wrjc1hod 发表于 2024-10-5 03:04:25

一项一项教你测等保2.0——Apache Tomcat中间件


    <h1 style="color: black; text-align: left; margin-bottom: 10px;"><span style="color: black;">1、</span>前言</h1>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">今天<span style="color: black;">咱们</span><span style="color: black;">来讲</span>说中间件Apache Tomcat,为了方便,<span style="color: black;">咱们</span>查看的是phpStudy环境下的Apache Tomcat中间件,这个比较简单<span style="color: black;">咱们</span><span style="color: black;">能够</span>在网上搜索下载phpStudy安装文件,自己搭建环境,这个非常简单,就像安装普通软件<span style="color: black;">同样</span>,安装完成后运行环境,需要<span style="color: black;">重视</span>的是,<span style="color: black;">保准</span>所用服务都开启正常,如下图所示:</p>
    <div style="color: black; text-align: left; margin-bottom: 10px;"><img src="https://p3-sign.toutiaoimg.com/tos-cn-i-qvj2lq49k0/dc9e2010450f421e8f72ef68e6ad44dc~noop.image?_iz=58558&amp;from=article.pc_detail&amp;lk3s=953192f4&amp;x-expires=1728294546&amp;x-signature=Ku6NLn7baGN%2BbRBrNxNCyLN%2FWH8%3D" style="width: 50%; margin-bottom: 20px;">
      <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">phpStudy</p>
    </div>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">平常</span>的问题<span style="color: black;">便是</span><span style="color: black;">由于</span>80端口被占用,而<span style="color: black;">引起</span>Apache服务<span style="color: black;">没法</span><span style="color: black;">起步</span>,<span style="color: black;">这儿</span><span style="color: black;">咱们</span>点击“其它选项菜单”,找到“phpStudy设置”-“端口常规设置”,如下图所示:</p>
    <div style="color: black; text-align: left; margin-bottom: 10px;"><img src="https://p3-sign.toutiaoimg.com/tos-cn-i-qvj2lq49k0/ba93e606e0b04e759dd0522b0279f187~noop.image?_iz=58558&amp;from=article.pc_detail&amp;lk3s=953192f4&amp;x-expires=1728294546&amp;x-signature=64vhMTkVWa81CXKp3u87%2BD%2BdLQs%3D" style="width: 50%; margin-bottom: 20px;">
      <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">更改端口设置</p>
    </div>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">就<span style="color: black;">能够</span>打开端口常规设置界面,<span style="color: black;">咱们</span>讲Apache里边的httpd端口改为非“80”(默认80),点击应用就<span style="color: black;">能够</span>了,如下图所示:</p>
    <div style="color: black; text-align: left; margin-bottom: 10px;"><img src="https://p3-sign.toutiaoimg.com/tos-cn-i-qvj2lq49k0/95257d0da2784c0ca33d2d93d73cc392~noop.image?_iz=58558&amp;from=article.pc_detail&amp;lk3s=953192f4&amp;x-expires=1728294546&amp;x-signature=VumoQgN7AgqisJPqbHGTIRNDbwM%3D" style="width: 50%; margin-bottom: 20px;">
      <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">更改端口设置</p>
    </div>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">修改完成<span style="color: black;">保留</span>,phpStudy会自动重启Apache服务,<span style="color: black;">此时</span>就<span style="color: black;">能够</span>正常<span style="color: black;">起步</span>了,<span style="color: black;">咱们</span><span style="color: black;">能够</span>打开浏览器,输入上图<span style="color: black;">咱们</span>设置的默认首页“http://127.0.0.1:8000”,就<span style="color: black;">能够</span><span style="color: black;">拜访</span>Apache Tomcat界面了,如下图所示:</p>
    <div style="color: black; text-align: left; margin-bottom: 10px;"><img src="https://p3-sign.toutiaoimg.com/tos-cn-i-qvj2lq49k0/4a5c226cdcd44319b77ccbea6b7f88ce~noop.image?_iz=58558&amp;from=article.pc_detail&amp;lk3s=953192f4&amp;x-expires=1728294546&amp;x-signature=3hR9sXfIeN3Oj4alh%2BGTNNKlr%2B4%3D" style="width: 50%; margin-bottom: 20px;">
      <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">Apache Tomcat默认界面</p>
    </div>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">安装完环境,<span style="color: black;">咱们</span><span style="color: black;">起始</span>等保2.0测评。</p>
    <h1 style="color: black; text-align: left; margin-bottom: 10px;"><span style="color: black;">2、</span>测评项</h1>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">1、身份鉴别</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">a)应对登录的用户进行身份标识和鉴别,身份标识<span style="color: black;">拥有</span><span style="color: black;">独一</span>性,身份鉴别信息<span style="color: black;">拥有</span><span style="color: black;">繁杂</span>度<span style="color: black;">需求</span>并<span style="color: black;">定时</span>更换;</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">这一项<span style="color: black;">咱们</span><span style="color: black;">能够</span>查看<span style="color: black;">tomcat目录下/conf/tomcat-user.xml文件,查看username<span style="color: black;">是不是</span><span style="color: black;">独一</span>,查看password<span style="color: black;">是不是</span><span style="color: black;">拥有</span><span style="color: black;">繁杂</span>度,<span style="color: black;">通常</span><span style="color: black;">需求</span>长度8位以上,由大写字母、小写字母、数字、特殊符号中的任意三种<span style="color: black;">构成</span>,<span style="color: black;">是不是</span><span style="color: black;">定时</span>修改并<span style="color: black;">无</span><span style="color: black;">详细</span>配置,这个只能询问管理人员了。</span></p>
    <div style="color: black; text-align: left; margin-bottom: 10px;"><img src="https://p3-sign.toutiaoimg.com/tos-cn-i-qvj2lq49k0/84faf5d53e874af09713d8faa743abd3~noop.image?_iz=58558&amp;from=article.pc_detail&amp;lk3s=953192f4&amp;x-expires=1728294546&amp;x-signature=Teqju103ulGR62JVErdv252x%2Fd8%3D" style="width: 50%; margin-bottom: 20px;">
      <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">用户口令</p>
    </div>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">b)应<span style="color: black;">拥有</span>登录失败处理功能,应配置并启用结束会话、限制<span style="color: black;">违法</span>登录次数和当登录连接超时自动退出等<span style="color: black;">关联</span><span style="color: black;">办法</span>;</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">这一项<span style="color: black;">咱们</span><span style="color: black;">能够</span>查看<span style="color: black;">tomcat目录下/conf/server.xml文件,查看对应的failureCount(“次”),lockOutTime(“秒”)值,可<span style="color: black;">自动</span>编辑,便是连续输入错误三次<span style="color: black;">秘码</span>,自动锁定300秒,如下图所示:</span></p>
    <div style="color: black; text-align: left; margin-bottom: 10px;"><img src="https://p3-sign.toutiaoimg.com/tos-cn-i-qvj2lq49k0/744ee862dba44e46bc0122328bfd6491~noop.image?_iz=58558&amp;from=article.pc_detail&amp;lk3s=953192f4&amp;x-expires=1728294546&amp;x-signature=0xFFhI3hodyll8cLKX1ny%2BNGWFc%3D" style="width: 50%; margin-bottom: 20px;">
      <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">登录失败处理</p>
    </div>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">至于登录连接超时自动退出,<span style="color: black;">亦</span>是在这个文件,找到<span style="color: black;">connectionTimeout值,默认是20000秒,显然需要修改。</span></p>
    <div style="color: black; text-align: left; margin-bottom: 10px;"><img src="https://p3-sign.toutiaoimg.com/tos-cn-i-qvj2lq49k0/cd793879da3048478aac13280b835dd6~noop.image?_iz=58558&amp;from=article.pc_detail&amp;lk3s=953192f4&amp;x-expires=1728294546&amp;x-signature=lL4O0jKvgUHMYAucidtLsr8Ddhg%3D" style="width: 50%; margin-bottom: 20px;">
      <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">超时自动退出</p>
    </div>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">c)当进行远程管理时,应采取必要<span style="color: black;">办法</span>防止鉴别信息在网络传输过程中被窃听;</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">这一项<span style="color: black;">重点</span>看信息传输过程中<span style="color: black;">是不是</span>被加密,比较直观的<span style="color: black;">便是</span>看<span style="color: black;">拜访</span>默认界面时,网址前缀是“http”还是“https”,后者的信息是经过加密后传输的。</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">d)应采用口令、<span style="color: black;">秘码</span>技术、生物技术等两种或两种以上组合的鉴别技术对用户进行身份鉴别,且其中一种鉴别技术<span style="color: black;">最少</span>应<span style="color: black;">运用</span><span style="color: black;">秘码</span>技术来实现。</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">Apache Tomcat中间件还<span style="color: black;">无</span>见过做过双<span style="color: black;">原因</span>认证的,基本都是不符合的,当然<span style="color: black;">倘若</span>作了,<span style="color: black;">根据</span><span style="color: black;">实质</span><span style="color: black;">状况</span>记录就行了。</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">2、<span style="color: black;">拜访</span><span style="color: black;">掌控</span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">a)应对登录的用户分配账户和权限;</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">查看<span style="color: black;">tomcat目录下/conf/tomcat-user.xml文件,找到有如下图配置字段的位置,<span style="color: black;">查询</span>有<span style="color: black;">那些</span>用户分别属于那种角色,<span style="color: black;">通常</span><span style="color: black;">来讲</span>,role1:<span style="color: black;">拥有</span>读权限;tomcat:<span style="color: black;">拥有</span>读和运行权限;admin:<span style="color: black;">拥有</span>读、运行和写的权限;manager:<span style="color: black;">拥有</span>远程管理权限。</span></p>
    <div style="color: black; text-align: left; margin-bottom: 10px;"><img src="https://p3-sign.toutiaoimg.com/tos-cn-i-qvj2lq49k0/4eb8870b678b4290a864ab6bb06564d2~noop.image?_iz=58558&amp;from=article.pc_detail&amp;lk3s=953192f4&amp;x-expires=1728294546&amp;x-signature=iCnDj6bYeeaK6OdXs%2FBXYkY7Hm4%3D" style="width: 50%; margin-bottom: 20px;">
      <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">查看用户和权限</p>
    </div>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">b)应重命名或删除默认账户,修改默认账户的默认口令;</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">一样</span>查看<span style="color: black;">tomcat目录下/conf/tomcat-user.xml文件,找到username和password字段,查看用户名和<span style="color: black;">秘码</span>,<span style="color: black;">通常</span>admin、manager、tomcat、role1、both等是默认账户,默认口令must_be_change<span style="color: black;">是不是</span>修改。</span></p>
    <div style="color: black; text-align: left; margin-bottom: 10px;"><img src="https://p3-sign.toutiaoimg.com/tos-cn-i-qvj2lq49k0/57b19cd84a804f87949541c3d18a09b4~noop.image?_iz=58558&amp;from=article.pc_detail&amp;lk3s=953192f4&amp;x-expires=1728294546&amp;x-signature=wqCRR8LNqSmpxqYsoPgOIZxj1nk%3D" style="width: 50%; margin-bottom: 20px;">
      <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">用户名和口令</p>
    </div>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">c)应<span style="color: black;">即时</span>删除或停用多余的、过期的账户,避免共享账户的存在;</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">对应上图用户名,询问管理员以上用户的用途,<span style="color: black;">针对</span><span style="color: black;">没法</span>确定用途的用户<span style="color: black;">能够</span>视为多余用户,至于过期用户Tomcat<span style="color: black;">无</span><span style="color: black;">关联</span>设置,用户永久有效,共享用户<span style="color: black;">亦</span>只能询问管理员,<span style="color: black;">没法</span>查证,<span style="color: black;">通常</span>都会回答<span style="color: black;">无</span>共享用户。</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">d)应授予管理用户所需的最小权限,实现管理用户的权限分离;</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">通常</span>系统都采用三权分立的设置来实现权限分离的,<span style="color: black;">针对</span>Tomcat<span style="color: black;">来讲</span>,它自己的权限分配原则,不满足三权分立的<span style="color: black;">需求</span>,<span style="color: black;">因此</span>默认不符合。</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">e)应由授权主体配置<span style="color: black;">拜访</span><span style="color: black;">掌控</span>策略,<span style="color: black;">拜访</span><span style="color: black;">掌控</span>策略规定主体对客体的<span style="color: black;">拜访</span>规则;</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">一样</span>查看<span style="color: black;">tomcat目录下/conf/tomcat-user.xml文件,找到roles字段,查看<span style="color: black;">区别</span>用户所分配的<span style="color: black;">区别</span>权限,即分配了<span style="color: black;">哪些</span><span style="color: black;">区别</span>的角色。</span></p>
    <div style="color: black; text-align: left; margin-bottom: 10px;"><img src="https://p3-sign.toutiaoimg.com/tos-cn-i-qvj2lq49k0/b6c182656fb942ddaa2cac5d0a8fb473~noop.image?_iz=58558&amp;from=article.pc_detail&amp;lk3s=953192f4&amp;x-expires=1728294546&amp;x-signature=w84G3xtav2OiKzb5PKuYm2b6zPo%3D" style="width: 50%; margin-bottom: 20px;">
      <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">角色分配</p>
    </div>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">f)<span style="color: black;">拜访</span><span style="color: black;">掌控</span>的粒度应达到主体为用户级或进程级,客体为文件、数据库表级;</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">Tomcat的主体<span style="color: black;">拜访</span><span style="color: black;">掌控</span>粒度是<span style="color: black;">能够</span>达到用户级的,<span style="color: black;">然则</span>客体不会分的<span style="color: black;">那样</span>细,<span style="color: black;">由于</span>Tomcat<span style="color: black;">通常</span>都是<span style="color: black;">做为</span>一个整体为系统<span style="color: black;">供给</span>支持的,<span style="color: black;">都数</span><span style="color: black;">咱们</span>会认为Tomcat不适用这一项。</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">g)应对重要主体和客体设置安全标记,并<span style="color: black;">掌控</span>主体对有安全标记信息资源的<span style="color: black;">拜访</span>。</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">这一项,Tomcat<span style="color: black;">亦</span>是<span style="color: black;">没法</span>实现的,默认不符合,<span style="color: black;">然则</span><span style="color: black;">都数</span><span style="color: black;">亦</span>是判定不适用。</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">3、安全审计</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">a)应启用安全审计功能,审计覆盖到<span style="color: black;">每一个</span>用户,对重要的用户<span style="color: black;">行径</span>和重要安全事件进行审计;</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">查看<span style="color: black;">tomcat目录下/conf/logging.properties文件,找到如下图的配置,只要图中被小红方块标注的<span style="color: black;">地区</span>不是OFF,就<span style="color: black;">暗示</span>开启了安全审计功能,默认<span style="color: black;">起始</span>,<span style="color: black;">因此</span>默认符。</span></p>
    <div style="color: black; text-align: left; margin-bottom: 10px;"><img src="https://p3-sign.toutiaoimg.com/tos-cn-i-qvj2lq49k0/63baa0cb77c14062b69088316a5afae2~noop.image?_iz=58558&amp;from=article.pc_detail&amp;lk3s=953192f4&amp;x-expires=1728294546&amp;x-signature=0FejRwSMmrksRoGYkGaCMHw4GCU%3D" style="width: 50%; margin-bottom: 20px;">
      <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">安全审计</p>
    </div>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">查看tomcat目录/conf/server.xml,Access网页<span style="color: black;">拜访</span>日志,<span style="color: black;">倘若</span>有如下图内容且取消注释,<span style="color: black;">暗示</span>Access网页<span style="color: black;">拜访</span>日志开启。</span></p>
    <div style="color: black; text-align: left; margin-bottom: 10px;"><img src="https://p3-sign.toutiaoimg.com/tos-cn-i-qvj2lq49k0/1c8f06bdd9eb445baf10f7dd7191114e~noop.image?_iz=58558&amp;from=article.pc_detail&amp;lk3s=953192f4&amp;x-expires=1728294546&amp;x-signature=mTSwLLMn%2BUrEJeZPNHhmDAhhAKw%3D" style="width: 50%; margin-bottom: 20px;">
      <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">Access网页<span style="color: black;">拜访</span>日志</p>
    </div>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">b)审计记录应<span style="color: black;">包含</span>事件的日期和时间、用户、事件类型、事件<span style="color: black;">是不是</span>成功及其他与审计<span style="color: black;">关联</span>的信息;</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">查看<span style="color: black;">tomcat目录下/logs文件夹里的日志文件,查看<span style="color: black;">是不是</span>满足本项的<span style="color: black;">需求</span>,如下图所示:</span></p>
    <div style="color: black; text-align: left; margin-bottom: 10px;"><img src="https://p3-sign.toutiaoimg.com/tos-cn-i-qvj2lq49k0/b8148079862b42d59c6933acc1589c7b~noop.image?_iz=58558&amp;from=article.pc_detail&amp;lk3s=953192f4&amp;x-expires=1728294546&amp;x-signature=Mez3IbVm2HxsEYbRru2t99T3jWg%3D" style="width: 50%; margin-bottom: 20px;">
      <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">日志文件1</p>
    </div>
    <div style="color: black; text-align: left; margin-bottom: 10px;"><img src="https://p3-sign.toutiaoimg.com/tos-cn-i-qvj2lq49k0/8094965cd8f84e65919cb40c14aa6599~noop.image?_iz=58558&amp;from=article.pc_detail&amp;lk3s=953192f4&amp;x-expires=1728294546&amp;x-signature=IMDe10SMMe8vvSjx8BMk1E%2BpvME%3D" style="width: 50%; margin-bottom: 20px;">
      <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">日志文件2</p>
    </div>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">c)应对审计记录进行<span style="color: black;">守护</span>,<span style="color: black;">定时</span>备份,避免受到未预期的删除、修改或覆盖等;</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">查看logs文件的属性,设置了只读,安全选项里除了超级管理员有完全<span style="color: black;">掌控</span>权限,其他用户<span style="color: black;">仅有</span>读取的权限,如下图所示:</p>
    <div style="color: black; text-align: left; margin-bottom: 10px;"><img src="https://p3-sign.toutiaoimg.com/tos-cn-i-qvj2lq49k0/5f7ac5ba3f9c443cafb581503f49bdde~noop.image?_iz=58558&amp;from=article.pc_detail&amp;lk3s=953192f4&amp;x-expires=1728294546&amp;x-signature=POZjJI84tBxCw%2BcphRmNZR2LoIY%3D" style="width: 50%; margin-bottom: 20px;">
      <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">logs文件属性</p>
    </div>
    <div style="color: black; text-align: left; margin-bottom: 10px;"><img src="https://p3-sign.toutiaoimg.com/tos-cn-i-qvj2lq49k0/30b81094fd6344a78e8a6c5d7bde28ab~noop.image?_iz=58558&amp;from=article.pc_detail&amp;lk3s=953192f4&amp;x-expires=1728294546&amp;x-signature=AG8K8nDScNE9pOJ%2Ft0VhhY2sjLA%3D" style="width: 50%; margin-bottom: 20px;">
      <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">权限查看</p>
    </div>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">至于<span style="color: black;">是不是</span>做了日志备份,只能询问管理员了,并查看备份的日志文件。</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">d)应对审计进程进行<span style="color: black;">守护</span>,防止未经授权的中断。</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">Tomcat只要开启了审计功能,就会和主程序<span style="color: black;">一块</span>进行,<span style="color: black;">通常</span>不会中断,<span style="color: black;">因此呢</span>是默认符合的。</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">4、入侵防范</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">a)应遵循最小安装的原则,仅安装需要的组件和应用程序;</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">不适用</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">b)应关闭不需要的系统服务、默认共享和高危端口;</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">不适用</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">c)应<span style="color: black;">经过</span>设定终端接入方式或网络<span style="color: black;">位置</span>范围对<span style="color: black;">经过</span>网络进行管理的管理终端进行限制;</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">Tomcat<span style="color: black;">无</span><span style="color: black;">关联</span>设置,应该查看系统<span style="color: black;">是不是</span>做了<span style="color: black;">关联</span>设置。</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">d)应<span style="color: black;">供给</span>数据有效性检验功能,<span style="color: black;">保准</span><span style="color: black;">经过</span>人机接口输入或<span style="color: black;">经过</span>通信接口输入的内容符合系统设定<span style="color: black;">需求</span>;</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">Tomcat<span style="color: black;">无</span><span style="color: black;">关联</span>设置,应该查看系统<span style="color: black;">是不是</span>做了<span style="color: black;">关联</span>设置。</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">e)应能<span style="color: black;">发掘</span>可能存在的已知漏洞,并在经过充分测试<span style="color: black;">评定</span>后,<span style="color: black;">即时</span>修补漏洞;</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">低版本的Tomcat会存在已知漏洞,<span style="color: black;">因此呢</span>需要<span style="color: black;">即时</span>升级到最新的Tomcat版本。</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">f)应能够检测到对重要节点进行入侵的<span style="color: black;">行径</span>,并在<span style="color: black;">出现</span>严重入侵事件时<span style="color: black;">供给</span>报警。</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">Tomcat<span style="color: black;">无</span><span style="color: black;">关联</span>设置,应该查看系统<span style="color: black;">是不是</span>做了相关设置。</p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">以上<span style="color: black;">便是</span>一项一项教你测等保2.0——Apache Tomcat中间件的所有内容,<span style="color: black;">期盼</span>对<span style="color: black;">大众</span>有所<span style="color: black;">帮忙</span>,欢迎关注@科技兴<span style="color: black;">认识</span><span style="color: black;">更加多</span>科技尤其是网络安全方面的<span style="color: black;">新闻</span>与知识。</p>




m5k1umn 发表于 7 天前

期待更新、坐等、迫不及待等。
页: [1]
查看完整版本: 一项一项教你测等保2.0——Apache Tomcat中间件