首页> 外国专利> Generating rule-based access control policies using a bytecode instrumentation system

Generating rule-based access control policies using a bytecode instrumentation system

机译:使用字节码检测系统生成基于规则的访问控制策略

摘要

Instrumentation codes are inserted into predetermined portions of a bytecode. Every transaction referenced in the bytecode is virtually combined and arranged hierarchically to describe a virtual transaction stack describing the computer-based resources accessed during the transaction. Based at least on the origin of the transaction, the characteristics of the transaction and the computer-based resources accessed during the transaction, the sensitivity of the transaction, and the security context of each of the computer-based resources accessed during the transaction are determined. A policy store is searched for at least one access control policy referencing the transaction, or the computer-based resources requested accessed by the transaction. If such an access control policy is found, it is selectively modified to refer exclusively to the transaction and the corresponding sensitive computer-based resources. Otherwise, a new access control policy exclusively referencing the data-oriented transactions and the corresponding sensitive computer-based resources is created.
机译:插装码插入字节码的预定部分。字节码中引用的每个事务实际上是按层次进行组合和排列的,以描述一个虚拟事务堆栈,该堆栈描述了在事务期间访问的基于计算机的资源。至少基于事务的来源,确定事务的特征和事务期间访问的基于计算机的资源、事务的敏感性以及事务期间访问的每个基于计算机的资源的安全上下文。在策略存储中搜索至少一个引用该事务的访问控制策略,或该事务请求访问的基于计算机的资源。如果找到这样的访问控制策略,则会有选择地对其进行修改,以专门引用事务和相应的基于计算机的敏感资源。否则,将创建一个新的访问控制策略,专门引用面向数据的事务和相应的基于计算机的敏感资源。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号