FIELD: information technology.
SUBSTANCE: invention discloses a method for accurate setup of policy realised in a computer system and including steps on which: a request to access a resource is received from an executed program; a centralised policy storage containing policies is provided, with each policy applicable to a program different from others, where the policy applicable to the executing program contains at least one rule indicating whether to activate training mode for that rule; access control is checked to determine whether the program should be granted access to the resource, where if the rule is unsuccessful and the training mode is activated: the program is granted access to the resource and granting of access and the unsuccessful result of the rule are recorded in a journal; if the rule is unsuccessful and the training mode is not activated: the program is not granted access to the resource; if the rule allows access to the resource and the training mode is activated: the program is granted access to the resource and granting of access and indication of the rule responsible for granting access to the resource are recorded in a journal.
EFFECT: improvement and increased security of resources on a computer.
4 cl, 10 dwg
Title | Year | Author | Number |
---|---|---|---|
SAFETY MARKERS, INCLUDING DISPLAYED STATEMENTS | 2006 |
|
RU2421789C2 |
TRANSITION OF ENTITIES WITH ACCOUNTS OVER SECURITY BOUNDARIES WITHOUT SERVICE INTERRUPTION | 2008 |
|
RU2475837C2 |
TRANSITION OF ENTITIES WITH ACCOUNTS OVER SECURITY BOUNDARIES WITHOUT SERVICE INTERRUPTION | 2004 |
|
RU2348075C2 |
DETECTABILITY AND LISTING MECHANISM IN HIERARCHICALLY PROTECTED DATA STORAGE SYSTEM | 2006 |
|
RU2408070C2 |
DELEGATED MANAGEMENT OF DISTRIBUTED RESOURCES | 2004 |
|
RU2360368C2 |
REGISTRATION INFORMATION SYSTEM FOR USE IN COMPUTER ENVIRONMENT | 2004 |
|
RU2377641C2 |
SYSTEMS AND METHODS FOR CONTROL REALISED BY MEANS OF ACCESS AT LEVEL OF MINOR STRUCTURAL UNITS OVER DATA STORED IN RELATIONAL DATABASES | 2004 |
|
RU2373571C2 |
INTERACTING MODULE FACILITIES FOR COLLECTION OF AUTHENTICATORS AND ACCESS | 2004 |
|
RU2369025C2 |
DATA MANAGEMENT FOR CONNECTED DEVICES | 2014 |
|
RU2670573C2 |
METHOD AND SYSTEM FOR RECOGNITION OF REGISTRATION INFORMATION | 2004 |
|
RU2367998C2 |
Authors
Dates
2010-11-27—Published
2005-09-30—Filed