Automatically generating security policies for web services
    2.
    发明授权
    Automatically generating security policies for web services 有权
    自动生成Web服务的安全策略

    公开(公告)号:US07559080B2

    公开(公告)日:2009-07-07

    申请号:US11025375

    申请日:2004-12-29

    IPC分类号: G06F21/00

    摘要: Systems and methods for automatically generating security policy for a web service are described. In one aspect, one or more links between one or more endpoints are described with an abstract link description. The abstract link description describes, for each link of the one or more links, one or more security goals associated with exchange of message(s) between the one or more endpoints associated with the link. The one or more endpoints host respective principals networked in a distributed operating environment. Detailed security policies for enforcement during exchange of messages between the one or more endpoints are automatically generated from the abstract link description.

    摘要翻译: 描述了用于自动生成Web服务的安全策略的系统和方法。 在一个方面,一个或多个端点之间的一个或多个链路用抽象链接描述来描述。 抽象链接描述针对一个或多个链接的每个链接描述与在与链接相关联的一个或多个端点之间的消息交换相关联的一个或多个安全目标。 一个或多个端点托管在分布式操作环境中联网的各个主体。 在一个或多个端点之间的消息交换期间执行的详细的安全策略是从抽象链接描述中自动生成的。

    Reviewing the security of trusted software components
    3.
    发明授权
    Reviewing the security of trusted software components 有权
    检查可信软件组件的安全性

    公开(公告)号:US07437718B2

    公开(公告)日:2008-10-14

    申请号:US10656654

    申请日:2003-09-05

    IPC分类号: G06F9/44 G06F17/00

    CPC分类号: G06F21/577 G06F2221/033

    摘要: An analysis tool provides a call path set for reviewing the security of trusted software components during development. By examining the usage of permissions in programs and libraries within a managed execution environment, potential gaps in the security of trusted components may be identified. A call graph generator creates a permission-sensitive call graph. A call graph analyzer evaluates the permission-sensitive call graph to highlight call paths that may present security risks.

    摘要翻译: 分析工具提供了一个调用路径集,用于在开发期间查看可信软件组件的安全性。 通过检查受管执行环境中的程序和库中的权限的使用,可以识别可信组件的安全性中的潜在差距。 调用图生成器创建一个权限敏感的调用图。 调用图分析器评估权限敏感的调用图,以突出可能存在安全风险的呼叫路径。

    CHECKING AND/OR COMPLETION FOR DATA GRIDS
    4.
    发明申请
    CHECKING AND/OR COMPLETION FOR DATA GRIDS 审中-公开
    检查和/或完成数据网

    公开(公告)号:US20130346844A1

    公开(公告)日:2013-12-26

    申请号:US13530121

    申请日:2012-06-22

    IPC分类号: G06F17/20

    摘要: Checking and/or completing for data grids is described such as for grids having rows and columns of cells at least some of which contain data values such as numbers or categories. In various embodiments predictive probability distributions are obtained from an inference engine for one or more of the cells and the predictive probability distributions are used for various tasks such as to suggest values to complete blank cells, highlight cells having outlying values, identify potential errors, suggest corrections to potential errors, identify similarities between cells, identify differences between cells, cluster rows of the data grid, and other tasks. In various embodiments a graphical user interface displays a data grid and provides facilities for completing, error checking/correcting, and analyzing data in the data grid.

    摘要翻译: 描述数据网格的检查和/或完成,例如对于具有行和列的单元格的网格,其中至少一些包含诸如数字或类别的数据值。 在各种实施例中,从针对一个或多个单元的推理引擎获得预测概率分布,并且将预测概率分布用于各种任务,例如建议完成空白单元的值,突出显示具有偏离值的单元格,识别潜在错误,建议 纠正潜在的错误,识别单元格之间的相似性,识别单元格之间的差异,数据网格的集群行和其他任务。 在各种实施例中,图形用户界面显示数据网格并提供用于完成,错误检查/校正和分析数据网格中的数据的设施。