发明名称 Merging mandatory access control (MAC) policies in a system with multiple execution containers
摘要 Application of a local instance of a general security policy is described. In a system with an instance of a program executing in a path container, a security policy applicable the the instance of the program is managed locally for the path container. The path container provides a confined execution environment for the program instance, and the security policy defines permitted operations for the program an all its instances. The instance of the security policy is associated with the path container, which allows the program instance to "see" management within the path container as though with the security policy, while entities having permissions outside the path container "see" the program instance limited to the path container and its associated security policy instance.
申请公布号 US8479256(B2) 申请公布日期 2013.07.02
申请号 US20080324677 申请日期 2008.11.26
申请人 VAN RIEL HENRI H.;WALSH DANIEL J.;TOGAMI, JR. WARREN I.;RED HAT, INC. 发明人 VAN RIEL HENRI H.;WALSH DANIEL J.;TOGAMI, JR. WARREN I.
分类号 G06F9/00;G06F17/30 主分类号 G06F9/00
代理机构 代理人
主权项
地址