Security problems in computer communication systems
Rein Türn · ACM SIGCOMM Computer Communication Review · 1975
At the present time there is a rapid growth in computer communications associated with terminal-based, multi-user computer systems, and in networks of computers [1,2,3]. Nearly all such systems communicate, process, or store information which is considered private or proprietary by their owners and users, or which must be safeguarded from unauthorized access as required by law. Furthermore, associated terminals, telecommunication systems, communication processors, and computers must be protected from intruders that may seek to alter programs or data in the system, or to disrupt the services provided. These threats are real, since it is not difficult to intercept transmissions in telecommunication networks [4,5], and it is possible to connect illicit terminals (or even computers) into the system for the purposes of "managing" the normal terminal-computer communications, masquerading as a legitimate user, or simply making the system unavailable to others [6,7]. The protection of a computer communication system against the various threats involves: (1) identification, and authentication of the identity, (2) controlled access to computers and their data bases, and (3) protection of the data in transit in the telecommunication system. Associated with each are a number of problems -- conceptual, as well as technical -- and a variety of solutions. In this brief survey, the emphasis is on the problems.