发明名称 Computer device and method for controlling access to a resource via a security system
摘要 A computer system that is configured to provide a resource to an application contains an agent 303 which modifies the ordinary behaviour of a native security system 103, such as to allow security decisions with alternate granularity or an alternate set of access rights. The agent 303 intercepts authorisation requests made by applications 109 for resources 110 identified by URIs 111 and sends amended requests to the security system 103. The intercepted URI is replaced with a URI that redirects to an alternate authorisation mechanism 307 of the agent 303, whereupon the agent 303 may selectively allow or deny the request according to the originally presented URI 111. This allows the least-privilege principal to be implemented while still enabling, legitimate applications to execute on the computer device by accessing the relevant resources, resulting in the computer device being better protected than granting additional privileges to all members of a relevant group.
申请公布号 GB2538518(A) 申请公布日期 2016.11.23
申请号 GB20150008577 申请日期 2015.05.19
申请人 Avecto Limited 发明人 John Goodridge;Simon Jonathan Fradkin
分类号 G06F21/62 主分类号 G06F21/62
代理机构 代理人
主权项
地址