首页> 外国专利> Elevating security privileges for creation and use of component object model (COM) objects without escalating to administrator profile.

Elevating security privileges for creation and use of component object model (COM) objects without escalating to administrator profile.

机译:提升安全特权,以创建和使用组件对象模型(COM)对象,而无需升级到管理员配置文件。

摘要

Component object model (COM) objects are created and used by a user without the need to upgrade to administrator privileges by using a black and white list of COM policies which is administered by software which sits between existing software structures, intercepts calls to create and use COM objects, and allows/denies them according to the predefined security policies. This bypasses the need for a user to obtain administrator privileges by customising the security access control to a much more granular level than the standard Microsoft (RTM) user account control (UAC) system. A COM creating unit 800 intercepts a request for creation of an elevated COM object by a first user process, determines whether the first user process is entitled to access the COM object, and creates the COM object without elevated privileges. A COM implementing unit intercepts a second user process that implements the COM object, confirms that the second user process is entitled to access the COM object and elevates the privilege level of the second user process to implement the elevated COM object.
机译:组件对象模型(COM)对象由用户创建和使用,而无需通过使用COM策略黑白名单来升级到管理员权限,该黑白名单由位于现有软件结构之间的软件管理,拦截创建和使用的调用COM对象,并根据预定义的安全策略允许/拒绝它们。通过将安全访问控制自定义到比标准Microsoft(RTM)用户帐户控制(UAC)系统更精细的级别,从而无需用户获得管理员特权。 COM创建单元800拦截由第一用户进程创建提升的COM对象的请求,确定第一用户进程是否有权访问COM对象,并且创建没有提升特权的COM对象。 COM实现单元拦截实现COM对象的第二用户进程,确认第二用户进程有权访问COM对象,并提高第二用户进程的特权级别以实现提升的COM对象。

著录项

  • 公开/公告号GB2501469A

    专利类型

  • 公开/公告日2013-10-30

    原文格式PDF

  • 申请/专利权人 AVECTO LIMITED;

    申请/专利号GB20120006639

  • 发明设计人 JOHN GOODRIDGE;MARK JAMES AUSTIN;

    申请日2012-04-16

  • 分类号G06F21/12;G06F9/54;

  • 国家 GB

  • 入库时间 2022-08-21 16:20:13

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号