EBA欧洲银行-10Annex-5-mobile_code_standard_13页_237kb
报告摘要
European Commission Information System Security Policy: Standard on Mobile Code
Core Content
This document outlines the European Commission's (EC) Security Standard on Mobile Code, adopted on 21 June 2011 by Mrs. Irene Souka, Director-General of DG Human Resources and Security. It is based on Commission Decision C(2006) 3602, which establishes the framework for information system security within the EC.
The standard defines mobile code as any code that is downloaded and executed directly on an end user device, often without the user's knowledge or intervention. Mobile code can be used for both legitimate and malicious purposes, such as providing rich user interfaces or spreading computer viruses. The objective of this standard is to ensure the safe execution of legitimate mobile code and prevent it from exploiting system weaknesses and spreading across the EC network.
Main Objectives
- To provide measures for the safe execution of imported mobile code.
- To prevent unauthorized use or disruption of system, network, or application resources.
- To reduce the impact of information security threats associated with mobile code.
Scope
- Applies to all European Commission information systems.
- Covers all types of mobile code technologies, including those with potentially dangerous content.
- Focuses on security controls to mitigate risks from mobile code execution.
Threats Covered
The standard addresses the following threats:
- T23 - Disclosure: Unauthorized exposure of sensitive information.
- T24 - Data from untrustworthy sources: Data integrity and authenticity issues.
- T26 - Tampering with software: Unauthorized modification of software.
- T30 - Saturation of the information system: Overloading systems with excessive requests.
- T31 - Software malfunction: Malfunction due to code errors or malicious activity.
- T36 - Corruption of data: Unauthorized alteration of data.
- T39 - Abuse of rights: Unauthorized use of system privileges.
Key Definitions
| Term | Description |
|---|---|
| ActiveX | A set of interfaces from Microsoft that link desktop applications to the Web. |
| Applet | A small application with limited features, typically used in web browsers. |
| Certificate | An electronic document verifying the identity of the certificate holder. |
| Code Signing | A process to verify the authenticity and integrity of code using digital signatures. |
| Flash | A multimedia platform for animation, video, and interactivity on web pages. |
| Java | A cross-platform programming language for developing applications. |
| JavaScript | A scripting language used in web browsers to create interactive content. |
| LotusScript | A dialect of BASIC used in IBM Lotus Software. |
| Mobile Agent | Software that can migrate between computers and execute autonomously. |
| Runtime Environment | An execution environment that allows mobile code to run, such as web browsers or JRE. |
| Script | A sequence of instructions executed by another program. |
| Self-signed Certificate | A certificate signed by its creator, which may be less trustworthy. |
| Shockwave | A multimedia player for Adobe Director applications. |
| Silverlight | A framework for developing rich internet applications, similar to Flash. |
| Unmediated Access | Access to system resources without security policy enforcement. |
| VBScript | A scripting language used in Internet Explorer. |
| VBA (Visual Basic for Applications) | A programming language embedded in Microsoft Office applications. |
Risk Categories
-
High Risk Mobile Code:
- Has unmediated access to system resources.
- Examples: Binary executables, ActiveX, Java programs, Windows Scripting Host, and batch/shell scripts.
- Requires secure delivery (e.g., encrypted connections or code signing).
-
Standard Risk Mobile Code:
- Uses mediated access or has limited functionality.
- Examples: Java applets, VBA, JavaScript, Flash, Shockwave, and Silverlight.
- May be used with documentation and approval in the system's security plan.
Security Controls
Server Side
- Code Signing: Preferred method to ensure code integrity. Mobile code must be signed with an EC CA or commercial certificate.
- Input Validation: All data received from clients must be validated to prevent malicious input.
- Risk Assessment: Before acquiring or developing a system with mobile code, risks must be evaluated, and lower-risk technologies should be preferred.
- Secure Delivery: High-risk code must be delivered securely, such as through encrypted connections or code signing.
Client Side
- Runtime Environment Configuration: All runtime environments must be securely configured and minimised to reduce attack surfaces.
- Prevention of Unauthorised Execution: Users must not be allowed to change security settings or install alternative runtime environments.
- Anti-malware Protection: All end user devices must have up-to-date anti-malware software.
- Application Lockdown: Controls must be in place to restrict unauthorised software installation or execution.
- User Prompting: Execution of high-risk mobile code must be manually approved by the user.
- Trusted Sources: EC systems are considered trusted sources, and runtime environments should accept EC or trusted commercial code-signing certificates.
References
- Commission Decision (2001/844/EC): Related to security of information systems.
- Commission Decision C(2006) 3602: Framework for information system security.
- Implementing Rules for C(2006) 3602: Details on security measures.
- Standards on Information Security Risk Management, Controls against Malicious Code, Secure Systems Development, and Management of Technical Vulnerabilities (all in draft at the time of writing).
Related Documents
- ISO/IEC 27001 – Information security management.
- ISO/IEC 17799 – Code of practice for information security.
- NIST SP 800-28 Version 2 – Guidelines on active content and mobile code.
- Model-Carrying Code (MCC) – A new paradigm for mobile-code security.
Conclusion
This standard ensures that mobile code is used securely and responsibly within the European Commission's information systems. It outlines server-side and client-side controls to mitigate risks and prevent malicious activities, while allowing legitimate use of mobile code. The document is aligned with international security standards and emphasizes the importance of code signing, secure configuration, and user awareness.
试读结束,高清完整版pdf/doc/ppt,请点下载