IP Library › Granted Patent US 8,082,590
Granted Patent B2
US 8,082,590 · App. 12/055,381 · Granted Dec 20, 2011

Apparatus and method of detecting and controlling privilege level violation process

Assignee: Electronics and Telecommunications Research Institute
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,082,590
App. No.
12/055,381
Granted
Dec 20, 2011
Kind
B2
Abstract

Provided are an apparatus and method of detecting and controlling a privilege level violation process. The apparatus monitors whether higher-privileged processes depend on information provided from lower-privileged objects or denies the higher-privileged processes to access the lower-privileged objects. The apparatus is provided in a process, and monitors whether a process accesses to a lower-privileged object. The apparatus gives a warning message or denies an access of the process to the lower-privileged object when it detects that the higher-privileged process access to the lower-privileged object. Therefore, the apparatus of detecting and controlling a privilege level violation process detects weaknesses that may be caused by privilege level violation, thus allowing a system to be safely operated.

Claims (11)

1. A method of detecting and controlling a privilege level violation process when a process accesses an object, the method comprising: determining whether the process having a high privilege level accesses the object having a relatively lower privilege level detecting an access of the process to the object; acquiring process information of the process accessing the object; acquiring object information of the object; determining whether a privilege level of the process is higher than a privilege level of the object by comparing the privilege levels with each other using the process information with the object information; and interrupting execution of the process or outputting a warning message according to a user's setting when the privilege level of the process is determined to be higher than the privilege level of the object.

2. The method of claim 1 , wherein an access of the process having a high privilege level to the object having a relatively low privilege level is a reading.

3. The method of claim 1 , wherein the process information includes information regarding a privilege level of the process and a name and a pathname of the process.

4. The method of claim 1 , wherein the object information includes information regarding the privilege level of the object, and a name and a pathname of the object.

5. The method of claim 1 , wherein the warning message includes a name and a pathname of a privilege level violation process, a name and a pathname of an object to be accessed, and privilege levels of the process and the object when the warning message is outputted.

6. A method of detecting and controlling a privilege level violation process when a process accesses an object, the method comprising: determining whether the process having a high privilege level accesses the object having a relatively lower privilege level detecting an access of the process to the object; acquiring process information of the process accessing the object; acquiring object information of the object; determining whether a privilege level of the process is higher than a privilege level of the object by comparing the privilege levels with each other using the process information with the object information; and interrupting execution of the process or outputting a warning message according to a user's setting when the privilege level of the process is determined to be higher than the privilege level of the object, wherein interrupting execution of the process or outputting a warning message according to a user's setting comprises: determining whether the user's setting is preset to give the warning message on process violation and giving a warning message to a user when it is determined that the user's setting is preset to give the warning message; inquiring from the user whether the process is allowed to access the lower-privileged object and receiving allowance or denial for access from the user.

7. The method of claim 6 , wherein the warning message displays a name and a pathname of the process, a name and a pathname of the object, and privilege levels of the process and the object.

8. The method of claim 6 , wherein an access of the process having a high privilege level to the object having a relatively low privilege level is a reading.

9. The method of claim 6 , wherein the process information includes information regarding a privilege level of the process and a name and a pathname of the process.

10. The method of claim 6 , wherein the object information includes information regarding the privilege level of the object, and a name and a pathname of the object.

11. The method of claim 6 , wherein the warning message includes a name and a pathname of a privilege level violation process, a name and a pathname of an object to be accessed, and privilege levels of the process and the object when the warning message is outputted.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 26, 2008
From: KIM, SU YONG; CHOI, DAE SIK; LEE, DONG HYUN; LEE, DO HOON
To: ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE
Reel/Frame 020701/0286 →
Priority Claims (1)
KR 10-2007-0059544 · Jun 18, 2007 · national
Continuity (1)
Related Publication 20080313417A1 · Dec 18, 2008