- Least Privilege Security for Windows 7, Vista and XP
- Russell Smith
- 227字
- 2021-08-05 16:18:03
Advanced Least Privilege Security concepts
Most operating systems, including Windows NT, use advanced Least Privilege Security concepts as follows:
Discretionary Access Control
Discretionary Access Control (DAC) is where system administrators assign access to a set of objects, such as a directory of files, and allow the user to change the security properties of those files. The user becomes the owner of the directory and can modify the security properties of all files within that directory.
Mandatory Access Control
Mandatory Access Control (MAC) allows system administrators to centrally control the changes users can make to objects they own. MAC helps prevent the flow of sensitive information from a high-privileged account to a lower one.
Mandatory Integrity Control
Windows Vista introduced a form of MAC through Mandatory Integrity Control (MIC) that prevents processes running with a low Integrity Level (IL) from writing to or deleting objects with a higher IL.
Role-based Access Control
Windows Server 2003 included Role-based Access Control (RBAC) that allows system administrators to control access, based on users' organizational roles. Focusing on users' roles rather than objects and resources, as with DAC, is a more natural way for system administrators to control access to data across an organization. DAC enforces basic least privilege concepts to protect operating system files and registry keys using groups, which are collections of users, whereas RBAC roles are collections of permissions.
- JBoss AS 5 Development
- 中文版CorelDRAW X7基礎(chǔ)培訓(xùn)教程(移動(dòng)學(xué)習(xí)版)
- 24小時(shí)全速學(xué)會(huì)Photoshop 2021
- Adobe創(chuàng)意大學(xué)InDesign CS5 版式設(shè)計(jì)師標(biāo)準(zhǔn)實(shí)訓(xùn)教材
- Instant Microsoft SQL Server Analysis Services 2012 Dimensions and Cube
- Drupal: Creating Blogs, Forums, Portals, and Community Websites
- Photoshop CS6案例教程(第3版)
- Illustrator CC平面設(shè)計(jì)標(biāo)準(zhǔn)教程(微課版)
- Photoshop數(shù)字圖像處理
- Flash CC動(dòng)畫制作與應(yīng)用(第3版)
- Photoshop海報(bào)設(shè)計(jì)技巧與實(shí)戰(zhàn)
- 電腦寫作與定制五筆(第2版)
- EJB 3.1 Cookbook
- 計(jì)算機(jī)圖形學(xué)編程(使用OpenGL和C++)
- Excel數(shù)據(jù)分析與可視化