Russell Smith's Least Privilege Security for Windows 7, Vista, and XP (LPS) is a helpful contribution to the toolbox of many enterprise system administrators. Numerous organizations are finally realizing that the Internet is too hostile an environment to let normal users function with elevated privileges. Although by no means a panacea for preventing intrusions, users operating with least privilege are somewhat more able to resist some attack vectors. Beyond resisting attacks, users operating with least privilege are more likely to meet organizational rules. Thanks to LPS, administrators running Windows 7, Vista, and XP can apply the author's lessons and guidance to their own environment.
I liked LPS because it applies to Windows 7, Vista, and XP. This really reflects the range of environments one is likely to encounter in the real world. (I still see Windows 2000 and even some NT, but those should be considered targets for decommissioning, not new life using least privilege!) The author does not assume that implementing least privilege is a foregone conclusion. He devotes an entire chapter to cultural and political objections to removing local administrator rights. Most chapters present a variety of tools and techniques to accomplish similar goals. The text is also very thorough, with dozens of checklists and supporting screen captures. I also appreciated hearing about several technologies which were fairly new to me, such as DirectAccess, Windows Remote Management (WinRM, Microsoft's version of WS-Management Protocol), Windows Remote Assistance and Easy Connect, and Microsoft's Internet Connectivity Evaluation Shell. The thought of Remote Desktop Protocol over HTTPS through TS Gateways, from the Internet straight to corporate desktops, horrified me.
My main problem with LPS (hence the loss of one star) involved framing the discussions in each chapter. I didn't quite follow some of the material (such as chapter 3). The author seemed too quick to jump to describing an implementation. I could have used more background on the technology and the problem it was trying to solve. However, I felt that it was likely many readers would already know the problem they needed to solve, and Smith's approach would deliver the content fairly well.
I recommend LPS to readers trying to better protect their enterprise, but be sure to include stronger warnings about the limitations of least privilege. Many instances of modern malware are happy to operate with least privilege constraints, so consider improved configuration as one element of a comprehensive security strategy.
Kindle电子书价格: | ¥349.88 |

下载免费的 Kindle 阅读软件,即可立即在智能手机、平板电脑或电脑上阅读 Kindle 电子书 - 无需 Kindle 设备。了解更多信息
使用 Kindle 网页版即时在浏览器上阅读。
使用手机摄像头 - 扫描以下代码并下载 Kindle 阅读软件。
![“Least Privilege Security for Windows 7, Vista and XP (English Edition)”,作者:[Russell Smith]](https://images-cn.ssl-images-amazon.cn/images/I/51SQ-gaeTeL._SX260_.jpg)
Least Privilege Security for Windows 7, Vista and XP (English Edition) Kindle电子书
无评论
|
广告
This practical handbook has detailed step-by-step instructions for implementing Least Privilege Security and related management technologies. It has solutions to the most common technical challenges and Microsoft best practice advice. It also covers techniques for managing Least Privilege on the desktop. This book is for System Administrators or desktop support staff who want to implement Least Privilege Security on Windows systems.
- ISBN-13978-1849680042
- 出版社Packt Publishing
- 出版日期2010年7月5日
- 语言英语
- 文件大小54337 KB
由于文件较大,下载时间可能较长。
Kindle Fire 平板电脑
基本信息
- ASIN : B005OY7S2U
- 出版社 : Packt Publishing (2010年7月5日)
- 出版日期 : 2010年7月5日
- 语言 : 英语
- 文件大小 : 54337 KB
- 标准语音朗读 : 已启用
- X-Ray : 未启用
- 生词提示功能 : 未启用
- 纸书页数 : 464页
无买家评论
5 星 (0%) |
|
0% |
4 星 (0%) |
|
0% |
3 星 (0%) |
|
0% |
2 星 (0%) |
|
0% |
1 星 (0%) |
|
0% |
评分是如何计算的?
在计算总星级评分以及按星级确定的百分比时,我们不使用简单的平均值。相反,我们的系统会考虑评论的最新程度以及评论者是否在亚马逊上购买了该商品。系统还会分析评论,验证评论的可信度。
此商品在美国亚马逊上最有用的商品评论
美国亚马逊:
4.0 颗星,最多 5 颗星
2 条评论

Richard Bejtlich
4.0 颗星,最多 5 颗星
Very focused and timely book on an important security topic
2010年8月23日 -
已在美国亚马逊上发表5 个人发现此评论有用

EDWARD ARACTINGI
4.0 颗星,最多 5 颗星
Good resource for Windows security professionals
2013年2月26日 -
已在美国亚马逊上发表
This book covers Microsoft latest operating systems from the perspective of security and specifically the least privilege security of Windows. It provides a historical background of the principle from Windows 9.x until windows 7, It also discusses the different types of access controls (DAC, MAC, MIC, and RBAC). The book provides some workarounds fixes to solve issues around compatibility issues and LUA problems and hot to configure software distribution, run support accounts with elevated privilege and best practices in using Internet Explorer and ActiveX. Overall, the book is a great resource for security professionals especially those managing environment with Windows operating systems.