×

Automated penetration analysis system and method

  • US 5,485,409 A
  • Filed: 04/30/1992
  • Issued: 01/16/1996
  • Est. Priority Date: 04/30/1992
  • Status: Expired due to Fees
First Claim
Patent Images

1. A method for preventing users of a computer system from exploiting system flaws to gain illegal or unintended access to system variables, objects and/or operations, comprising the steps of:

  • (1) generating a set of interpretation constants by applying a set of penetration-resistant properties to a given system, wherein said set of interpretation constants represent a database of required conditions, parameter validations and privilege checks that are associated with access to each abstract cell and critical function in said given system, wherein said given system has previously been determined to be penetration-resistant;

    (2) generating an integrated flow path within said given system which records information regarding flows and condition checks that would be encountered along a given integrated flow path to an alter operation or a view operation on a particular abstract cell or an invoke operation on an internal system function;

    (3) applying, in response to said alter operation, said view operation, or said invoke operation, a set of model rules to said given integrated flow path to determine whether said given integrated flow path conforms to said penetration-resistant properties, wherein said model rules are based on said interpretation constants; and

    (4) allowing said alter operation, said view operation, or said invoke operation to proceed if said given integrated flow path was in conformity with said penetration-resistant properties.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×