发明授权
US08060937B2 System for protecting domain system configurations from users with local privilege rights 有权
具有本地特权权限的用户保护域系统配置的系统

System for protecting domain system configurations from users with local privilege rights
摘要:
A group change lockout system for protecting the configuration of a securable object in an operating system from members of a locally privileged group, such as the local administrators group, when a security descriptor exists for the securable object that includes a discretionary access control list (DACL). A copy of the security descriptor is made. Then a new access control entry (ACE) is added to the DACL in the copy. This new ACE specifies denying the local administrators group an access right to the securable object. Then the security descriptor in the operating system is overwritten with the copy.
信息查询
0/0