Forgot password?
|
|
|
|
We were unable to sign you in.
Please verify your user name and password and try again. If you do not have a TEC account, register now.
Read Comments
L. Taylor - June 20, 2000

The following article appeared in Midrange Computing's Showcase Magazine, June 2000.

Note: For additional articles by Laura Taylor, click on the Security category in the Research Panels box on the TEC website home page.

Event Summary

An off-shoot of System/38, the AS/400 was originally going to be called the AS/40. However, purely for marketing purposes, IBM added an extra zero to the name to make it appear bigger, better, and smarter. In order to add substance and credibility to the additional zero, in a bold announcement, Steve Schwartz, the AS/400 division President, announced back in June of 1988 that the AS/400 could support 400 concurrent users. Analysts bought the story, and IT decision makers bought the box.

Withstanding the trials and tribulations of new technology and sophisticated application reengineering, the AS/400 deserves a medal for versatility and the ability to re-invent itself every few years in a an ever changing world of user requirements. One of the changes that the digital world and the AS/400 must cope with in the 21st century is the on-slaught of security intrusions. Not surprisingly, the media is hard-pressed for security incident reports involving AS/400s. Attacking and exploiting an AS/400 is much more difficult than attacking a UNIX or NT box.

Unlike many other computing platforms where security is built-in as an afterthought, security was built into the AS/400 from the get go, as part of the original design. The security smart IBM server uses industry standard network protocols, and can be protected by your corporate perimeter firewall, and guarded by your intrusion detection system, in the same manner as other networked multi-user systems. However, network security should never replace host security, and therefore how to implement sound host security on your AS/400 is something worth understanding.

You probably won't want to turn your AS/400 into a firewall, even though an add-on package exists for doing so. As well, you're not going to want to use IBM's SecureWay firewall since it was recently announced that the SecureWay's development will be discontinued. Though firewalls are not IBM's forte, mid-range host security is something that they took time to think about. Typically security incidents can be attributed to either problems in the system's architecture, programming bugs in the systems operating system, or configuration errors. In the IBM AS/400, you won't find any of the former two. It is far more complex to attack an AS/400 than to attack a UNIX, NT, or Netware server.

Built-in Encryption

To start with, the AS/400's crypto engine is built into the hardware. The 4758 PCI card, which is a common hardware solution across IBM server platforms, has built-in support for IBM's Common Cryptographic Architecture (CCA), and includes APIs that offer unique support for financial packages. Designed to meet the Federal Information Processing key protection Standards (FIPS 140-1), the 4758 is of particular interest for on-line banking and payment gateways that span International networks or networks that are part of Federal Agencies.

To complement the hardware encryption engine, there is a 40 bit, 56 bit, and a 128 bit encryption add-on software access provider product that can be installed in the AS/400 to enable the secure sockets layer (SSL) function. Due to export laws, the 128bit encryption add-on is available only in the U.S. and Canada.

AS/400 Server SSL Add-On Encryption Modules

Size of Crypto Access Provider Product Name
40 bits 5769-AC1
56 bits 5769-AC2
128 bits 5769-AC3

Client encryption products also exist so that AS/400 clients can security access encrypted information on AS/400 servers.

AS/400 Client SSL Add-On Encryption Modules

Size of Crypto Access Provider Product Name
40 bits 5769-CE1
56 bits 5769-CE1
128 bits 5769-CE3

IP-Masquerading through NAT

For added security, the AS/400 is able to perform IP-masquerading through Network Address Translation (NAT). NAT hides the real IP address of outbound packets, assigning them a single public IP address. This type of IP proxying secures the internal network by not broadcasting the real IP addresses making an AS/400 network less vulnerable to IP spoofing and being used a launch point for Denial of Service attacks.

The Security Wizard

The AS/400 Windows-like Security Wizard guides you through the security configuration process asking questions about the base AS/400 and making recommendations regarding configuration options. The Security Wizard can also generate separate administrator and user reports containing the security configuration status of password management rules, job time-out intervals, remote service attributes, object ownership changes, user profile changes, authority changes, and a whole lot more.

HTTP and Internet Connection Server

The AS/400 comes with an HTTP Server, which was previously branded as the Internet Connection Server. Add on IBM Websphere for a Java based Web application server, which comes pre-bundled with Java Security Extensions.

SET Internet Security Manager

The AS/400 comes bundled with the Secure Electronic Transaction (SET) protocol. SET is a protocol developed by Visa and Mastercard for payment systems, and has its own unique connection handshake. SET is a third party payment system which allows retailer to accept orders and send charges to the bank where card is registered. To use SET, the retailer does not have to handle the credit card. Due to the administrative overhead associated with it, SET has not caught on as well in the United States and Canada as it has among eCommerce vendors in Europe, however, that is likely to change as security engineers educate eCommerce vendors about the inherent weakness in Secure Sockets Layer (SSL). SSL only encrypts transactions in transit. Once a transaction has reached an Internet merchant, a user is placing an undue amount of trust into how well the merchant is securing their credit card data on their own internal infrastructure. Since SSL has no way of assuring that the merchant is authorized to accept credit card payments, there is no implied security verifiable with the merchant. A SET merchant needs to register with a financial institution and setup communications with a bank which does require additional overhead.

SET, like SSL, can slow down transactions, however, with multiple crypto accelerators on the market that can speed up transactions, what will separate true eCommerce vendors from eCommerce wannabes is whether they are using SET or SSL. Any service provider serious about security, e.g. online financial institutions, ought to be using SET not SSL. The fact that the AS/400 comes bundled with SET shows IBM's commitment and leadership when it comes to eCommerce security.

The IBM Payment Server supports SET, and with this additional software package installed on the AS/400, if configured correctly, there is the potential to have a truly secure eCommerce server that transfers money from a users digital eWallete through SET to a Payment Server, and then to your bank.

Security Levels

There are four systems parameters for configuring security that need to be set on the AS/400. These parameters are:

  • QSECURITY

  • QAUDJRL

  • QMAXSIGN

  • QRETSVRSEC

QSECURITY
QSECURITY is the security enforcer. The value of QSECURITY can be set to 10, 20, 30, 40, or 50. System/38, and the original AS/400 had only three levels of system security. A fourth level was added in V1, release 3, and a fifth level was added in V2, release 3.

A minimum security level of 40 is highly recommended.

Note that Machine Interface (MI) instructions are not available to programs authored by users regardless of the security level the system is running. As well, it is not possible for third-party programs to bypass object auditing.


QAUDJRL
QUADJRL turns on the security audit journal. The security audit journal can also run at various levels. The events that are logged by the security audit journal are determined by a combination of the level of QAUDJRL and QSECURITY. The events that can potentially be recorded include authorization failures, deleted objects, and identification of programs using restricted instructions. These logs should be reviewed on a regular schedule by a security engineer.


QMAXSIGN
The QMAXSIGN parameter is for specifying the number of sign-on attempts allowable for a particular user from a particular device. If the number of unsuccessful attempts to sign-on to the AS/400 exceeds this number, the device from which the user attempted access is disconnected.


QRETSVRSEC
The QRETSVRSEC parameter determines whether or not security authentication data needed by the AS/400 can be retained, or stored, on the client host system. If it is setup so that the authentication data cannot be retained on the client system, the AS/400 will prompt the user for an ID and password. A similar parameter exists for TCP/IP, IPX/SPX, and Lotus Notes networks called FFQRETSVRSEC.

Access User Classes

Every user client of an AS/400 has a profile. A user profile contains security fields that specify values for class, ownership, authority, scheduling priorities, device sessions, and privileged instructions. The values for a User Class can be any of the following:

  • Security Officer

  • Security Administrator

  • System Programmer

  • System Operator

  • Workstation User

The Security Officer is equivalent to root access in UNIX, or administrator access in NT. The Workstation User has the lowest level of security access. A user can be a member of more than one User Class.

Using the IOSYSCFG command, it is a good idea to restrict who has authority to configure TCP/IP using STRTCP (start TCP/IP) to the Security Officer and Security Administrator only.

Object Ownership and Authorization

Objects can be either owned, or authorized, by a user through the user profile. A user who creates an object is its owner by default. Authorization of objects is done through membership to a group. If a particular user is a member of a group, it is possible to specify in the profile that all objects created by the particular user also belong to that group. The owner of an object can grant other users private authority to an object, similar to how a UNIX owner can grant execute privileges, but not read or write privileges, to another user.

Each object can be characterized by eight potential authorities or permissions. The eight authorities are:

  • Operational authority

  • Management authority

  • Existence authority

  • List management Read authority

  • Add authority

  • Delete authority

  • Update authority

Attacks, Exploits, Viruses, and Vulnerabilities

Because security is object based, and is integrated throughout the hardware and operating system, instructions only work on objects that they are designed to work on. This makes it rather difficult to bypass security on an AS/400. If an AS/400 is subjected to a buffer overflow attack, an attack that often results in security breaches on UNIX and NT systems, it will simply close down the attacker's connection. As far as viruses go, because the AS/400 does not use PC instructions, it is extremely resistant to PC viruses.

The Ideal Webserver

The AS/400 was built with compiled C binaries with no interpreted scripts making it extremely resilient to CGI subversion, and ideal for webhosting. If configured correctly, from a security perspective you can't go wrong using AS/400s to build your eCommerce site. With the recent outbreaks of system security compromises, we expect the AS/400 to continue its strong showing in the world of Internet commerce.


 
comments powered by Disqus


Demystifying SAP Solution Manager | Cloud Assets: A Guide for SMBs—Part 3 | I Want My Private Cloud | The Sum of All Malware Fears: Siemens on Stuxnet | Managing the Overflow of E-mails | Security Risk Assessment and Management in Web Application Security | Are You Adequately Protecting Your IT Infrastructure Components Inside the Firewall? | Enterprise Resource Planning Giants Eye the Shop Floor | Who Else is Using Your Wireless Network? | Information Security Firewalls Market Report Part Two: Current Market Trends and User Recommendations | Information Security Firewalls Market Report Part One: Market Overview and Technology Background | Automated Enterprise: Many High-ROI Opportunities | Secure Transfers of Large Files Over the Internet Using YouSendIt | Fed Warms Up to ERP Spending, but Will Contractors and Their ERP Vendors Comply? Part Two: Challenges and User Recommendations | Feds Warms Up to ERP Spending, but Will Contractors and Their ERP Vendors Comply? Part One: Event Summary and Market Impact |
Product Review: GFI's LANguard Network Security Scanner | The Best ACT! Is Still to Come | HIPAA-Watch for Security Speeds Up Compliance Part Two: Phase III and IV, and Product and User Recommendations | HIPAA-Watch for Security Speeds Up Compliance Part One: Vendor and Product Information | EAM Versus CMMS: What's Right for Your Company? Part One | Using PKI to Protect Your Business Information | The CyberAngel: Laptop Recovery and File Encryption All-in-One | Evaluating Enterprise Software-Business Process or Feature/Function-Based Approach? All the above, Perhaps? Part Three: Knowledge Bases and User Recommendations | InsideOut Firewall Reporter Unravels the Mysteries of Your Firewall Logs | The Future of Secure Remote Password (SRP) Part Two: Overcoming Obstacles to Success | The Future of Secure Remote Password (SRP) | Integrated Security: A New Network Approach Part Two: The Shift Toward Integration | Integrated Security: A New Network Approach | Vendor Analysis: Kaspersky Anti-Virus Products Examined | 6 Immediate Business Improvements Offered by an Online SRM System: Part 3: Other Points to Consider | Legacy Single Sign-On: Novell, Evidian, IBM, PassGo, or Computer Associates? | Fourth Shift's evolution Within SoftBrands' DemandStream | OKENA Brews Up a StormSystem that Secures All Applications | Incident Handling and Response Capability: An IT Security Safeguard Part 2: Establishing the Capability | Incident Handling and Response Capability: An IT Security Safeguard Part 1: Are You Ready to Support an Incident Response Capability? | Outsourcing Security Part 3: Selecting a Managed Security Services Provider | Outsourcing Security Part 2: Measuring the Cost | Outsourcing Security Part 1: Noting the Benefits | Vendor Review: SecureWave Protects Microsoft Operating System Platforms | Thanks to a Smart Little Company called Lexias, CIOs Can Now Empower their Users to Assist in eBusiness Security | Feds Buckle Down on Customer Information Security | Identix Leads Biometric Authentication | Bootcamp for the Pros; Why Ernst & Young Will Lead Security Auditing Standards | Vendor Analysis: Interliant's Security Vulnerability Assessment | OKENA Pioneers Next-Generation Intrusion Prevention | Social Engineering Can Thwart the Best Laid Security Plans | Application Single-Sign On: Netegrity, Securant, or Evidian? | Lost Your Laptop? The CyberAngel® Brings It Back | InsideOut Makes Firewall Reporting Useful | The SOAP Opera Progresses - Helping XML to Rule the World | Talarian and NextSet Team for B2B Solutions | Tempest Creates a Secure Teapot | E*Trade Ignores Private Security Warning, But Public Hullaballoo Gets Response | My Network Engineers are Talking about Implementing Split DNS. What Does that Mean? | Human-Machine Interaction Company Ramps Up Firewall Product Line | Security Information Market Heading for Growth | Alibris Charged with Intercepting Email | Cart32 in Need of Duct Tape | Deutsche Telekom to Acquire VoiceStream Wireless | Study Shows: FBI Alienates Industry Security Experts | Firewall Cowboyz Set the Stage to Free Innocent Convict | Symantec Swallows AXENT; Takes on Network Associates | Novatel Wireless and Diversinet Team Up to Provide Security for Wireless Modems | Windows 2000 Bug Fixes Posted | Baltimore Technologies Doubles Revenues, Offers World-Class PKI Hosting | The Whys and Hows of a Security Vulnerability Assessment | Earthlink Leads the Way in DSL Security | PKI and Biometrics Ready for Take-Off | Secure Transport of EDI and XML for Trading Exchanges | Can You Trust Entrust? | Standard & Poor's Announces Security Certification | Check Point Leads Firewall Market | Fighting Cybercrime on the Internet | NetWare for Small Business – NetWhy? | Let Your Hard Drives Tell You Where they Are! | E&Y Spins-Off eSecurity Online and Unveils Security Vulnerability Assessment Services | With Record Revenues, AXENT Puts Down a Solid Fist | NAI Will Pay Trend $12.5 Million Resulting from Law Suit | Sub7 Tells Chat Rooms All Your Stuff; F-Secure Leads the Battle | E-Cash Rollout Replaces Amex | GSA Schedule Partnership Gets Network-1 in the Door | Los Alamos Loses Top-Secret Information, Again! | Standard & Poor's Exposes Customers' Security | Trend Micro Steps into PDA/Wireless AntiVirus Information Market | CryptoSwift Takes Rainbow Revenues Up 620% | Smart Shoppers Go Abroad for Affordable Information Security Programs | Anti-Virus Advisories: Rating Them | The 7 Habits of Highly Effective Security | Fischer’s Prio! SecureSync ~ A Solution to Enterprise Directory Chaos | Abandon All Insecurity, Ye Who Enter Here | Top 10 Excuses For Not Securing Your Website or Network | Ernst & Young Leads Big 5 in Security | 6 Days After Advisory Posted, AboveNet Gets Hit | A Firewall is Cheaper Than a Lawyer | Fixing Security Backdoors:
Red Hat 1, Microsoft 0
| WAP Forum Specifies RSA’s RC5 Encryption For Wireless | Netpliance Responds Quickly to Hardware Hack | Security Stocks Burn Rubber | DSL Provider Scoops up Netscreen Firewall Goldmine | Cyclone Untangles Digital Partnerships | Security Begins on Your Desktop | Network Associates Hopes to Rekindle the Flame | Hacker Publication Gets Top Defense Attorney | Saudi Arabian Network Security Provokes Local Considerations | Gosh, There’s a Bug in Windows 98 | Robust Systems are Built from the Bottom Up | DOJ Keeps Low Profile on Curador; Protect Your IIS Server Today! | Security Breach: Now What? | Sendmail, Inc. and Disappearing, Inc. Team Up to Add Enhanced Security | Is Your Financial Transaction Secure? | Compaq, HP, IBM, Intel and Microsoft Create New PC Security Alliance | Expect Boom in Electronic Signatures | Secure Your Search Engine | President Proposes Security of Medical Records | Sendmail Takes Security to the Next Level with Version 3.0 for NT | CheckPoint & Nokia Team Up to Unleash a Rockin' Security Appliance | Trend Micro Anti-Virus Server for Microsoft Exchange ~ A Secure Choice For Enterprise Wide Anti Virus Protection. | Security Snafu at NetBank | Freeware Vendor's Web Tracking Draws Curses | The "S" in SAP Doesn't Stand for Security (that goes for PeopleSoft too) | Content Technologies releases MIMEsweeper PolicyPlus | Hackers Will Be Out in Full Force On New Year's Eve | Analysis of Virgin Net's Hacker Scare | Network Associates RePositions Itself as a Security E-Village | Lexiguard™: The Coming "Adobe Acrobat" of Encryption | CyberPeepers from Korean Sites Peek at U.S. Networks | Would You Hire a Hacker? What Would Your Mother Say? | @Home Scans Own Customers | CIOs Need to Be Held Accountable for Security | New Market for Security Insurance | At Least Your Boss Can't Read Your Home E-mail, Right? Wrong! | PrettyPark Virus Litters Cyberspace | Packard Bell / NEC Leads Secure Etoken Deployment | Congress Acknowledges Outdated Banking Laws | How Secure is Your E-Mail? | Trend Virus Control System - A Centralized Approach to Protection | VPNs Are Hot, but What Are They? | ATM Machines Hacked in Moscow | How To Mitigate Holiday Cybercrime | Surf's Up at Akamai |


Use this index to search for white papers related to commonly used search terms A B C D E F G H I J K L M N O P Q R S T U V W X Y Z Others 
Recent Searches
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z Others
A: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26
B: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19
D: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19
E: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22
F: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27
G: 1 2 3 4 5 6 7
H: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20
I: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15
J: 1 2 3 4 5
K: 1 2 3 4
L: 1 2 3 4 5 6 7 8 9 10 11 12 13 14
M: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20
N: 1 2 3 4 5 6 7 8
O: 1 2 3 4 5 6 7 8 9 10 11 12 13 14
P: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19
Q: 1 2
R: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17
T: 1 2 3 4 5 6 7 8 9 10 11 12 13
U: 1 2 3
V: 1 2 3 4
W: 1 2 3 4 5 6 7 8 9 10 11
X: 1
Y: 1
Z: 1
Others: 1 2 3


©2013 Technology Evaluation Centers Inc. All rights reserved. Search powered by Google