发明名称 ISOLATING AN EXECUTION CONTAINER IN A SYSTEM WITH MANDATORY ACCESS CONTROL (MAC)
摘要 Preventing a process from traversing back a directory tree through its parent directories is described. In a system with a program executing in a path container, an access permission rule applicable to the instance of the program prevents the program from traversing the tree structure back through its parent directories towards an absolute root directory. The access permission rule may be a rule in an instance of a security policy applicable to the particular path container from which the process is executing.
申请公布号 US2010131559(A1) 申请公布日期 2010.05.27
申请号 US20080324643 申请日期 2008.11.26
申请人 RED HAT, INC. 发明人 VAN RIEL HENRI H.;WALSH DANIEL J.;TOGAMI, JR. WARREN I.
分类号 G06F17/30 主分类号 G06F17/30
代理机构 代理人
主权项
地址