发明授权
- 专利标题: System for protecting domain system configurations from users with local privilege rights
- 专利标题(中): 具有本地特权权限的用户保护域系统配置的系统
-
申请号: US10710491申请日: 2004-07-15
-
公开(公告)号: US08060937B2公开(公告)日: 2011-11-15
- 发明人: Nicholas M. Carroll
- 申请人: Nicholas M. Carroll
- 申请人地址: US CA Los Angeles
- 专利权人: Lieberman Software Corporation
- 当前专利权人: Lieberman Software Corporation
- 当前专利权人地址: US CA Los Angeles
- 代理机构: Patent Venture Group
- 代理商 Raymond E. Roberts
- 主分类号: G06F21/00
- IPC分类号: G06F21/00 ; G06F21/24 ; G06F7/04
摘要:
A group change lockout system for protecting the configuration of a securable object in an operating system from members of a locally privileged group, such as the local administrators group, when a security descriptor exists for the securable object that includes a discretionary access control list (DACL). A copy of the security descriptor is made. Then a new access control entry (ACE) is added to the DACL in the copy. This new ACE specifies denying the local administrators group an access right to the securable object. Then the security descriptor in the operating system is overwritten with the copy.
公开/授权文献
信息查询