US2017154190A1PendingUtilityA1

Methods, Systems, and Products for Secure Acces to File System Structures

Assignee: AT & T IP I LPPriority: Dec 2, 2008Filed: Feb 10, 2017Published: Jun 1, 2017
Est. expiryDec 2, 2028(~2.3 yrs left)· nominal 20-yr term from priority
G06F 21/31G06F 2221/2141G06F 21/6218G06F 21/552G06F 21/554G06F 21/577
39
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Methods, systems, and products secure access to a file system. A directory is established in a hierarchical file structure having access permission defined by a first owner. A subdirectory is established in the directory. A sub-level subdirectory is established in the subdirectory having access permissions defined by a second owner. The subdirectory is publically accessible to anyone satisfying the access permission defined by the first owner, such that a change directory system call is executed for a user in the subdirectory, even though the user has not authenticated the access permission defined by the second owner.

Claims

exact text as granted — not AI-modified
1 . A system, comprising:
 a hardware processor; and   a memory device, the memory device storing an operating system associated with a hierarchical file structure, the operating system when executed causing the hardware processor to perform operations, the operations comprising:   establishing a directory in the hierarchical file structure;   establishing multiple directory paths associated with the directory, each one of the multiple directory paths associated with a different access permission, and some of the multiple directory paths purposefully invalid as invalid directory paths;   summing a count of the invalid directory paths selected during authentication attempts associated with the directory;   comparing the count of the invalid directory paths to a threshold value; and   generating a security threat in response to the count of the invalid directory paths exceeding the threshold value.   
     
     
         2 . The system of  claim 1 , wherein the operations further comprise generating an alarm in response to the security threat. 
     
     
         3 . The system of  claim 1 , wherein the operations further comprise generating a notification in response to the security threat. 
     
     
         4 . The system of  claim 1 , wherein the operations further comprise determining a time associated with the authentication attempts. 
     
     
         5 . The system of  claim 4 , wherein the operations further comprise comparing the time to a threshold access time. 
     
     
         6 . The system of  claim 5 , wherein the operations further comprise generating another security threat in response to the time exceeding the threshold access time. 
     
     
         7 . The system of  claim 1 , wherein the operations further comprise associating the threshold value to a user. 
     
     
         8 . A method, comprising:
 establishing, by a server, a directory in the hierarchical file structure;   establishing, by the server, multiple directory paths associated with the directory, each one of the multiple directory paths associated with a different access permission, and some of the multiple directory paths purposefully invalid as invalid directory paths;   summing, by the server, a count of the invalid directory paths selected during authentication attempts associated with the directory;   comparing, by the server, the count of the invalid directory paths to a threshold value; and   generating, by the server, a security threat in response to the count of the invalid directory paths exceeding the threshold value.   
     
     
         9 . The method of  claim 8 , further comprising generating an alarm in response to the security threat. 
     
     
         10 . The method of  claim 8 , further comprising generating a notification in response to the security threat. 
     
     
         11 . The method of  claim 8 , further comprising determining a time associated with the authentication attempts. 
     
     
         12 . The method of  claim 11 , further comprising comparing the time to a threshold access time. 
     
     
         13 . The method of  claim 12 , further comprising generating another security threat in response to the time exceeding the threshold access time. 
     
     
         14 . The method of  claim 8 , further comprising associating the threshold value to a user. 
     
     
         15 . A memory device storing instructions that when executed cause a hardware processor to perform operations, the operations comprising:
 establishing a directory in the hierarchical file structure;   establishing multiple directory paths associated with the directory, each one of the multiple directory paths associated with a different access permission, and some of the multiple directory paths purposefully invalid as invalid directory paths;   summing a count of the invalid directory paths selected during authentication attempts associated with the directory;   comparing the count of the invalid directory paths to a threshold value; and   generating a security threat in response to the count of the invalid directory paths exceeding the threshold value.   
     
     
         16 . The memory device of  claim 15 , wherein the operations further comprise generating an alarm in response to the security threat. 
     
     
         17 . The memory device of  claim 15 , wherein the operations further comprise generating a notification in response to the security threat. 
     
     
         18 . The memory device of  claim 15 , wherein the operations further comprise determining a time associated with the authentication attempts. 
     
     
         19 . The memory device of  claim 18 , wherein the operations further comprise comparing the time to a threshold access time. 
     
     
         20 . The memory device of  claim 19 , wherein the operations further comprise generating another security threat in response to the time exceeding the threshold access time.

Join the waitlist — get patent alerts

Track US2017154190A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.