| is radically different from that of UNIX, relying on sets of security descriptors -- for the user, for the application, for the data files in use. By relying on multiple points of control, M$ has simultaneously increased the risk (by increasing the number of vulnerabilities) and limited the risk (by ensuring that objects not directly attacked can maintain their integrity).
Run out to M$'s website, look up SFU (Windows Services For Unix), and take their free web-training, "Windows Administration for UNIX System Administrators". It highlights the differences between the two security models. |