发明名称 |
METHOD AND SYSTEM FOR RUN-TIME DYNAMIC AND INTERACTIVE IDENTIFICATION OF SOFTWARE AUTHORIZATION REQUIREMENTS AND PRIVILEGED CODE LOCATIONS, AND FOR VALIDATION OF OTHER SOFTWARE PROGRAM ANALYSIS RESULTS |
摘要 |
A system, method and computer program product for identifying security authorizations and privileged-code requirements; for validating analyses performed using static analyses; for automatically evaluating existing security policies; for detecting problems in code; in a run¬ time execution environment in which a software program is executing. The method comprises: implementing reflection objects for identifying program points in the executing program where authorization failures have occurred in response to the program's attempted access of resources requiring authorization; displaying instances of identified program points via a user interface, the identified instances being user selectable; for a selected program point, determining authorization and privileged-code requirements for the access restricted resources in real-time; and, enabling a user to select, via the user interface, whether a required authorization should be granted, wherein local system, fine-grained access of resources requiring authorizations is provided. |
申请公布号 |
WO2007130356(A2) |
申请公布日期 |
2007.11.15 |
申请号 |
WO2007US10461 |
申请日期 |
2007.04.30 |
申请人 |
INTERNATIONAL BUSINESS MACHINES CORPORATION;CENTONZE, PAOLINA;GOMES, JOSE;PISTOIA, MARCO |
发明人 |
CENTONZE, PAOLINA;GOMES, JOSE;PISTOIA, MARCO |
分类号 |
H04L9/32;G06F7/04;G06F17/30;G06K9/00;H03M1/68;H04K1/00;H04L9/00;H04N7/16 |
主分类号 |
H04L9/32 |
代理机构 |
|
代理人 |
|
主权项 |
|
地址 |
|