发明名称 Analyzing access control configurations
摘要 A facility is described for analyzing access control configurations. In various embodiments, the facility comprises an operating system having resources and identifications of principals, the principals having access control privileges relating to the resources, the access control privileges described by access control metadata; an access control scanner component that receives the access control metadata, determines relationships between principals and resources, and emits access control relations information; and an access control inference engine that receives the emitted access control relations information and an access control policy model, analyzes the received information and model, and emits a vulnerability report. In various embodiments, the facility generates an information flow based on access control relations, an access control mechanism model, and an access control policy model; determines, based on the generated information flow, whether privilege escalation is possible; and when privilege escalation is possible, indicates in a vulnerability report that privilege escalation is possible.
申请公布号 US8701200(B2) 申请公布日期 2014.04.15
申请号 US201213610702 申请日期 2012.09.11
申请人 NALDURG PRASAD G.;RAJAMANI SRIRAM K.;SCHWOON STEFAN;LAMBERT JOHN;MICROSOFT CORPORATION 发明人 NALDURG PRASAD G.;RAJAMANI SRIRAM K.;SCHWOON STEFAN;LAMBERT JOHN
分类号 G06F7/04;G06F11/00;G06F21/00 主分类号 G06F7/04
代理机构 代理人
主权项
地址