The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Mar. 23, 2021

Filed:

Nov. 06, 2019
Applicant:

International Business Machines Corporation, Armonk, NY (US);

Inventors:

Matthias Daniel Dietsch, Freiburg, DE;

Pietro Ferrara, White Plains, NY (US);

Marco Pistoia, Amawalk, NY (US);

Omer Tripp, Bronx, NY (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/00 (2013.01); G06F 21/57 (2013.01); G06F 21/52 (2013.01); G06F 30/33 (2020.01);
U.S. Cl.
CPC ...
G06F 21/577 (2013.01); G06F 21/52 (2013.01); G06F 30/33 (2020.01); G06F 2221/033 (2013.01);
Abstract

Techniques for identifying computer program security access control violations using static program analysis are provided. In one example, a computer-implemented method comprises generating, by a device operatively coupled to a processor, a mathematical model of a computer program product, wherein the mathematical model defines data flows through nodes of the computer program product that reach a secure node corresponding to a secure resource. The computer implemented method further comprises evaluating, by the device, a security protocol of the computer program product using static program analysis of the mathematical model to determine whether any of the data flows provides access to the secure node without proceeding through one or more security nodes corresponding to the security protocol, wherein the one or more security nodes are included in the nodes of the computer program product.


Find Patent Forward Citations

Loading…