Security Enhanced LinuxµÄÀúÊ·
Ò»¸öСÀúÊ·½«ÓÐÖúÓÚ°ïÖúÄúÀí½â Security-Enhanced Linux£¨SELinux£©——¶øÇÒËü±¾ÉíÒ²ÊǶÎÓÐȤµÄÀúÊ·¡£
ÃÀ¹ú¹ú¼Ò°²È«¾Ö
£¨National
Security
Agency£¬NSA£©³¤Ê±¼äÒÔÀ´¾Í¹Ø×¢´ó²¿·Ö²Ù×÷ϵͳÖÐÊÜÏ޵ݲȫÄÜÁ¦¡£±Ï¾¹£¬ËûÃǵŤ×÷Ö®Ò»¾ÍÊÇҪȷ±£ÃÀ¹ú¹ú·À²¿Ê¹ÓõļÆËã»úÔÚÃæÁÙûÍêûÁ˵Ĺ¥»÷ʱ
±£³Ö°²È«¡£NSA ·¢Ïִ󲿷ֲÙ×÷ϵͳµÄ°²È«»úÖÆ£¬°üÀ¨ Windows ºÍ´ó²¿·Ö UNIX ºÍ Linux ϵͳ£¬Ö»ÊµÏÖÁ˓ѡÔñÐÔ·ÃÎÊ¿ØÖÆ
£¨discretionary access control£©”£¨DAC
£©»úÖÆ¡£DAC »úÖÆÖ»ÊǸù¾ÝÔËÐгÌÐòµÄÓû§µÄÉí·ÝºÍÎļþµÈ¶ÔÏóµÄËùÓÐÕßÀ´¾ö¶¨³ÌÐò¿ÉÒÔ×öʲô¡£NSA ÈÏΪÕâÊÇÒ»¸öÑÏÖØµÄÎÊÌ⣬ÒòΪ DAC ±¾Éí¶Ô´àÈõµÄ»ò¶ñÒâµÄ³ÌÐòÀ´ËµÊÇÒ»¸ö²»ºÏ¸ñµÄ·À»¤Õß¡£È¡¶ø´úÖ®µÄ£¬NSA ³¤ÆÚÒÔÀ´Ò»Ö±Ï£Íû²Ù×÷ϵͳͬÑùÄÜÖ§³Ö“Ç¿ÖÆ·ÃÎÊ¿ØÖÆ
£¨mandatory access control£©”£¨MAC
£©»úÖÆ¡£
MAC
»úÖÆÊ¹µÃϵͳ¹ÜÀíÔ±¿ÉÒÔ¶¨ÒåÕû¸öϵͳµÄ°²È«²ßÂÔ£¬Õâ¸ö²ßÂÔ¿ÉÒÔ»ùÓÚÆäËûÒòËØ£¬ÏñÊÇÓû§µÄ½ÇÉ«¡¢³ÌÐòµÄ¿ÉÐÅÐÔ¼°Ô¤ÆÚʹÓᢳÌÐò½«ÒªÊ¹ÓõÄÊý¾ÝµÄÀàÐ͵ȵȣ¬À´
ÏÞÖÆ³ÌÐò¿ÉÒÔ×öÄÄЩÊÂÇé¡£Ò»¸öСÀý×Ó£¬ÓÐÁË MAC
ºóÓû§²»ÄÜÇáÒ׵ؽ«“±£Ãܵģ¨Secret£©”Êý¾Ýת»¯Îª“²»±£Ãܵģ¨Unclassified£©”µÄÊý¾Ý¡£²»¹ý£¬MAC
ʵ¼ÊÉÏ¿ÉÒÔ×öµÄ±ÈÄÇÒª¶àµÃ¶à¡£
NSA ÒѾÓë²Ù×÷ϵͳÌṩÉ̺Ï×÷Á˶àÄ꣬µ«ÊǺܶàÕ¼ÓÐ×î´óÊг¡µÄÌṩÉ̶ÔÓÚ½« MAC ¼¯³É½øÀ´Ã»ÓÐÐËȤ¡£¼´Ê¹ÊÇÄÇЩ¼¯³ÉÁË MAC µÄÌṩÉÌҲͨ³£Êǽ«Æä×öΪ“µ¥¶ÀµÄ²úÆ·”£¬¶ø²»Êdz£¹æ²úÆ·¡£Ò»²¿·ÖÔÒòÖ»ÊÇÒòΪ¾ÉʽµÄ MAC ²»¹»Áé»î¡£
ÓÚÊÇ
NSA µÄÑо¿Á¦Á¿¾¡Á¦È¥Ê¹ MAC ¸üÁé»î²¢ÇÒ²¢ÈÝÒ×±»°üº¬ÔÚ²Ù×÷ϵͳÖС£ËûÃÇʹÓà Mach
²Ù×÷ϵͳ¿ª·¢ÁËËûÃǵÄ˼ÏëµÄÔÐÍ£¬ºóÀ´·¢ÆðµÄ¹¤×÷À©Õ¹ÁË“Fluke”Ñо¿²Ù×÷ϵͳ¡£²»¹ý£¬ÄÑÒÔÈÃÈËÃÇÐÅ·þÕâЩ˼Ïë¿ÉÒÔÊÊÓÃÓÚ “ÕæÊµµÄ”²Ù×÷ϵͳ
£¬ÒòΪËùÓÐÕâЩ¹¤×÷¶¼»ùÓÚ΢ÐÍµÄ“Íæ¾ß¼¶µÄ”Ñо¿ÏîÄ¿¡£¼«ÉÙ¿ÉÒÔÔÚÔÐÍÖ®Íâ½øÐг¢ÊÔÒԲ鿴ÕâЩ˼ÏëÔÚÕæÊµµÄÓ¦ÓóÌÐòÖй¤×÷µÃÈçºÎ¡£NSA
²»ÄÜ˵·þ¾ßÓÐËùÓÐȨµÄÌṩÉÌÀ´Ìí¼ÓÕâЩ˼Ï룬¶øÇÒ NSA ҲûÓÐȨÀûÈ¥ÐÞ¸Ä˽ÓеIJÙ×÷ϵͳ¡£Õâ²»ÊǸöÐÂÎÊÌ⣻¶àÄêǰ DARPA
ÊÔÍ¼Ç¿ÖÆËüµÄ²Ù×÷ϵͳÑо¿ÈËԱʹÓÃ˽ÓеIJÙ×÷ϵͳ Windows£¬µ«Óöµ½Á˺ܶàÎÊÌâ¡£
ÓÚÊÇ£¬NSA żȻ·¢ÏÖÁËÒ»¸ö»ØÏëÆðÀ´ËƺõÏÔ¶øÒ×¼ûµÄÏë·¨£ºÊ¹ÓÃÒ»¸ö²»ÊÇ Íæ¾ßµÄ¿ª·ÅÔ´´úÂë²Ù×÷ϵÍ
Ïà¹ØÎĵµ£º
<!--
@page { margin: 2cm }
P { margin-bottom: 0.21cm }
-->
Ò»°ã˵À´£¬
Linux
ÉçÇø°æ×ÜÓеã¶ù´ÕºÏµÄÒâ˼£¬ÈËÃDz»¸ÒʹÓ㬵«ÊÇ£¬Ò²ÓÐÀýÍâµÄÇé¿ö¡£±ÈÈ磬¹ÚÃûΪ
Mint
µÄ
Linux
·¢Ðа档¾ßÌåÇé¿öÊÇÔõÑùµÄÄØ£¿
......
java µÄconnectÓÐtimeoutÕâ¸ö¹¦ÄÜ£¬C++µÄconnect·´¶øÃ»ÓУ¿ Íø²éµÃµ½ÁËÁ½¸öʵÏֵİ汾ÈçÏ£º
Ö§³ÖtimeoutµÄconnect() / Connect with timeout
Code:
void connect_w_to(void) {
int res;
struct sockaddr_in addr;
long arg;
fd_set myset;
struct timeval tv;
int valopt;
socklen_t ......
¡¡¡¡Ð´ÁËÕ⼸Äê³ÌÐò£¬Í»È»×ªµ½linuxÏ£¬Í»È»¸Ðµ½×Ô¼º»¹ÒªÑ§µÄÌ«¶à¡£
¡¡¡¡1¡£linuxµÄÃüÁºÃ¶à....
2. Ì«¶àµÄIDE£¬²»ÖªµÀ¾¿¾¹Äĸö²ÅÕæÕýºÃʹ£¬ÔÝʱÓÃeclicpes°É£¬¾Ý˵ºÜÏóVS¡£
¡¡¡¡3. VMWAREϵÄlinux,¡¡ÏÔ¿¨¾¹È»×°²»ºÃ£¬Ìý˵µ½×°VTOOLS,£¬µ«Ã»ÕÒµ½ºÃÓõġ£
¡¡¡¡4¡¡³ýÁËMSµÄ ......
¿É°²×°ÔÚUÅÌÉϵIJÙ×÷ϵͳ Puppy Linux 4.1 Beta
Ò»¡¢ UÅ̰²×°Puppy Linux·½·¨
1¡¢ÏÂÔØ°²×°FlashBoot¡£¿ÉÒÔÔÚgoogleÉÏËÑÒ»ÏÂÏÂÔØ
ÔËÐÐFlashBoot£¬°´ÏÂͼºìÉ«¿òÑ¡Ôñ£¬µã¡¾ÏÂÒ»²½¡¿
Ñ¡ÔñÄãÏÂÔØµÄiso¾µÏñ£¬¡¾ÏÂÒ»²½¡¿
Ñ¡ÔñÄãµÄUÅÌÅÌ·û£¬²»ÒªÑ¡´íÁË¡£µã¡¾ÏÂÒ»²½¡¿
ÕâÒ»²½Òª×¢Ò⣬ĬÈÏÑ¡ÔñµÄÊDz»¸ñÅÌ¡£ ......