官术网_书友最值得收藏!

Least Privilege Security in the real world

As servers are usually considered crucial to an organization, operators are often granted limited privileges to perform a restricted set of duties. A common example of this is management of backups in remote offices. Employees responsible for backup may have limited IT knowledge, but they need to change tapes and log on to the server to check for running backup jobs. It's preferable not to assign unqualified personnel administrative privileges on a server and create an additional significant risk.

In the same way that a firewall is supplied with all inbound ports blocked (requiring an admin to specifically open individual ports for Internet traffic to traverse one of the firewall's network interfaces to the corporate intranet) modern operating systems elevate privilege only when necessary. The firewall system of all ports closed, by default where the factory configuration prevents network traffic flowing from an untrusted to trusted network, also makes the device simple to configure. Issuing a command to open one or two ports is easier than trying to shut off hundreds of ports, leaving just a few open.

主站蜘蛛池模板: 随州市| 册亨县| 洪洞县| 丹凤县| 惠水县| 屏边| 竹山县| 郯城县| 东阳市| 乐东| 澄迈县| 尉氏县| 阳城县| 嘉义市| 贵港市| 黑河市| 鲜城| 金坛市| 韩城市| 清徐县| 泰安市| 阳东县| 乐都县| 藁城市| 祁阳县| 辽源市| 鄂伦春自治旗| 鞍山市| 华宁县| 民县| 沈阳市| 青阳县| 浦县| 疏勒县| 阿克| 文成县| 上虞市| 龙陵县| 会宁县| 云南省| 阳谷县|