- Least Privilege Security for Windows 7, Vista and XP
- Russell Smith
- 227字
- 2021-08-05 16:18:03
Advanced Least Privilege Security concepts
Most operating systems, including Windows NT, use advanced Least Privilege Security concepts as follows:
Discretionary Access Control
Discretionary Access Control (DAC) is where system administrators assign access to a set of objects, such as a directory of files, and allow the user to change the security properties of those files. The user becomes the owner of the directory and can modify the security properties of all files within that directory.
Mandatory Access Control
Mandatory Access Control (MAC) allows system administrators to centrally control the changes users can make to objects they own. MAC helps prevent the flow of sensitive information from a high-privileged account to a lower one.
Mandatory Integrity Control
Windows Vista introduced a form of MAC through Mandatory Integrity Control (MIC) that prevents processes running with a low Integrity Level (IL) from writing to or deleting objects with a higher IL.
Role-based Access Control
Windows Server 2003 included Role-based Access Control (RBAC) that allows system administrators to control access, based on users' organizational roles. Focusing on users' roles rather than objects and resources, as with DAC, is a more natural way for system administrators to control access to data across an organization. DAC enforces basic least privilege concepts to protect operating system files and registry keys using groups, which are collections of users, whereas RBAC roles are collections of permissions.
- Adobe創意大學After Effects CS5 產品專家認證標準教材
- 3ds Max 2014標準教程(全視頻微課版)
- OpenStack實戰指南
- Cacti 0.8 Beginner's Guide
- BPEL Cookbook: Best Practices for SOA/based integration and composite applications development
- ASP.NET MVC 2 Cookbook
- Instant MuseScore
- 攝影輕松入門:Photoshop后期處理
- SolidWorks 2018快速入門及應用技巧
- Elasticsearch數據搜索與分析實戰
- 計算機輔助翻譯基礎與實訓
- 中文版CorelDRAW X7技術大全
- Drupal for Education and E/Learning
- UG NX 12.0中文版自學視頻教程
- OpenCms 7 Development