The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Mar. 28, 2017

Filed:

Sep. 22, 2013
Applicant:

International Business Machines Corporation, Armonk, NY (US);

Inventors:

Paolina Centonze, Amawalk, NY (US);

Yinnon Avraham Haviv, Beerotaim, IL;

Roee Hay, Haifa, IL;

Marco Pistoia, Amawalk, NY (US);

Adi Sharabani, Ramat Gan, IL;

Omer Tripp, Har-Adar, IL;

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/00 (2013.01); G06F 21/57 (2013.01); G06F 21/60 (2013.01); H04L 29/06 (2006.01);
U.S. Cl.
CPC ...
G06F 21/57 (2013.01); G06F 21/604 (2013.01); H04L 63/102 (2013.01); H04L 63/20 (2013.01);
Abstract

Access-control and information-flow integrity policies are enforced in a computing system by detecting security-sensitive sinks in software code for an application running on the computing system and retrieving an access-control policy from a database accessible to the computing system. The access-control policy maps a set of access permissions within the computing system to each one of a plurality of principals. For each detected security-sensitive sink, all principals that influence that security-sensitive sink are detected and an overall access permission is assigned to each security-sensitive sink by taking the intersection of the access permission sets for all influencing principals of that security-sensitive sink. If this permission set is inadequate, an integrity violation is reported. In addition, permission labels are assigned to each value of variables used in the security-sensitive sinks. Each permission label is a set of permissions.


Find Patent Forward Citations

Loading…