US2005044381A1PendingUtilityA1

System & method of table building for a process-based security system using intrusion detection

Priority: Feb 1, 2002Filed: Oct 27, 2003Published: Feb 24, 2005
Est. expiryFeb 1, 2022(expired)· nominal 20-yr term from priority
G06F 2221/2141G06F 21/6218
33
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method to build a resource access table in a system for controlling access to resources is disclosed. The protocol identifies a resource call in a process. Each of the resources accessed by resource calls are identified and routed to intrusion detection software for analysis. Permission is assigned to the resource, with regard to the process. A resource access table is written, with each entry identifying the process, the resource and the permission. When the process is executed and the process makes a resource call to the resource, access to the resource is controlled by the permission data entry in the resource access table entry of the resource access table.

Claims

exact text as granted — not AI-modified
1 . A method of building a resource access table in a system for controlling access to resources comprising the steps of: 
 identifying a resource call in a process;    identifying a resource accessed by the resource call;    analyzing the resource call by an intrusion detection module;    assigning permission to the resource;    writing a resource access table entry in a resource access table including data identifying the process, the resource and the permission;    such that when the process is executed and the process makes a resource call to the resource, access to the resource may be controlled by the permission data entry in the resource access table entry of the resource access table.    
   
   
       2 . The method of building a resource access table of  claim 1 , wherein the step of identifying a resource call in a process is automated.  
   
   
       3 . The method of building a resource access table of  claim 1 , wherein the step of identifying a resource accessed by the resource call is performed by a computer.  
   
   
       4 . The method of building a resource access table of  claim 1 , wherein the step of assigning permission data to the resource is performed by software.  
   
   
       5 . The method of building a resource access table of  claim 1 , further including the step of writing a resource access table entry to a process resource access table.  
   
   
       6 . The method of building a resource access table of  claim 5 , wherein said process resource access table is compiled to generate a resource access table.  
   
   
       7 . A method of building a resource access table in a system for controlling access to resources comprising the steps of: 
 identifying a resource call in a process;    identifying a resource accessed by the resource call;    analyzing the resource call by an intrusion detection module.    assigning permission to the resource call;    writing a resource access table entry in a resource access table including data identifying the process, the resource call, the resource and the permission;    such that when the process is executed and the process makes a resource call to the resource, access to the resource may be controlled by the permission data in the resource access table entry of the resource access table.    
   
   
       8 . The method of building a resource access table of  claim 7 , wherein the step of identifying a resource call in a process is automated.  
   
   
       9 . The method of building a resource access table of  claim 7 , wherein the step of identifying a resource accessed by the resource call is performed by a computer.  
   
   
       10 . The method of building a resource access table of  claim 7 , wherein the step of assigning permission data to the resource is performed by software.  
   
   
       11 . The method of building a resource access table of  claim 7 , further including the step of writing a resource access table entry to a process resource access table.  
   
   
       12 . The method of building a resource access table of  claim 11 , wherein said process resource access table is compiled to generate a resource access table.  
   
   
       13 . A method of controlling access to resources comprising the steps of: 
 identifying a resource call from a process;    identifying a resource accessed by the resource call;    determining if the process is associated with a resource access table;    checking process permissions and granting access to the resource in accordance with said process permissions when the process is associated with a resource access table; and    checking user permissions and granting access to the resource in accordance with said user permissions when the process is not associated with a resource access table.    
   
   
       14 . The method of controlling access of  claim 13 , wherein said user permissions are UNIX permissions.  
   
   
       15 . The method of controlling access of  claim 13 , wherein said step of identifying a resource call is performed by an operating system.  
   
   
       16 . The method of controlling access of  claim 13 , further comprising the step of analyzing the resource call to generate a resource access table.  
   
   
       17 . The method of controlling access of  claim 16 , wherein said analyzing the resource call is performed by intrusion detection methods.  
   
   
       18 . The method of controlling access of  claim 13 , wherein said resource is a process.  
   
   
       19 . The method of controlling access of  claim 13 , wherein said process permissions define resources that can be accessed by the process.  
   
   
       20 . The method of controlling access of  claim 13 , wherein said process permissions define resources that can be accessed by a process resource call.

Join the waitlist — get patent alerts

Track US2005044381A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.