{"id":4206,"date":"2018-12-11T21:02:29","date_gmt":"2018-12-11T13:02:29","guid":{"rendered":"https:\/\/ixyzero.com\/blog\/?p=4206"},"modified":"2018-12-11T21:02:29","modified_gmt":"2018-12-11T13:02:29","slug":"hadoop%e5%ae%89%e5%85%a8%e5%ad%a6%e4%b9%a0%e8%b5%84%e6%96%99%e6%95%b4%e7%90%86","status":"publish","type":"post","link":"https:\/\/ixyzero.com\/blog\/archives\/4206.html","title":{"rendered":"Hadoop\u5b89\u5168\u5b66\u4e60\u8d44\u6599\u6574\u7406"},"content":{"rendered":"<p>=Start=<\/p>\n<h4 id=\"id-\u6a21\u677f-\u7f18\u7531\uff1a\">\u7f18\u7531\uff1a<\/h4>\n<p>\u6700\u8fd1\u5728\u5b66\u4e60\u5927\u6570\u636e\u5b89\u5168\u76f8\u5173\u7684\u77e5\u8bc6\uff0c\u4e3b\u8981\u662f\u901a\u8fc7\u300aHadoop\u5b89\u5168\uff1a\u5927\u6570\u636e\u5e73\u53f0\u9690\u79c1\u4fdd\u62a4\u300b\u8fd9\u672c\u4e66\uff0c\u4ee5\u53ca\u7f51\u4e0a\u7684\u4e00\u4e9b\u6587\u7ae0\u6765\u5165\u95e8\uff0c\u5728\u6b64\u6574\u7406\u4e00\u4e0b\u5728\u8fd9\u4e00\u8fc7\u7a0b\u4e2d\u770b\u5230\u7684\u89c9\u5f97\u8fd8\u4e0d\u9519\u7684\u8d44\u6599\uff0c\u65b9\u4fbf\u81ea\u5df1\u7684\u540c\u65f6\u4e5f\u65b9\u4fbf\u4ed6\u4eba\u3002<\/p>\n<h4 id=\"id-\u6a21\u677f-\u6b63\u6587\uff1a\">\u6b63\u6587\uff1a<\/h4>\n<h5 id=\"id-\u6a21\u677f-\u53c2\u8003\u89e3\u7b54\uff1a\">\u53c2\u8003\u89e3\u7b54\uff1a<\/h5>\n<h6>Hadoop\u5b89\u5168-\u5927\u6570\u636e\u5e73\u53f0\u9690\u79c1\u4fdd\u62a4<\/h6>\n<ul>\n<li>\u7b2c\u4e00\u90e8\u5206\u3000\u5b89\u5168\u67b6\u6784\uff08CIA\uff09<\/li>\n<li>\u7b2c\u4e8c\u90e8\u5206\u3000\u9a8c\u8bc1\u3001\u6388\u6743\u548c\u5ba1\u8ba1\uff08AAA\uff09<\/li>\n<li>\u7b2c\u4e09\u90e8\u5206\u3000\u6570\u636e\u5b89\u5168\uff08\u9759\u6001\u6570\u636e\u52a0\u5bc6\u3001\u52a8\u6001\u6570\u636e\u52a0\u5bc6\uff09<\/li>\n<\/ul>\n<h6>\u5927\u6570\u636e\u5b89\u5168\u6280\u672f\u603b\u4f53\u89c6\u56fe<\/h6>\n<p>\uff08\u4e00\uff09\u5927\u6570\u636e\u5e73\u53f0\u5b89\u5168<br \/>\n\uff08\u4e8c\uff09\u6570\u636e\u5b89\u5168<br \/>\n\uff08\u4e09\uff09\u9690\u79c1\u4fdd\u62a4<\/p>\n<h6>\u5927\u6570\u636e\u5b89\u5168\u9762\u4e34\u7684\u5a01\u80c1\u4e0e\u6280\u672f<\/h6>\n<ol>\n<li><strong>\u6570\u636e\u7684\u771f\u5b9e\u6027\u548c\u5b8c\u6574\u6027\u6821\u9a8c\u56f0\u96be<\/strong>\u3002\u9ed1\u5ba2\u5229\u7528\u7f51\u7edc\u653b\u51fb\u5411\u6570\u636e\u91c7\u96c6\u7aef\u6ce8\u5165\u810f\u6570\u636e\uff0c\u4f1a\u7834\u574f\u6570\u636e\u771f\u5b9e\u6027\uff0c\u6545\u610f\u5c06\u6570\u636e\u5206\u6790\u7684\u7ed3\u679c\u5f15\u5411\u9884\u8bbe\u7684\u65b9\u5411\uff0c\u8fdb\u800c\u5b9e\u73b0\u64cd\u7eb5\u5206\u6790\u7ed3\u679c\u7684\u653b\u51fb\u76ee\u7684\u3002<\/li>\n<li><strong>\u5927\u6570\u636eDLP \u9632\u62a4\u6280\u672f<\/strong>\uff1a\u9488\u5bf9\u4f7f\u7528\u6cc4\u9732\u548c\u5b58\u50a8\u6cc4\u9732\uff0c\u901a\u5e38\u91c7\u7528\u8eab\u4efd\u8ba4\u8bc1\u7ba1\u7406\u3001\u8fdb\u7a0b\u76d1\u63a7\u3001\u65e5\u5fd7\u5206\u6790\u548c\u5b89\u5168\u5ba1\u8ba1\u7b49\u6280\u672f\u624b\u6bb5\uff0c\u89c2\u5bdf\u548c\u8bb0\u5f55\u64cd\u4f5c\u5458\u5bf9\u8ba1\u7b97\u673a\u3001\u6587\u4ef6\u3001\u8f6f\u4ef6\u548c\u6570\u636e\u7684\u64cd\u4f5c\u60c5\u51b5\uff0c\u53d1\u73b0\u3001\u8bc6\u522b\u3001\u76d1\u63a7\u8ba1\u7b97\u673a\u4e2d\u7684\u654f\u611f\u6570\u636e\u7684\u4f7f\u7528\u548c\u6d41\u52a8\uff0c\u5bf9\u654f\u611f\u6570\u636e\u7684\u8fdd\u89c4\u4f7f\u7528\u8fdb\u884c\u8b66\u544a\u3001\u963b\u65ad\u7b49\u3002\u9488\u5bf9\u4f20\u8f93\u6cc4\u9732\uff0c\u901a\u5e38\u91c7\u53d6\u654f\u611f\u6570\u636e\u52a8\u6001\u8bc6\u522b\u3001\u52a8\u6001\u52a0\u5bc6\u3001\u8bbf\u95ee\u963b\u65ad\u3001\u548c\u6570\u636e\u5e93\u9632\u706b\u5899\u7b49\u6280\u672f\uff0c\u76d1\u63a7\u670d\u52a1\u5668\u3001\u7ec8\u7aef\u4ee5\u53ca\u7f51\u7edc\u4e2d\u52a8\u6001\u4f20\u8f93\u7684\u654f\u611f\u6570\u636e\uff0c\u53d1\u73b0\u548c\u963b\u6b62\u654f\u611f\u6570\u636e\u901a\u8fc7\u804a\u5929\u5de5\u5177\u3001\u7f51\u76d8\u3001\u5fae\u535a\u3001FTP\u3001\u8bba\u575b\u7b49\u65b9\u5f0f\u6cc4\u9732\u51fa\u53bb\u3002<\/li>\n<li><strong>\u5bc6\u6587\u8ba1\u7b97\u6280\u672f<\/strong>\uff1a\u540c\u6001\u52a0\u5bc6\u548c\u5b89\u5168\u591a\u65b9\u8ba1\u7b97\u7b49\u5bc6\u6587\u8ba1\u7b97\u65b9\u6cd5\uff08SMPC\uff09\u4e3a\u89e3\u51b3\u8fd9\u4e2a\u96be\u9898\u63d0\u4f9b\u4e86\u4e00\u79cd\u6709\u6548\u7684\u89e3\u51b3\u601d\u8def\u3002<\/li>\n<\/ol>\n<ul>\n<li><strong>\u540c\u6001\u52a0\u5bc6<\/strong>\u63d0\u4f9b\u4e86\u4e00\u79cd\u5bf9\u52a0\u5bc6\u6570\u636e\u8fdb\u884c\u5904\u7406\u7684\u529f\u80fd\uff0c\u5bf9\u7ecf\u8fc7\u540c\u6001\u52a0\u5bc6\u7684\u6570\u636e\u5904\u7406\u5f97\u5230\u4e00\u4e2a\u8f93\u51fa\uff0c\u5c06\u8fd9\u4e00\u8f93\u51fa\u8fdb\u884c\u89e3\u5bc6\uff0c\u5176\u7ed3\u679c\u4e0e\u7edf\u4e00\u65b9\u6cd5\u5904\u7406\u672a\u52a0\u5bc6\u7684\u539f\u59cb\u6570\u636e\u5f97\u5230\u7684\u8f93\u51fa\u7ed3\u679c\u4e00\u81f4\u3002<\/li>\n<li><strong>\u5b89\u5168\u591a\u65b9\u8ba1\u7b97<\/strong>\uff08SecureMulti-PartyComputation, SMPC\uff09\u662f\u89e3\u51b3\u4e00\u7ec4\u4e92\u4e0d\u4fe1\u4efb\u7684\u53c2\u4e0e\u65b9\u4e4b\u95f4\u4fdd\u62a4\u9690\u79c1\u7684\u534f\u540c\u8ba1\u7b97\u95ee\u9898\uff0cSMPC\u8981\u786e\u4fdd\u8f93\u5165\u7684\u72ec\u7acb\u6027\uff0c\u8ba1\u7b97\u7684\u6b63\u786e\u6027\uff0c\u540c\u65f6\u4e0d\u6cc4\u9732\u5404\u8f93\u5165\u503c\u7ed9\u53c2\u4e0e\u8ba1\u7b97\u7684\u5176\u4ed6\u6210\u5458\u3002<\/li>\n<\/ul>\n<ol start=\"4\">\n<li><strong>\u6570\u5b57\u6c34\u5370\u548c\u6570\u636e\u8840\u7f18\u8ffd\u8e2a\u6280\u672f<\/strong><\/li>\n<\/ol>\n<ul>\n<li><strong>\u6570\u5b57\u6c34\u5370\u6280\u672f<\/strong>\u662f\u4e3a\u4e86\u4fdd\u6301\u5bf9\u5206\u53d1\u540e\u7684\u6570\u636e\u6d41\u5411\u8ffd\u8e2a\uff0c\u5728\u6570\u636e\u6cc4\u9732\u884c\u4e3a\u53d1\u751f\u540e\uff0c\u5bf9\u9020\u6210\u6570\u636e\u6cc4\u9732\u7684\u6e90\u5934\u53ef\u8fdb\u884c\u56de\u6eaf\u3002<\/li>\n<li><strong>\u6570\u636e\u8840\u7f18<\/strong>(Lineage\uff0cProvenance\uff0cPedigree)\u4ea6\u53ef\u8bd1\u4e3a\u8840\u7edf\u3001\u8d77\u6e90\u3001\u4e16\u7cfb\u3001\u8c31\u7cfb\uff0c\u662f\u6307\u6570\u636e\u4ea7\u751f\u7684\u94fe\u8def\uff0c\u6570\u636e\u8840\u7f18\u8bb0\u8f7d\u4e86\u5bf9\u6570\u636e\u5904\u7406\u7684\u6574\u4e2a\u5386\u53f2\uff0c\u5305\u62ec\u6570\u636e\u7684\u8d77\u6e90\u548c\u5904\u7406\u8fd9\u4e9b\u6570\u636e\u7684\u6240\u6709\u540e\u7ee7\u8fc7\u7a0b\u3002<\/li>\n<\/ul>\n<ol start=\"5\">\n<li><strong>\u6570\u636e\u8131\u654f\u6280\u672f<\/strong><\/li>\n<\/ol>\n<ul>\n<li>\u7b2c\u4e00\u79cd\u52a0\u5bc6\u65b9\u6cd5\uff0c\u662f\u6307\u6807\u51c6\u7684\u52a0\u5bc6\u7b97\u6cd5\uff0c\u52a0\u5bc6\u540e\u5b8c\u5168\u5931\u53bb\u4e1a\u52a1\u5c5e\u6027\uff0c\u5c5e\u4e8e\u4f4e\u5c42\u6b21\u8131\u654f\u3002\u7b97\u6cd5\u5f00\u9500\u5927\uff0c\u9002\u7528\u4e8e\u673a\u5bc6\u6027\u8981\u6c42\u9ad8\u3001\u4e0d\u9700\u8981\u4fdd\u6301\u4e1a\u52a1\u5c5e\u6027\u7684\u573a\u666f\u3002<\/li>\n<li>\u7b2c\u4e8c\u79cd\u57fa\u4e8e\u6570\u636e\u5931\u771f\u7684\u6280\u672f\uff0c\u6700\u5e38\u7528\u7684\u662f\u968f\u673a\u5e72\u6270\u3001\u4e71\u5e8f\u7b49\uff0c\u662f\u4e0d\u53ef\u9006\u7b97\u6cd5\uff0c\u901a\u8fc7\u8fd9\u79cd\u7b97\u6cd5\u53ef\u4ee5\u751f\u6210\u201c\u770b\u8d77\u6765\u5f88\u771f\u5b9e\u7684\u5047\u6570\u636e\u201d\u3002\u9002\u7528\u4e8e\u7fa4\u4f53\u4fe1\u606f\u7edf\u8ba1\u6216\uff08\u548c\uff09\u9700\u8981\u4fdd\u6301\u4e1a\u52a1\u5c5e\u6027\u7684\u573a\u666f\u3002<\/li>\n<li>\u7b2c\u4e09\u79cd\u53ef\u9006\u7684\u7f6e\u6362\u7b97\u6cd5\uff0c\u517c\u5177\u53ef\u9006\u548c\u4fdd\u8bc1\u4e1a\u52a1\u5c5e\u6027\u7684\u7279\u5f81\uff0c\u53ef\u4ee5\u901a\u8fc7\u4f4d\u7f6e\u53d8\u6362\u3001\u8868\u6620\u5c04\u3001\u7b97\u6cd5\u6620\u5c04\u7b49\u65b9\u5f0f\u5b9e\u73b0\u3002<\/li>\n<\/ul>\n<ol start=\"6\">\n<li><strong>\u6570\u636e\u533f\u540d\u5316\u7b97\u6cd5<\/strong>\u53ef\u4ee5\u5b9e\u73b0\u6839\u636e\u5177\u4f53\u60c5\u51b5\u6709\u6761\u4ef6\u5730\u53d1\u5e03\u90e8\u5206\u6570\u636e\uff0c\u6216\u8005\u6570\u636e\u7684\u90e8\u5206\u5c5e\u6027\u5185\u5bb9\uff0c\u5305\u62ec\u5dee\u5206\u9690\u79c1\u3001K \u533f\u540d\u3001L \u591a\u6837\u6027\u3001T \u63a5\u8fd1\u7b49\u3002<\/li>\n<\/ol>\n<h6>\u5927\u6570\u636e\u5e73\u53f0\u5b89\u5168\u4f53\u7cfb\u7684\u56db\u4e2a\u5c42\u6b21<\/h6>\n<ol>\n<li>\u5916\u56f4\u5b89\u5168\uff1b<\/li>\n<li>\u6570\u636e\u5b89\u5168\uff1b<\/li>\n<li>\u8bbf\u95ee\u5b89\u5168\uff1b<\/li>\n<li>\u8bbf\u95ee\u884c\u4e3a\u76d1\u63a7\u3002<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<h5 id=\"id-\u6a21\u677f-\u53c2\u8003\u94fe\u63a5\uff1a\">\u53c2\u8003\u94fe\u63a5\uff1a<\/h5>\n<ul>\n<li>\u300a<a href=\"https:\/\/item.jd.com\/12202691.html\">Hadoop\u5b89\u5168\uff1a\u5927\u6570\u636e\u5e73\u53f0\u9690\u79c1\u4fdd\u62a4<\/a>\u300b<br \/>\n<a href=\"https:\/\/github.com\/hadoop-security\/examples\">https:\/\/github.com\/hadoop-security\/examples<\/a><\/li>\n<li><a href=\"https:\/\/www.freebuf.com\/column\/171450.html\">Hadoop\u5b89\u5168\u6307\u5357<\/a><\/li>\n<li><a href=\"https:\/\/docs.hortonworks.com\/HDPDocuments\/HDP2\/HDP-2.6.3\/bk_security\/content\/ch_hdp-security-guide-overview.html\">HDP Security Overview<\/a><\/li>\n<li><a href=\"https:\/\/www.cloudera.com\/documentation\/enterprise\/5-8-x\/topics\/sg_edh_overview.html\">Security Overview for an Enterprise Data Hub(Cloudera Hadoop)<\/a><\/li>\n<li><a href=\"https:\/\/datahovel.com\/2017\/10\/11\/hadoop-security-concepts\/\">Hadoop Security Concepts<\/a><\/li>\n<li><a href=\"https:\/\/zhuanlan.zhihu.com\/p\/33525241\">\u5927\u6570\u636eSRE\u7684\u603b\u7ed3\uff089\uff09\uff0d\uff0d \u6f2b\u8c08hadoop\u5b89\u5168\u6cbb\u7406\uff0d\u4e0a<\/a><\/li>\n<li><a href=\"https:\/\/github.com\/wbwangk\/wbwangk.github.io\/wiki\/hadoop%E5%AE%89%E5%85%A8\">hadoop\u5b89\u5168<\/a><\/li>\n<li><a href=\"https:\/\/tech.meituan.com\/hadoop_security_practice.html\">Hadoop\u5b89\u5168\u5b9e\u8df5<\/a><\/li>\n<li><a href=\"https:\/\/makeling.github.io\/bigdata\/39395030.html\">\u57fa\u4e8eKerberos\u8ba4\u8bc1\u914d\u7f6eHadoop\u96c6\u7fa4\u5728\u5b89\u5168\u6a21\u5f0f\u4e0b\u8fd0\u884c<\/a><\/li>\n<li><a href=\"https:\/\/cn.cloudera.com\/products\/security.html\">Enterprise security for Apache Hadoop<\/a><\/li>\n<li><a href=\"http:\/\/blackwolfsec.cc\/2018\/09\/29\/Hadoop\/\">\u5927\u6570\u636e\u5b89\u5168\u5165\u95e8-Hadoop<\/a><\/li>\n<li><a href=\"http:\/\/www.polaris-lab.com\/index.php\/archives\/187\/\">Hadoop\u6e17\u900f\u53ca\u5b89\u5168\u52a0\u56fa<\/a><br \/>\n<a href=\"http:\/\/www.mottoin.com\/article\/network\/91334.html\">http:\/\/www.mottoin.com\/article\/network\/91334.html<\/a><\/li>\n<li><a href=\"https:\/\/www.alibabacloud.com\/help\/zh\/faq-detail\/50128.htm\">Hadoop\u73af\u5883\u5b89\u5168\u52a0\u56fa<\/a><\/li>\n<li><a href=\"https:\/\/cloud.tencent.com\/developer\/article\/1169377\">\u4f60\u53ea\u77e5\u5927\u6570\u636e\u7684\u4fbf\u5229\uff0c\u5374\u4e0d\u77e5\u6f0f\u6d1e\u2014\u2014hadoop\u5b89\u5168\u5b8c\u6574\u89e3\u6790<\/a><\/li>\n<li><a href=\"https:\/\/www.anquanke.com\/post\/id\/85343\">\u3010\u6280\u672f\u5206\u4eab\u3011\u540c\u7a0b\u65c5\u6e38Hadoop\u5b89\u5168\u5b9e\u8df5<\/a><\/li>\n<li><a href=\"http:\/\/blog.sae.sina.com.cn\/archives\/2844\">\u5927\u6570\u636e\u5b89\u5168: Hadoop\u5b89\u5168\u6a21\u578b\u7684\u6f14\u8fdb<\/a><br \/>\n<a href=\"http:\/\/www.infoq.com\/articles\/HadoopSecurityModel\">http:\/\/www.infoq.com\/articles\/HadoopSecurityModel<\/a><\/li>\n<li><a href=\"https:\/\/yq.aliyun.com\/articles\/590664\">\u4f60\u7684\u6570\u636e\u5b89\u5168\u4e48\uff1fHadoop\u518d\u66dd\u5b89\u5168\u6f0f\u6d1e| \u9ed1\u5ba2\u5229\u7528Hadoop Yarn\u8d44\u6e90\u7ba1\u7406\u7cfb\u7edf\u672a\u6388\u6743\u8bbf\u95ee\u6f0f\u6d1e\u8fdb\u884c\u653b\u51fb<\/a><\/li>\n<li><a href=\"http:\/\/www.wuzesheng.com\/?p=2345\">Hadoop, Hbase, Zookeeper\u5b89\u5168\u5b9e\u8df5<\/a><\/li>\n<li><a href=\"https:\/\/linux.cn\/article-4813-1.html\">\u4e3a\u4ec0\u4e48 Cloudera \u8981\u521b\u5efa Hadoop \u5b89\u5168\u7ec4\u4ef6 Sentry \uff1f<\/a><\/li>\n<li><a href=\"http:\/\/www.tastones.com\/stackoverflow\/bigdata\/getting-started-with-big-data-hadoop-security\/\">\u5927\u6570\u636e Hadoop \u5b89\u5168\u6027\u5165\u95e8<\/a><\/li>\n<li><a href=\"http:\/\/www.yangbing.club\/2017\/06\/04\/from-kinit-to-kerberos-security-mechanism\/\">\u4ecekinit\u5230kerberos\u5b89\u5168\u673a\u5236<\/a><\/li>\n<\/ul>\n<p>=END=<\/p>\n","protected":false},"excerpt":{"rendered":"<p>=Start= \u7f18\u7531\uff1a \u6700\u8fd1\u5728\u5b66\u4e60\u5927\u6570\u636e\u5b89\u5168\u76f8\u5173\u7684\u77e5\u8bc6\uff0c\u4e3b\u8981\u662f\u901a\u8fc7\u300aHadoop\u5b89\u5168\uff1a\u5927\u6570\u636e\u5e73\u53f0\u9690\u79c1\u4fdd\u62a4\u300b\u8fd9\u672c [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[23,25,12],"tags":[933,1197,963],"class_list":["post-4206","post","type-post","status-publish","format-standard","hentry","category-knowledgebase-2","category-security","category-tools","tag-hadoop","tag-kerberos","tag-963"],"views":7173,"_links":{"self":[{"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/posts\/4206","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/comments?post=4206"}],"version-history":[{"count":1,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/posts\/4206\/revisions"}],"predecessor-version":[{"id":4207,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/posts\/4206\/revisions\/4207"}],"wp:attachment":[{"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/media?parent=4206"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/categories?post=4206"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/tags?post=4206"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}