User-based Security Model
SNMP version 3 (SNMPv3) (RFC 2570 through 2575) introduces a User-based Security model (USM) (RFC 2574) for authentication and privacy services.
SNMP version 1 and version 2 use community strings to authenticate SNMP access to management modules. This method can still be used for authentication. In SNMPv3, the User-based Security Model can be used to secure against the following threats:
- Modification of information
- Masquerading the identity of an authorized entity
- Message stream modification
- Disclosure of information
SNMPv3 also supports the View-based Access Control Mechanism (VACM) (RFC 2575) to control access at the PDU level. It defines mechanisms for determining whether access to a managed object in a local MIB by a remote principal should be allowed. For more information, refer to SNMPv3 Configuration Examples.