发明名称 SYSTEM AND METHOD FOR DETERMINING SYMANTIC EQUIVALENCE BETWEEN ACCESS CONTROL LISTS
摘要 Aspects of the invention pertain to analyzing and modifying access control lists that are used in computer networks. Access control lists may have many individual rules that indicate whether information can be passed between certain devices in a computer network. The access control lists may include redundant or conflicting rules. An aspect of the invention determines whether two or more access control lists are equivalent or not. Order-dependent access control lists are converted into order-independent access control lists, which enable checking of semantic equivalence of different access control lists. Upon conversion to an order-independent access control list, lower-precedence rules in the order-free list are checked for overlap with a current higher precedence entry. If overlap exists, existing order-free rules are modified so that spinoff rules have no overlap with the current entry. This is done while maintaining semantic equivalence.
申请公布号 US2010199346(A1) 申请公布日期 2010.08.05
申请号 US20090634975 申请日期 2009.12.10
申请人 TELCORDIA TECHNOLOGIES, INC. 发明人 LING YIBEI;NAIDU ADITYA;TALPADE RAJESH
分类号 G06F9/32 主分类号 G06F9/32
代理机构 代理人
主权项
地址