网络服务监视MIB( 七 )


RFC1565的一些更新使有了这个目前的版本 。
9.参考资料
[1]Grillo,P.andS.Waldbusser,"HostResourcesMIB",RFC1514,
September1993.
[2]Krupczak,C.andJ.Saperia,"DefinitionsofSystem-Level
ManagedObjectsforApplications",RFC2287,February1998.
[3]Wijnen,B.,Harrington,D.andR.Presuhn,"AnArchitecturefor
DescribingSNMPManagementFrameworks",RFC2571,April1999.
[4]Rose,M.andK.McCloghrie,"StrUCtureandIdentificationof
ManagementInformationforTCP/IP-basedInternets",STD16,RFC
1155,May1990.
[5]Rose,M.andK.McCloghrie,"ConciseMIBDefinitions",STD16,
RFC1212,March1991.
[6]Rose,M.,"AConventionforDefiningTrapsforusewiththe
SNMP",RFC1215,March1991.
[7]McCloghrie,K.,Perkins,D.andJ.Schoenwaelder,"Structureof
ManagementInformationVersion2(SMIv2)",STD58,RFC2578,
April1999.
[8]McCloghrie,K.,Perkins,D.andJ.Schoenwaelder,"Textual
ConventionsforSMIv2",STD58,RFC2579,April1999.
[9]McCloghrie,K.,Perkins,D.andJ.Schoenwaelder,"Conformance
StatementsforSMIv2",STD58,RFC2580,April1999.
[10]Case,J.,Fedor,M.,Schoffstall,M.andJ.Davin,"Simple
NetworkManagementProtocol",STD15,RFC1157,May1990.
[11]Case,J.,McCloghrie,K.,Rose,M.andS.Waldbusser,
"IntroductiontoCommunity-basedSNMPv2",RFC1901,January
1996.
[12]Case,J.,McCloghrie,K.,Rose,M.andS.Waldbusser,"Transport
MappingsforVersion2oftheSimpleNetworkManagementProtocol
(SNMPv2)",RFC1906,January1996.
[13]Case,J.,HarringtonD.,PresuhnR.andB.Wijnen,"Message
ProcessingandDispatchingfortheSimpleNetworkManagement
Protocol(SNMP)",RFC2572,April1999.
[14]Blumenthal,U.andB.Wijnen,"User-basedSecurityModel(USM)
forversion3oftheSimpleNetworkManagementProtocol
(SNMPv3)",RFC2574,April1999.
[15]Case,J.,McCloghrie,K.,Rose,M.andS.Waldbusser,"Protocol
OperationsforVersion2oftheSimpleNetworkManagement
Protocol(SNMPv2)",RFC1905,January1996.
[16]Levi,D.,Meyer,P.andB.Stewart,"SNMPv3Applications",RFC
2573,April1999.
[17]Wijnen,B.,Presuhn,R.andK.McCloghrie,"View-basedAccess
ControlModel(VACM)fortheSimpleNetworkManagementProtocol
(SNMP)",RFC2575,April1999.
[18]Wahl,M.,Kille,S.andT.Howes,"LightweightDirectoryAccess
Protocol(v3):UTF-8StringRepresentationofDistinguished
Names",RFC2253,December1997.
[19]Kille,S.,"MappingbetweenX.400(1988)andRFC822/MIME",RFC
2156,January1998.
[20]Berners-Lee,T.,Masinter,L.andM.McCahill,"UniformResource
Locators(URL)",RFC1738,December1994.
[21]Hoffman,P.,Masinter,L.andJ.Zawinski,"ThemailtoURL
Scheme",RFC2368,July1998.
[22]Freed,N.andS.Kille,"NetworkServicesMonitoringMIB",RFC
2248,January1998.
[23]Freed,N.andKille,"NetworkServicesMonitoringMIB",RFC
1565,January1994.
[29]Postel,J.andJ.Reynolds,"TelnetProtocolSpecification",STD
8,RFC854,RFC855,May1983.
8.安全考虑
在MIB中没有治理对象定义成有最大访问权限如读写和/或读创建 。所以,假如MIB
正确的执行,入侵者通过直接SNMP设置操作改变或创建MIB的任何治理对象是不可能的 。
但是,这个MIB不提供给定主机关于应用的存在性,类型,设置的被动信息,这些信
息可能显示一些攻击隐患 。对后,MIB信息提供可以用作分析网络流量 。
SNMPv1自身不是一个安全环境 。即使假如它自身是安全的(如用IPSec),假使那样那么没
有控制能够在网络上答应连通或GET/SET(read/change/create/delete)在MIB中的信息 。
极力被推荐的具有安全特性的应用为SNMPv3.非凡的,基本用户安全模型RFC2574[14]
和基于观点连接控制模型RFC2575[17]是推荐使用的 。
保证SNMP提供连通MIB是客户/用户的责任,应该配置成只有给那些合法用户有权实
际Get或Set信息 。
9.AuthorandChairAddresses
NedFreed

推荐阅读