二月二十三日是什么星座| 什么是元气| 什么器官分泌胰岛素| 女生下体长什么样| 系统性红斑狼疮是什么病| 女生下面长什么样| 精卫填海是什么意思| 吃什么食物能补钾| 女生适合喝什么茶| 属狗和什么属相最配| 治疗幽门螺旋杆菌的四联药是什么| 3.17是什么星座| 什么东西软化鱼刺最快| 去疤痕挂什么科| 衣带渐宽终不悔是什么意思| 敛财什么意思| 智商是什么| gg是什么牌子| 极有家是什么意思| 什么滔滔| 尿微量白蛋白高是什么原因| ada是什么意思| 治疗白头发挂什么科| 舌头发涩是什么原因造成的| 吃稀饭配什么菜好吃| 七月18日是什么星座| doosan挖掘机是什么牌子| 什么检查需要空腹| 月经推迟吃什么| 麦冬有什么功效| 胃病忌什么| 窦性心律不齐什么意思| 冠状动脉钙化是什么意思| 右边锁骨疼是什么原因| 喝什么解辣| 浑身瘙痒是什么原因| 甲状腺与甲亢有什么区别| 翌日是什么意思| 圣罗兰为什么叫杨树林| 盆腔b超检查什么| 拉屎不成形是什么原因| 精疲力尽是什么意思| 肝病晚期什么症状| 冲虎煞南是什么意思| 共青团书记是什么级别| 孕激素高是什么原因| 猜忌是什么意思| 乙酉日五行属什么| 南京市徽为什么是貔貅| 风湿挂什么科室| 甲字五行属什么| 鼻涕臭是什么原因| 甲状腺滤泡性肿瘤是什么意思| 挂钩疼挂什么科| 4月28日是什么日子| 肉丝炒什么好吃| 吃什么可以提升白细胞| 荆芥不能和什么一起吃| 耳石症是什么| 甲减长期服用优甲乐有什么危害| 脖子上为什么会长丝状疣| 肾功能三项检查什么| 有点想吐是什么原因| 男人什么时候精子最强| 清洁度111是什么意思| 梦见很多虫子是什么意思| 肠镜前一天可以吃什么| 2月2号是什么星座| 儿童内分泌科检查什么| 急性会厌炎吃什么药| 什么是soho| 看颈椎挂什么科| 多囊卵巢综合征是什么意思| 蒜薹和蒜苔有什么区别| 每天早上起来口苦是什么原因| 吃什么对肺有好处| 编外人员是什么意思| 靶点是什么意思| 宫颈阳性是什么意思| 儒艮为什么叫美人鱼| 打更是什么意思| 不加要是什么字| 拍身份证穿什么颜色衣服| 巨蟹座喜欢什么星座| 苹果熬水喝有什么功效| 失眠吃什么药| 藜麦是什么东西| 什么样的天安门| 身上到处痒是什么原因| 悔教夫婿觅封侯是什么意思| 梦见打老公是什么意思| 枸杞加什么泡水喝壮阳| 法院院长是什么级别| 中药不能和什么一起吃| 贤上腺瘤是什么意思| 外感风热是什么意思| 琥珀五行属什么| 什么是脑白质病变| 尿路感染用什么药| 蚧壳虫用什么药最有效| 中国信什么教| 一毛不拔指什么生肖| 隐翅虫咬人后用什么药| 流鼻涕咳嗽吃什么药| 语重心长是什么意思| 蛇什么时候出来活动| 蚊子最怕什么植物| 什么都不是| 甲状腺是什么病严重吗| 静置是什么意思| 黑眼袋是什么原因引起的| 拔得头筹是什么意思| 今年什么时候进伏天| 小狗的耳朵像什么| 寻常疣是什么原因造成的| 尿酸高能吃什么水果| 生死劫是什么意思| 羊水穿刺检查什么| 荔枝有什么营养| 小人痣代表什么意思| 怀孕了胃不舒服是什么原因| 做肠镜检查什么| 臣字五行属什么| 真数是什么| 三有动物是什么意思| 小孩子腿疼是什么原因| 生姜泡醋有什么功效| 中暑喝什么好| 五四运动是什么| 牟利什么意思| 狗女和什么属相最配| sb是什么元素符号| 头疼吃什么| 水里有什么| 乌龙茶是什么茶| 脑供血不足吃什么药最好| 低钾吃什么药| 弱智的人有什么表现| 纪梵希属于什么档次| 有机可乘是什么意思| 睡觉为什么会打呼噜| 嗳气什么意思| 七月种什么菜| 风起云涌是什么意思| 精神病是什么意思| 空腹血糖受损是什么意思| 霍乱时期的爱情讲的是什么| 女人肾虚吃什么药调理| 大油边是什么| 正常白带是什么颜色| 腊肉炒什么最好吃| 身体缺钾会有什么症状| 浑身麻是什么原因| 明天代表什么生肖| 农历十月初八是什么星座| 甘薯和红薯有什么区别| 南京鸡鸣寺求什么灵| 腰酸痛挂什么科| 肩周炎吃什么药| 洗葡萄用什么洗最干净| 梦见和死去的人说话是什么意思| 新鲜的乌梅长什么样| om是什么意思| 四肢发麻是什么原因| 右肾肾盂分离什么意思| 3月6日是什么星座| 凉栀是什么意思| 斜视是什么意思| 什么中药补气血效果最好| 乘载和核载是什么意思| 安哥拉树皮有什么功效| 单人旁的字和什么有关| 酸奶有什么好处| 治疗荨麻疹用什么药最好| 结婚前要准备什么| 卵磷脂什么牌子好| 家徒四壁是什么生肖| 元五行属性是什么| 什么人不穿衣服| 男人有霉菌是什么症状| 动物的尾巴有什么用处| 五代十国是什么意思| 冰箱什么品牌好| 没有什么| 晚上睡觉口干是什么原因| 肛门不舒服是什么原因| 二次元文化是什么意思| 子宫肌瘤吃什么药好| 阳光灿烂是什么意思| 未央什么意思| 但闻人语响的但是什么意思| 月经来有血块是什么原因| 羊和什么生肖最配| 药品经营与管理学什么| 什么的脚| 做梦笑醒了有什么征兆| 什么钻进风箱里两头受气| 脾胃虚弱吃什么食物好| 关节痛挂号挂什么科| 为什么怀孕会孕酮低| 惨无人道是什么意思| 胆总管结石有什么症状| 超声检查是什么| 棕色裤子配什么颜色上衣| 什么猫| 耳石症是什么引起的| 怀孕是什么脉象| 一库一库雅蠛蝶是什么意思| 去肝火喝什么茶好| 吃什么补蛋白质| 1月23日是什么星座| 掉头发缺少什么维生素| 同比什么意思| 海带和什么不能一起吃| 生日礼物送什么| 两横一竖是什么字| 软肋骨炎吃什么药对症| 吃什么补骨髓造血| 姜枣茶什么时间喝最好| 梦见换房子是什么预兆| 天妇罗是什么| 吃什么食物可以去湿气| 什么叫释怀| 梦见龙是什么意思| 医院特需号是什么意思| 32周岁属什么生肖| 有什么有什么四字词语| 京东什么时候优惠最大| 梦见皮带断了什么预兆| 男人右眉毛里有痣代表什么| 膝盖后面的窝叫什么| 女性私处为什么会变黑| 尿蛋白高是什么意思| 腿毛长得快是什么原因| 肚子疼吃什么药管用| 经常做春梦是什么原因| 换肾是什么病| 为什么现在不吃糖丸了| 低盐饮食有利于预防什么疾病| 血钾查什么项目| 什么情况属于骗婚| 什么蔬菜| 神经衰弱吃什么药效果最好| 女人严重口臭挂什么科| 肌酐偏高是什么意思| 男士阴囊湿疹用什么药膏| 手心脱皮是什么原因| mcm是什么意思| 九宫是什么意思| 下午6点半是什么时辰| 一般什么原因做宫腔镜| 尿中有泡沫是什么原因| 为什么狱警离婚率高| 00年属龙的是什么命| 武夷岩茶属于什么茶| 总胆汁酸高是什么意思| 有点想吐是什么原因| 结核感染是什么意思| 方脸适合什么发型| 陪跑什么意思| 脚有酸臭味是什么原因| 松花粉有什么功效| 牙痛吃什么药| 梅长苏是什么电视剧| 百度Jump to content

中国石化2017年实现净利511亿元 同比增一成

From Wikipedia, the free encyclopedia
百度 兴实业通过一把绿色加油枪,李克强总理为装配线上一辆红色重型卡车的油箱加满了油。

In computing, privilege is defined as the delegation of authority to perform security-relevant functions on a computer system.[1] A privilege allows a user to perform an action with security consequences. Examples of various privileges include the ability to create a new user, install software, or change kernel functions.

Users who have been delegated extra levels of control are called privileged. Users who lack most privileges are defined as unprivileged, regular, or normal users.

Theory

[edit]

Privileges can either be automatic, granted, or applied for.

An automatic privilege exists when there is no requirement to have permission to perform an action. For example, on systems where people are required to log into a system to use it, logging out will not require a privilege. Systems that do not implement file protection - such as MS-DOS - essentially give unlimited privilege to perform any action on a file.

A granted privilege exists as a result of presenting some credential to the privilege granting authority. This is usually accomplished by logging on to a system with a username and password, and if the username and password supplied are correct, the user is granted additional privileges.

A privilege is applied for by either an executed program issuing a request for advanced privileges, or by running some program to apply for the additional privileges. An example of a user applying for additional privileges is provided by the sudo command to run a command as superuser (root) user, or by the Kerberos authentication system.

Modern processor architectures have multiple CPU modes that allows the OS to run at different privilege levels. Some processors have two levels (such as user and supervisor); i386+ processors have four levels (#0 with the most, #3 with the least privileges). Tasks are tagged with a privilege level. Resources (segments, pages, ports, etc.) and the privileged instructions are tagged with a demanded privilege level. When a task tries to use a resource, or execute a privileged instruction, the processor determines whether it has the permission (if not, a "protection fault" interrupt is generated). This prevents user tasks from damaging the OS or each other.

In computer programming, exceptions related to privileged instruction violations may be caused when an array has been accessed out of bounds or an invalid pointer has been dereferenced when the invalid memory location referenced is a privileged location, such as one controlling device input/output. This is particularly more likely to occur in programming languages such as C, which use pointer arithmetic or do not check array bounds automatically.

Criticism

[edit]

Mark Miller has critiqued the framing of privilege as being poorly defined and hard to measure, and suggested that authority can be defined as the set of things a program can do, which is more helpful.[2]

Unix

[edit]

On Unix-like systems, the superuser (commonly known as 'root') owns all the privileges. Ordinary users are granted only enough permissions to accomplish their most common tasks. UNIX systems have built-in security features. Most users cannot set up a new user account nor do other administrative procedures. The user “root” is a special user, something called super-user, which can do anything at all on the system. This high degree power is necessary to fully administer a UNIX system, but it also allows its user to make a mistake and cause system problems.

Unprivileged users usually cannot:

  • Adjust kernel options;
  • modify system files, or files of other users.
  • change the ownership of any files;
  • change the runlevel (on systems with System V-style initialization);
  • change the file mode of any files;
  • adjust ulimits or disk quotas;
  • start, stop and remove daemons;
  • signal processes of other users;
  • create device nodes;
  • create or remove users or groups;
  • mount or unmount volumes (although it is becoming common to allow regular users to mount and unmount removable media, such as compact discs - this is typically accomplished via FUSE);
  • execute the contents of any sbin/ directory (although it is becoming common to simply restrict the behavior of such programs when executed by regular users);
  • bind ports below 1024.

Windows NT

[edit]

On Windows NT-based systems, privileges are delegated in varying degrees. These delegations can be defined using the local security policy manager (secpol.msc). The following is an abbreviated list of the default assignments:

  • 'NT AUTHORITY\System' is the closest equivalent to the Superuser on Unix-like systems. It has many of the privileges of a classic Unix superuser (such as being a trustee on every file created);
  • 'Administrator' is one of the closest equivalents to the superuser (root) on Unix-like systems. However, this user cannot override as many of the operating system's protections as the superuser can;
  • members of the 'Administrators' group have privileges almost equal to 'Administrator';
  • members of the 'Power Users' group have the ability to install programs and backup the system.
  • members of the 'Users' group are the equivalent to unprivileged users on Unix-like systems.

Windows defines a number of administrative privileges[3] that can be assigned individually to users and/or groups. An account (user) holds only the privileges granted to it, either directly or indirectly through group memberships. Upon installation a number of groups and accounts are created and privileges are granted to them. However, these grants can be changed at a later time or though a group policy. Unlike Linux, no privileges are implicitly or permanently granted to a specific account.

Some administrative privileges (e.g. taking ownership of or restoring arbitrary files) are so powerful that if used with malicious intent they could allow the entire system to be compromised. With user account control (on by default since Windows Vista) Windows will strip the user token of these privileges at login. Thus, if a user logs in with an account with broad system privileges, he/she will still not be running with these system privileges. Whenever the user wants to perform administrative actions requiring any of the system privileges he/she will have to do this from an elevated process. When launching an elevated process, the user is made aware that his/her administrative privileges are being asserted through a prompt requiring his/her consent. Not holding privileges until actually required is in keeping with the principle of least privilege.

Elevated processes will run with the full privileges of the user, not the full privileges of the system. Even so, the privileges of the user may still be more than what is required for that particular process, thus not completely least privilege.

The DOS-based Windows ME, Windows 98, Windows 95 and previous versions of non-NT Windows only operated on the FAT filesystem, did not support filesystem permissions[4] and therefore privileges are effectively defeated on Windows NT-based systems that do not use the NTFS file system.

Nomenclature

[edit]

The names used in the Windows source code end in either "privilege" or "logonright". This has led to some confusion about what the full set of all these "rights" and "privileges" should be called.

Microsoft currently uses the term "user rights".[5] In the past some other terms have also been used by Microsoft, such as "privilege rights"[6] , "logon user rights"[7] and "nt-rights".[8]

See also

[edit]

References

[edit]
  1. ^ "Glossary". CSRC. NIST. Archived from the original on 13 February 2019. Retrieved 12 February 2019.
  2. ^ Miller, Mark (2006). Robust Composition: Towards a Unified Approach to Access Control and Concurrency Control. PhD Theses. Johns Hopkins University.
  3. ^ "Privilege constants". Microsoft. 7 April 2022.
  4. ^ "How permissions work". Microsoft. 3 July 2013. You can set permissions at the file level only if the files are stored on an NTFS volume.
  5. ^ "User rights". Microsoft TechNet library. 18 June 2014. Userrights include logon rights and privileges.
  6. ^ "Privilege rights". Microsoft MSDN library. 23 April 2024.
  7. ^ "How to set logon user rights by using the ntrights utility". Microsoft support.
  8. ^ "How to set logon user rights by using the ntrights utility". Microsoft support.
新生儿白细胞高是什么原因 执业药师证有什么用 尿蛋白阴性是什么意思 惠五行属什么 外感风寒是什么意思
喉咙发炎吃什么消炎药 空调自动关机什么原因 寒战是什么症状 2010年是什么命 降尿酸吃什么药
烂尾是什么意思 人心不足蛇吞象是什么意思 每天喝牛奶有什么好处 改户口需要什么手续 hpv都有什么症状
一般手脚慢进什么工厂 吃薄荷叶有什么好处和坏处 银行卡开户名是什么 气血不足看什么科室 脓毒血症是什么病
2月22是什么星座hcv8jop2ns7r.cn 喉咙痛吃什么药hcv9jop1ns1r.cn 流产是什么样子的520myf.com 造影检查是什么意思hcv7jop4ns8r.cn 喝酒手掌发红是什么原因hcv7jop6ns6r.cn
一月7日是什么星座hcv8jop8ns6r.cn 冬天送什么礼物hcv9jop7ns5r.cn 龙肉指的是什么肉hcv9jop4ns5r.cn 乾隆为什么不喜欢雍正hcv9jop5ns2r.cn 五光十色是什么意思wzqsfys.com
肾上腺彩超是检查什么hcv9jop1ns3r.cn 下肢静脉曲张是什么原因引起的dayuxmw.com 德不配位是什么意思hcv9jop1ns9r.cn 土豆与什么食物相克hcv9jop2ns1r.cn 五味是什么helloaicloud.com
准妈妈是什么意思hcv8jop9ns4r.cn 黑色加什么颜色是棕色hcv9jop5ns8r.cn 什么和什么hcv8jop0ns4r.cn 531是什么意思hcv7jop9ns2r.cn 托人办事送什么礼物较好hcv9jop5ns0r.cn
百度