Access control and least privilege · 접제어 및 최소 권한
Least privilege
- A core security rule: give every person and program only the access they need — no more.
- If an account is broken into, least privilege means the attacker can reach less.
최소 권한 원칙
- 핵심 보안 규칙입니다. 모든 사람과 프로그램에게 필요한 접근권만 제공하십시오 — 그 이상은 금지합니다.
- 계정이 해킹당했을 때 최소 권한 원칙은 공격자가 도달할 수 있는 범위를 줄여줍니다.
Access control on files
- On Linux, file permissions are access control in action (you met these in the Linux course).
ls -lshows who can read, write, and execute, for the owner, the group, and everyone else.
파일 접근 제어
- 리눅스에서의 파일 권한은 접근 제어가 실제로 작동하는 모습입니다(리눅스 수업에서 이 내용을 접하셨을 것입니다).
ls -l는 소유자, 그룹, 그리고 기타 모든 사람에게 read(읽기), write(쓰기), execute(행) permission을 나타냅니다.
ls -l secret.txt
Locking down a secret
- A file holding a password or key should be readable by its owner only.
chmod 600gives the owner read+write, and nothing to anyone else:
6= read+write for the owner;0and0= no access for group and others.
비밀 정보 잠금
- 비밀번호나 키를 포함하는 파일은 소유자만 읽을 수 있어야 합니다.
chmod 600는 소유자에게 읽기+쓰기权限을 부여하고, 다른 누구에게는什么都没有:
chmod 600 secret.txt
6= 소유자의 읽기+쓰기;0와0= 그룹 및 기타用户对无访问权限。
Your turn
- Lock down
secret.txtso only its owner can touch it. Good permissions are a simple, powerful defence.
Covers: A-Level 6.1 (access levels / security measures).
직접 해보기
secret.txt를 잠그어 소유자만이 접근할 수 있도록 하십시오. 올바른 권한 설정은 간단하지만 강력한 방어 수단입니다.
내용: A-Level 6.1 (접근 수준 / 보안 조치).
Common mistakes
- Give each user only the access they need (least privilege).
- Do not use an administrator account for everyday work.
흔한 실수
- 각 사용자에게 필요한 접근권만 제공하십시오(최소 권한 원칙).
- 일상적인 업무 시 관리자 계정을 사용하지 마십시오.
Least privilege · 최소 권한
Give each user only the rwx they need — nothing more. · 각 사용자에게 필요한 rwx만 제공하세요 — 더 이상은 필요 없습니다.
secret.txt is currently readable by everyone. Lock it down so only its owner can read and write it, with chmod 600 secret.txt. The check shows ls -l. · secret.txt은 현재 모든 사람이 읽을 수 있습니다. chmod 600 secret.txt으로 잠그어 오직 소유자만이 읽고 쓸 수 있도록 하세요.检查结果는 ls -l입니다.
Least privilege is not always 600. Your team should read team-notes.txt, but not change it — and outsiders get nothing. Use chmod 640 team-notes.txt (6 = owner read+write, 4 = group read-only, 0 = others none). · 최소 권한이 항상 600은 아닙니다. 팀원은 team-notes.txt을 읽을 수 있어야 하지만 변경해서는 안 되며, 외부인은 아무것도 할 수 없어야 합니다. chmod 640 team-notes.txt을 사용하세요 (6 = 소유자 읽기+쓰기, 4 = 그룹 읽기 전용, 0 = 기타 없음).