IP Library Granted Patent US 8,087,065
Granted Patent B2
US 8,087,065 · App. 11/703,778 · Granted Dec 27, 2011

Method and system for implementing mandatory file access control in native discretionary access control environments

Assignee: McAfee, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,087,065
App. No.
11/703,778
Granted
Dec 27, 2011
Kind
B2
Abstract

A method is provided for implementing a mandatory access control model in operating systems which natively use a discretionary access control scheme. A method for implementing mandatory access control in a system comprising a plurality of computers, the system comprising a plurality of information assets, stored as files on the plurality of computers, and a network communicatively connecting the plurality of computers, wherein each of the plurality of computers includes an operating system that uses a discretionary access control policy, and wherein each of a subset of the plurality of computers includes a software agent component operable to perform the steps of intercepting a request for a file operation on a file from a user of one of the plurality of computers including the software agent, determining whether the file is protected, if the file is protected, altering ownership of the file from the user to another owner, and providing access to the file based on a mandatory access control policy.

Claims (67)

1. A method for implementing mandatory access control in a system comprising a plurality of computers, the system comprising a plurality of information assets, stored as files on the plurality of computers, and a network communicatively connecting the plurality of computers, wherein each of the plurality of computers includes an operating system that uses a discretionary access control policy, and wherein each of a subset of the plurality of computers includes a software agent component operable to perform the steps of:

intercepting a request for a file operation on a file from a user of one of a plurality of computers including a software agent;

determining whether the file is protected based on a mandatory access control policy;

determining whether the file is on storage local to or remote from the computer from which the request for the file operation occurred; and

providing access to the file based on the mandatory access control policy wherein providing access to the file comprises:

if the file is protected and on local storage:

altering ownership of the file from the user to another owner;

setting an access control list of the file based on the mandatory access control policy; and

if the file is protected and on remote storage:

setting an access control list of the file to allow another owner to take ownership of the file;

reopening the file using permissions of the other owner;

setting ownership of the file to the other owner; and

setting an access control list of the file based on the mandatory access control policy.

2. The method of claim 1 , wherein the requested file operation is at least one of creating the file, writing to the file, or closing the file.

3. The method of claim 1 , wherein the step of setting the access control list of the file if the file is protected and on local storage comprises the step of:

setting the access control list of the file so as to prevent a user from accessing the file from a computer that does not include the software agent component.

4. The method of claim 1 , wherein if the file is protected and on remote storage, the other owner is an account associated with a requesting computer from which the request for the file operation occurred.

5. The method of claim 4 , wherein the software agent component accesses the account associated with the requesting computer through a login session already associated with the requesting computer.

6. The method of claim 4 , wherein the other owner is a separate account for which the agent provides login information and creates a login session.

7. The method of claim 4 , further comprising the steps of:

intercepting a request for a file read operation on a file from a user of one of the plurality of computers including the software agent;

altering the read request; and

performing the altered read request using a login session not associated with the user.

8. The method of claim 7 , wherein the login session is established by the software agent component using login information associated with the other owner.

9. The method of claim 4 , further comprising the steps of:

intercepting a request for a file read operation on a file from a user of one of the plurality of computers including the software agent;

altering the read request; and

performing the altered read request using another login session associated with the user, but having a different set of group memberships than a login session used to request the file read operation.

10. The method of claim 9 , wherein the other login session does not have membership in at least one group to which the login session belongs.

11. The method of claim 10 , further comprising the steps of:

removing a group membership of a user account;

forming a login session for the user account; and

restoring the group membership of the user account.

12. The method of claim 1 , further comprising the steps of:

intercepting an attempt to modify an access control list of a file; and

allowing the modification based on a criterion.

13. The method of claim 12 , further comprising the step of:

altering a parameter of the attempt to modify an access control list of a file.

14. The method of claim 1 , wherein intercepting the request for the file operation includes intercepting system calls from user processes to an operating system and altering parameters and results of the system calls, utilizing the software agent.

15. A computer program product embodied on a non-transitory computer readable medium, the computer program product comprising a software agent for implementing a mandatory access control in a system comprising a plurality of computers, wherein each of the plurality of computers includes an operating system that uses a discretionary access control policy, and wherein each of a subset of the plurality of computers includes the software agent component, the computer readable medium comprising:

computer code for intercepting a request for a file operation on a file from a user of one of a plurality of computers including the software agent;

computer code for determining whether the file is protected based on a mandatory access control policy;

computer code for determining whether the file is on storage local to or remote from the computer from which the request for the file operation occurred; and

computer code for providing access to the file based on a mandatory access control policy;

wherein the computer code is operable such that providing access to the file includes:

if the file is protected and on local storage:

altering ownership of the file from the user to another owner;

setting an access control list of the file based on the mandatory access control policy; and

if the file is protected and on remote storage:

setting an access control list of the file to allow another owner to take ownership of the file;

reopening the file using permissions of the other owner;

setting ownership of the file to the other owner; and

setting an access control list of the file based on the mandatory access control policy.

16. A system, comprising:

a processor for executing a software agent component, the software agent component for implementing a mandatory access control in a system comprising a plurality of computers, wherein each of the plurality of computers includes an operating system that uses a discretionary access control policy, and wherein each of a subset of the plurality of computers includes the software agent component, the software agent component configuring the processor to:

intercept a request for a file operation on a file from a user of one of a plurality of computers including a software agent;

determine whether the file is protected based on a mandatory access control policy;

determine whether the file is on storage local to or remote from the computer from which the request for the file operation occurred; and

provide access to the file based on the mandatory access control policy wherein the act of providing access to the file comprises:

if the file is protected and on local storage:

altering ownership of the file from the user to another owner; and

setting an access control list of the file based on the mandatory access control policy;

if the file is protected and on remote storage:

setting an access control list of the file to allow another owner to take ownership of the file;

reopening the file using permissions of the other owner;

setting ownership of the file to the other owner; and

setting an access control list of the file based on the mandatory access control policy.

Assignments (21)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 1, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060561/0466 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 8, 2007
From: TIROSH, OREN; WERNER, ERAN
To: MCAFEE, INC
Reel/Frame 018979/0949 →
Continuity (1)
Related Publication 20080120695A1 · May 22, 2008