发明名称 System, apparatus, and method for identifying authorization requirements in component-based systems
摘要 Improved detecting the authorization requirements and defining the security policies for an application comprising one or more components is disclosed. A call and resource-access graph is used to model all the possible paths of execution within the application. Then, paths of execution detected during the analysis are combined with the access control information found in the security policy of the application. Finally, for each authorization point in the application, a minimal security policy is reported that the executing principal should be granted in order to pass the authorization successfully.
申请公布号 US2005262487(A1) 申请公布日期 2005.11.24
申请号 US20040842805 申请日期 2004.05.11
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 PISTOIA MARCO;KOVED LAWRENCE;CENTONZE PAOLINA
分类号 G06F9/45;G06F9/46;G06F21/00;(IPC1-7):G06F9/45 主分类号 G06F9/45
代理机构 代理人
主权项
地址