发明名称 Using security-related attributes
摘要 Described is a technology including an evaluation methodology by which a set of privileged code such as a platform's API method may be marked as being security critical and/or safe for being called by untrusted code. The set of code is evaluated to determine whether the code is security critical code, and if so, it is identified as security critical. Such code is further evaluated to determine whether the code is safe with respect to being called by untrusted code, and if so, is marked as safe. To determine whether the code is safe, a determination is made as to whether the first set of code leaks criticality, including by evaluating one or more code paths corresponding to one or more callers of the first set of code, and by evaluating one or more code paths corresponding to one or more callees of the first set of code.
申请公布号 US7926105(B2) 申请公布日期 2011.04.12
申请号 US20060364359 申请日期 2006.02.28
申请人 MICROSOFT CORPORATION 发明人 CORBY KAREN ELIZABETH;ALCAZAR MARK;RAMDATMISIER VIRESH;KIRSMAN ARIEL JORGE;NEEDHAM ANDRE A.;KAZA AKHILESH;KRISHNASWAMY RAJA;COOPERSTEIN JEFF;KAUFMAN CHARLES W;ANDERSON CHRIS;TAMMANA VENKATA RAMA PRASAD;GOLDFEDER AARON R;HAWKINS JOHN
分类号 G06F11/00;G06F12/14;G06F12/16;G08B23/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址