Study of automatic revoking of operation authorities
摘要
传统用户权限管理缺乏灵活性
未对所分配权限进行闭环验证
从而易出现用户权限过大的情况。本文基于用户操作日志及网元操作权限分析
提出一种网元操作权限自动调整方案。利用本方案
实现了对用户操作网元所需权限的客观评估
并可自动回收不必要的高级权限
对于减少高危指令误操作及重点网元操作权限被滥用造成的网络安全事故具有重大的现实意义。
Abstract
Traditionally
operation authorities of net elements are lack of flexibility. After an account is created
the authority will not be verified by closed-loop tests. This paper introduces a scheme to adjust the authority according to the operation log and the operation authority. With the scheme
the authority needed will be objectively evaluated and the unnecessary authority will be revoked. Thus the misuse of operation authorities will be reduced. This has great practical significance to prevent the occurrence of network security events.