首页> 外文会议>34th Annual IEEE Computer Software and Applications Conference >Towards Secure Virtual Directories: A Risk Analysis Framework
【24h】

Towards Secure Virtual Directories: A Risk Analysis Framework

机译:迈向安全虚拟目录:风险分析框架

获取原文

摘要

Directory services are used by almost every enterprise computing environment to provide data concerning users, computers, contacts, and other objects. Virtual directories are components that provide directory services in a highly customized manner. Unfortunately, though the use of virtual directory services are widespread, an analysis of risks posed by their unique position and architecture has not been completed. We present a detailed analysis of six attacks to virtual directory services, including steps for detection and prevention. We also describe various categories of attack risks, and discuss what is necessary to launch an attack on virtual directories. Finally, we present a framework to use in analyzing risks to individual enterprise computing virtual directory instances. We show how to apply this framework to an example implementation, and discuss the benefits of doing so.
机译:几乎每个企业计算环境都使用目录服务来提供有关用户,计算机,联系人和其他对象的数据。虚拟目录是以高度定制的方式提供目录服务的组件。不幸的是,尽管虚拟目录服务的使用已经很广泛,但是对由其独特位置和体系结构构成的风险的分析尚未完成。我们对虚拟目录服务的六种攻击进行了详细分析,包括检测和预防步骤。我们还描述了各种类别的攻击风险,并讨论了对虚拟目录发起攻击所必需的操作。最后,我们提出了一个框架,用于分析对单个企业计算虚拟目录实例的风险。我们展示了如何将此框架应用于示例实现,并讨论了这样做的好处。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号