2009年3月20日星期五

轉 Security Concept R

R.

RAT遠端存取特洛伊木馬程式
RAT是利用網路遠端控制他人電腦的惡意程式,駭客可藉由此木馬程式侵入被害電腦進其犯罪行為,如監視、竊取機密資料、變更資料等。

relay轉寄
轉寄,是指主機電腦轉發信件的功能。當主機電腦提供轉寄服務時,使用者可以透過電腦使用轉寄信件給其他人,但是企業多半會在主機提供轉寄服務的同時,也設定了轉發位址的限制,以避免企業的主機電腦成為廣告郵件濫發的轉寄站。

remote control遠端控制
遠端遙控是指利用別處的電腦連線至某電腦進行操作,例如課堂上教師遙控學生電腦。而遠端遙控的作法也常被駭客濫用成犯罪工具,譬如駭客會籍由植入木馬程式遙控受害人電腦。

rounding Down去尾法
與『薩拉米技術』同屬駭客竊取財務的犯罪手法,常被利用於財務資料的犯罪中。『去尾法』的犯罪方式是將數字四捨五入至最小整數後,才竊取其小數點後的尾數。因竊取的金額很小,交易單位不易發現,駭客可藉此將這些金額竊取轉至犯罪者的帳戶中。

补充:


reference monitor

the reference monitor is an abstract machine that mediates all access subject have to objects, both to ensure that the subjects have the necessary access rights and to protect the objects from unauthorized access and destructive modification. For a system to achieve a higher level of trust, it must require subjects( programs , users, or processes) to be fully authorized prior to accessing an object( file, program, or resource). A subject must not be allowed to use a requested resource until the subject has proven it has been granted access privileges to use the requested object. the reference monitor is an access control concept, not an actual physical component, which is why it is normally referred to as the "reference monitor concept" or an "abstract machine".

--cissp all in one 4th



没有评论:

发表评论