← กลับบทอ่าน5.IT Security Defense against the digital dark arts
T0685 · ข้อความต้นทางภาษาอังกฤษ
ไฟล์ transcript ต้นทาง · subtitle (36).txt
หน้านี้แสดงข้อความจากไฟล์ต้นทางที่ผู้ใช้ให้ไว้เพื่อเทียบแนวคิด คำอธิบายภาษาไทยในหนังสือเป็นการเรียบเรียงใหม่ ไม่ได้แปลข้อความนี้ทั้งไฟล์
Last but not least, the final A of the triple AAA's of security is accounting. This means keeping records of what resources and services your users access or what they did when they were using your systems. A critical component of this is auditing which involves reviewing these records to ensure that nothing is out of the ordinary. If we're watching and recording usage of our systems but never actually checking the usage data, that's not super useful. So what exactly do counting systems keep track of? Well, that depends on the purpose and intent of the system. For example, a TACACS+ server would be more concerned with keeping track of user authentication. What systems they authenticated to and what commands they ran during their session. This is because TACACS+ is a device access AAA system that manages who has access to your network devices and what they do on them. Cisco's AAA system supports accounting of individual commands executed connection to and from network devices. Commands executed in privileged mode and network services and system details like configuration reloads or reboots. Radius would track details like session duration, client location and bandwidth or other resources used during the session. This is because radius is a network access AAA system so it tracks details about network access and usage. Radius accounting kicks off with the network access server sending an accounting request packet to the accounting server that contains an event record to be logged. This starts the accounting session on the server. The server replies with an accounting response indicating that the message was received. The nass will continue sending periodic accounting messages with statistics of the session until an accounting stop packet is received. Radius accounting can be used for billing purposes by ISPs. Because it records the length of a session and the amount of data sent and received by the user. This data can also be used to enforce data or time quotas, limiting the duration of sessions or restricting the amount of data that can be sent or received. But this accounting information isn't detailed and won't contain specifics of what exactly the user did during the session. Information, like websites visited or what protocols were used aren't recorded.สารบัญบทอ่าน →