发明申请
US20100043048A1 System, Method, and Apparatus for Modular, String-Sensitive, Access Rights Analysis with Demand-Driven Precision
有权
用于采用需求驱动精度的模块化,字符串敏感的访问权限分析的系统,方法和装置
- 专利标题: System, Method, and Apparatus for Modular, String-Sensitive, Access Rights Analysis with Demand-Driven Precision
- 专利标题(中): 用于采用需求驱动精度的模块化,字符串敏感的访问权限分析的系统,方法和装置
-
申请号: US12190718申请日: 2008-08-13
-
公开(公告)号: US20100043048A1公开(公告)日: 2010-02-18
- 发明人: Julian Timothy Dolby , Emmanuel Geay , Marco Pistoia , Barbara G. Ryder , Takaaki Tateishi
- 申请人: Julian Timothy Dolby , Emmanuel Geay , Marco Pistoia , Barbara G. Ryder , Takaaki Tateishi
- 申请人地址: US NY ARMONK
- 专利权人: INTERNATIONAL BUSINESS MACHINES CORPORATION
- 当前专利权人: INTERNATIONAL BUSINESS MACHINES CORPORATION
- 当前专利权人地址: US NY ARMONK
- 主分类号: G06F21/00
- IPC分类号: G06F21/00
摘要:
A static analysis for identification of permission-requirements on stack-inspection authorization systems is provided. The analysis employs functional modularity for improved scalability. To enhance precision, the analysis utilizes program slicing to detect the origin of each parameter passed to a security-sensitive function. Furthermore, since strings are essential when defining permissions, the analysis integrates a sophisticated string analysis that models string computations.
公开/授权文献
信息查询