发明名称 System and method for the automatic verification of privilege-asserting and subject-executed code
摘要 The present relates to a method for verifying privileged and subject-executed code within a program, the method further comprising the steps of constructing a static model of a program, identifying checkPermission nodes that are comprised within the invocation graph, and performing a fixed-point iteration, wherein each determined permission set is propagated backwards across the nodes of the static model until a privilege-asserting code node is reached. The method further comprises the steps of associating each node of the invocation graph with a set of Permission allocation sites, analyzing each identified privilege-asserting code node and subject-executing code node to determine the Permission allocation site set that is associated with each privilege-asserting code node and subject-executing code node, and determining the cardinality of a Permission allocation-site set that is associated with each privilege-asserting code node and subject-executing code node.
申请公布号 US8006233(B2) 申请公布日期 2011.08.23
申请号 US20070677259 申请日期 2007.02.21
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 CENTONZE PAOLINA;PISTOIA MARCO
分类号 G06F9/44;G06F9/45 主分类号 G06F9/44
代理机构 代理人
主权项
地址