Using security-related attributes
Described is a technology including an evaluation methodology by which a set of privileged code such as a platform's API method may be marked as being security critical and/or safe for being called by untrusted code. The set of code is evaluated to determine whether the code is security critica...
Saved in:
Main Authors | , , , , , , , , , , , , |
---|---|
Format | Patent |
Language | English |
Published |
12.04.2011
|
Subjects | |
Online Access | Get full text |
Cover
Loading…
Summary: | Described is a technology including an evaluation methodology by which a set of privileged code such as a platform's API method may be marked as being security critical and/or safe for being called by untrusted code. The set of code is evaluated to determine whether the code is security critical code, and if so, it is identified as security critical. Such code is further evaluated to determine whether the code is safe with respect to being called by untrusted code, and if so, is marked as safe. To determine whether the code is safe, a determination is made as to whether the first set of code leaks criticality, including by evaluating one or more code paths corresponding to one or more callers of the first set of code, and by evaluating one or more code paths corresponding to one or more callees of the first set of code. |
---|---|
Bibliography: | Application Number: US20060364359 |