发明名称 Method for adding external security to file system resources through symbolic link references
摘要 The method of the invention assumes there is a security manager and mechanism present for defining, attaching, and evaluating external authorization policy to file resources based on the file's path name. In this invention, protected symbolic links and the resources that the link points to are stored in a protected object database. When a system access attempt occurs, the file attribute is extracted from the file used in the access. The file attribute is then used to search the protected object database. If a matching system resource is found, and that resource is protected but does not have independent security policy on it, then the resource will have the security policy of a symbolic link that points to it. In this case, the security of each protected symbolic link pointing to the system resource has to grant access in order for allowance of the access attempt. This approach insures that the most restrictive outcome prevails.
申请公布号 US2002162013(A1) 申请公布日期 2002.10.31
申请号 US20010843072 申请日期 2001.04.26
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 BURNETT RODNEY CARLTON;BARTLEY TIMOTHY SIMON;POWELL MICHAEL
分类号 G06F21/00;(IPC1-7):G06F12/14 主分类号 G06F21/00
代理机构 代理人
主权项
地址