...
首页> 外文期刊>International journal of computer science and network security >Privileged Account Management Approach for Preventing Insider Attacks
【24h】

Privileged Account Management Approach for Preventing Insider Attacks

机译:防止内部攻击的特权帐户管理方法

获取原文
   

获取外文期刊封面封底 >>

       

摘要

The companies gradually increase their safety precautions towards protecting their information systems, but the attackers simultaneously explore many different methods for breaching or bypassing the safety precautions. In this cycle, the attacks to information systems are expected from outside, and the cyber security investments are made in this parallel. As a result of this, the companies are caught unprepared for these conscious or unconscious breaches. In order to achieve their goals in insider attacks, the attackers attempt to seize the privileged accounts, which have much more authorizations on the information systems than the normal accounts. The reason for targeting the privileged account is that these accounts have wide authorizations on the information systems. IT personnel are responsible for realizing and managing the cyber security precautions within the company. In general, the IT personnel do the same mistake by adopting the general approach they expect the attacks from outsiders and ignore the insider threats. The most important one among these threats is the seizure of privileged accounts, which is used by the IT personnel every day, by the attackers. The measures to be taken for preventing the malicious use of privileged accounts and the approach to be adopted in order to increase awareness of IT personnel are discussed in this paper.
机译:这些公司逐渐增加其安全预防措施,以保护其信息系统,但攻击者同时探索了许多不同的方法来破坏或绕过安全预防措施。在这个周期中,预计会从外部对信息系统进行攻击,与此同时进行网络安全投资。结果,这些公司对这些有意或无意的违规行为没有做好准备。为了实现内部攻击的目标,攻击者试图夺取特权帐户,该特权帐户在信息系统上具有比普通帐户更多的授权。定位特权帐户的原因是,这些帐户在信息系统上具有广泛的授权。 IT人员负责在公司内部实现和管理网络安全预防措施。通常,IT人员采用一般的方法会犯同样的错误,他们期望外部人员会发动攻击,而忽略内部人员的威胁。在这些威胁中,最重要的一个就是夺取特权帐户,攻击者每天都会使用这些特权帐户。本文讨论了为防止特权帐户的恶意使用而采取的措施以及为提高IT人员的意识所采取的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号