Windows NT Security
Cunsheng Ding HKUST, Hong Kong, CHINA
- C. Ding - COMP4631 - L20
1
Windows NT Security Cunsheng Ding HKUST, Hong Kong, CHINA C. Ding - - PowerPoint PPT Presentation
Windows NT Security Cunsheng Ding HKUST, Hong Kong, CHINA C. Ding - COMP4631 - L20 1 Agenda Brief information about Windows NT Security architecture Identification and authentication Access control Administration C. Ding -
1
2
4
5
6
Cache Manager Device drivers Virtual Memory Processes & Threads Security
PnP/Power
Manager I/O Manager
Hardware interfaces (read/write port, timers, clocks, cache control, etc.) Alerter WinLogon
User Application Subsystem DLLs OS/2
Services Applications
File systems Object management / Executive RTL Kernel Hardware Abstraction Layer (HAL)
User Mode System Threads Kernel Mode
Executive API Win32 NTDLL.DLL (NT Layer DLL that control NT system functions )
System Processes
Subsystems
7
8
9
10
11
12
13
14
15
16
17
18
Access token
19
20
21
22
23
24
25
26
27
28
29
30
31
32
Security ID:S-1-5-21-146... User Name: MichaelW Group IDs: Employees Scientists EVERYONE LOCAL INTERACTIVE Other Information: Security Descriptor Deny MichaelW All Allow Employees Read, Write Allow Scientists Execute Access Token File Object Access Control List
. . . . . .
Read
33
34
35
36
North Seals South Penguins RWXD RW X No access RWX RW No access Bob Alice Adelie Humboldt Magellan Bear Elephant Lion GLOBAL GROUPS LOCAL GROUPS
37
38
39
40
– In my PC, I have a power user account, and I can manage local resources in my PC.
41
42
43
44
45
46
47
48
49
50
51
52
53