发明名称 IDENTIFYING UNAUTHORIZED PRIVILEGE ESCALATIONS
摘要 Disclosed herein is a method and system of determining and/or managing potential privilege escalation attacks in a system or network comprising one or more potentially heterogeneous hosts. The step of configuration scanning optionally includes making a list of operating system specific protection mechanism on each host. Vulnerability scanning optionally includes the step of identifying the vulnerability position of each identified program. Transitive closure of all security attacks on the network and potential privilege escalations can be determined. A user interface optionally renders the potential privilege escalations as an appropriate representation. The method may include none or one or more of several pre-emptive mechanisms and reactive mechanisms. Further, the method may optionally include a mechanism for a periodic safety check on the system ensuring continued security on the network.
申请公布号 WO2007089786(B1) 申请公布日期 2008.06.12
申请号 WO2007US02549 申请日期 2007.01.30
申请人 GOVINDAVAJHALA, SUDHAKAR;APPEL, ANDREW, W. 发明人 GOVINDAVAJHALA, SUDHAKAR;APPEL, ANDREW, W.
分类号 G06F15/18 主分类号 G06F15/18
代理机构 代理人
主权项
地址
您可能感兴趣的专利