CERT.)
      -  Detection: Finding attacks on end systems and subnetworks.
         (See: intrusion detection.)
      -  Prevention: Following defensive practices on network-connected
         systems. (See: [<a href="#ref-R2827" title=""Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing"">R2827</a>].)




<span class="grey">Shirey                       Informational                    [Page 101]</span>

<span id="page-102" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      -  Response: Reacting effectively when attacks occur. (See: CSIRT,
         contingency plan.)

   $ DES
      (N) See: Data Encryption Standard.

   $ designated approving authority (DAA)
      (O) /U.S. Government/ Synonym for "accreditor".

   $ detection
      (I) See: secondary definition under "security".

   $ deterrence
      (I) See: secondary definition under "security".

   $ dictionary attack
      (I) An attack that uses a brute-force technique of successively
      trying all the words in some large, exhaustive list.

      Examples: Attack an authentication service by trying all possible
      passwords. Attack an encryption service by encrypting some known
      plaintext phrase with all possible keys so that the key for any
      given encrypted message containing that phrase may be obtained by
      lookup.

   $ Diffie-Hellman
   $ Diffie-Hellman-Merkle
      (N) A key-agreement algorithm published in 1976 by Whitfield
      Diffie and Martin Hellman [<a href="#ref-DH76" title=""New Directions in Cryptography"">DH76</a>, <a href="#ref-R2631" title=""Diffie-Hellman Key Agreement Method"">R2631</a>].

      Usage: The algorithm is most often called "Diffie-Hellman".
      However, in the November 1978 issue of "IEEE Communications
      Magazine", Hellman wrote that the algorithm "is a public key
      distribution system, a concept developed by [Ralph C.] Merkle, and
      hence should be called 'Diffie-Hellman-Merkle' ... to recognize
      Merkle's equal contribution to the invention of public key
      cryptography."

      Tutorial: Diffie-Hellman-Merkle does key establishment, not
      encryption. However, the key that it produces may be used for
      encryption, for further key management operations, or for any
      other cryptography.

      The algorithm is described in [<a href="#ref-R2631" title=""Diffie-Hellman Key Agreement Method"">R2631</a>] and [<a href="#ref-Schn" title=""Applied Cryptography Second Edition"">Schn</a>]. In brief, Alice
      and Bob together pick large integers that satisfy certain
      mathematical conditions, and then use the integers to each
      separately compute a public-private key pair. They send each other
      their public key. Each person uses their own private key and the



<span class="grey">Shirey                       Informational                    [Page 102]</span>

<span id="page-103" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      other person's public key to compute a key, k, that, because of
      the mathematics of the algorithm, is the same for each of them.
      Passive wiretapping cannot learn the shared k, because k is not
      transmitted, and neither are the private keys needed to compute k.

      The difficulty of breaking Diffie-Hellman-Merkle is considered to
      be equal to the difficulty of computing discrete logarithms modulo
      a large prime. However, without additional mechanisms to
      authenticate each party to the other, a protocol based on the
      algorithm may be vulnerable to a man-in-the-middle attack.

   $ digest
      See: message digest.

   $ digital certificate
      (I) A certificate document in the form of a digital data object (a
      data object used by a computer) to which is appended a computed
      digital signature value that depends on the data object. (See:
      attribute certificate, public-key certificate.)

      Deprecated Usage: IDOCs SHOULD NOT use this term to refer to a
      signed CRL or CKL. Although the recommended definition can be
      interpreted to include other signed items, the security community
      does not use the term with those meanings.

   $ digital certification
      (D) Synonym for "certification".

      Deprecated Definition: IDOCs SHOULD NOT use this definition unless
      the context is not sufficient to distinguish between digital
      certification and another kind of certification, in which case it
      would be better to use "public-key certification" or another
      phrase that indicates what is being certified.

   $ digital document
      (I) An electronic data object that represents information
      originally written in a non-electronic, non-magnetic medium
      (usually ink on paper) or is an analogue of a document of that
      type.

   $ digital envelope
      (I) A combination of (a) encrypted content data (of any kind)
      intended for a recipient and (b) the content encryption key in an
      encrypted form that has been prepared for the use of the
      recipient.






<span class="grey">Shirey                       Informational                    [Page 103]</span>

<span id="page-104" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      Usage: In IDOCs, the term SHOULD be defined at the point of first
      use because, although the term is defined in PKCS #7 and used in
      S/MIME, it is not widely known.

      Tutorial: Digital enveloping is not simply a synonym for
      implementing data confidentiality with encryption; digital
      enveloping is a hybrid encryption scheme to "seal" a message or
      other data, by encrypting the data and sending both it and a
      protected form of the key to the intended recipient, so that no
      one other than the intended recipient can "open" the message. In
      PKCS #7, it means first encrypting the data using a symmetric
      encryption algorithm and a secret key, and then encrypting the
      secret key using an asymmetric encryption algorithm and the public
      key of the intended recipient. In S/MIME, additional methods are
      defined for encrypting the content encryption key.

   $ Digital ID(service mark)
      (D) Synonym for "digital certificate".

      Deprecated Term: IDOCs SHOULD NOT use this term. It is a service
      mark of a commercial firm, and it unnecessarily duplicates the
      meaning of a better-established term. (See: credential.)

   $ digital key
      (D) Synonym for an input parameter of a cryptographic algorithm or
      other process. (See: key.)

      Deprecated Usage: The adjective "digital" need not be used with
      "key" or "cryptographic key", unless the context is insufficient
      to distinguish the digital key from another kind of key, such as a
      metal key for a door lock.

   $ digital notary
      (I) An electronic functionary analogous to a notary public.
      Provides a trusted timestamp for a digital document, so that
      someone can later prove that the document existed at that point in
      time; verifies the signature(s) on a signed document before
      applying the stamp. (See: notarization.)

   $ digital signature
      1. (I) A value computed with a cryptographic algorithm and
      associated with a data object in such a way that any recipient of
      the data can use the signature to verify the data's origin and
      integrity. (See: data origin authentication service, data
      integrity service, signer. Compare: digitized signature,
      electronic signature.)





<span class="grey">Shirey                       Informational                    [Page 104]</span>

<span id="page-105" ></span>
<span class="grey"><a href="./rfc4949">RFC 4949</a>         Internet Security Glossary, Version 2       August 2007</span>


      2. (O) "Data appended to, or a cryptographic transformation of, a
      data unit that allows a recipient of the data unit to prove the
      source and integrity of the data unit and protect against forgery,
      e.g. by the recipient." [<a href="#ref-I7498-2" title=""Information Processing Systems -- Open Systems Interconnection Reference Model, Part 2: Security Architecture"">I7498-2</a>]

      Tutorial: A digital signature should have these properties:
      -  Be capable of being verified. (See: validate vs. verify.)
      -  Be bound to the signed data object in such a way that if the
         data is changed, then when an attempt is made to verify the
         signature, it will be seen as not authentic. (In some schemes,
         the signature is appended to the signed object as stated by
         definition 2, but in other it, schemes is not.)
      -  Uniquely identify a system entity as being the signer.
      -  Be under the signer's sole control, so that it cannot be
         created by any other entity.

      To achieve these properties, the data object is first input to a
      hash function, and then the hash result is cryptographically
      transformed using a private key of the signer. The final resulting
      value is called the digital signature of the data object. The
      signature value is a protected checksum, because the properties of
      a cryptographic hash ensure that if the data object is changed,
      the digital signature will no longer match it. The digital
      signature is unforgeable because one cannot be certain of
      correctly creating or changing the signature without knowing the
      private key of the supposed signer.

      Some digital signature schemes use an asymmetric encryption
      algorithm (e.g., "RSA") to transform the hash result. Thus, when
      Alice needs to sign a message to send to Bob, she can use her
      private key to encrypt the hash result. Bob receives both the
      message and the digital signature. Bob can use Alice's public key
      to decrypt the signature, and then compare the plaintext result to
      the hash result that he computes by hashing the message himself.
      If the values are equal, Bob accepts the message because he is
      certain that it is from Alice and has arrived unchanged. If the
      values are not equal, Bob rejects the message because either the
      message or the signature was altered in transit.

      Other digital signature schemes (e.g., "DSS") transform the hash
      result with an algorithm (e.g., "DSA", "El Gamal") that cannot be
      directly used to encrypt data. Such a scheme creates a signature
      value from the hash and provides a way to verify the signature
      value, but does not provide a way to recover the hash result from
      the signature value. In some countries, such a scheme may improve
      exportability and avoid other legal constraints on usage. Alice
      sends the signature value to Bob along with both the message and
      its hash result. The algorithm enables Bob to use Alice's public