FIELD: physics, computer engineering.
SUBSTANCE: invention relates to protection of operating system resources from unauthorised changes. Method for a client to perform operations on resource data using a resource manager comprises steps of: receiving a request, from a client, to the operating system kernel to perform operations on data stored in a resource which is stored in resource storage means; using a separate process to perform operations on the data stored in a resource which is stored in resource storage means and transmitting, thereto, data provided by the client, indicators for data of said resource and indicators for a resource manager function, required for processing the transmitted data; obtaining a security policy on performing, by the client, operations on said resource, data on operations of all clients on said resource, metadata of said resource; performing the client-requested operations on the resource stored in resource storage means in case of positive analysis results of the obtained data, where the analysis comprises: analysing the metadata for possible change of the current metadata and violation of isolation of said client-requested resource by operations on the resource; analysing information on operations of all system clients on said resource for possible distortion of results of said operations by operations of the current client; analysing information on client rights for performing operations on said resource for possible violation of said rights.
EFFECT: safer access, storage and use of resource content owing to full monitoring of operations on resources and preventing security policy violation.
11 cl, 4 dwg
Title | Year | Author | Number |
---|---|---|---|
ADMINISTRATION OF SECURE DEVICES | 2010 |
|
RU2557756C2 |
METHOD OF CONTROLLING IDENTIFICATION OF USERS OF INFORMATION RESOURCES OF HETEROGENEOUS COMPUTER NETWORK | 2009 |
|
RU2415466C1 |
CONTAINER-CONTROLLING AND DISPATCHING SYSTEM | 2019 |
|
RU2751576C2 |
SYSTEM AND METHOD OF EXECUTING OPERATING SYSTEM PROCESS REQUESTS TO FILE SYSTEM | 2015 |
|
RU2610228C1 |
METHOD AND SYSTEM FOR CONTROLLING ACCESS TO CONFIDENTIAL INFORMATION IN OPERATING SYSTEM | 2023 |
|
RU2825554C1 |
EFFICIENT STORAGE OF REGISTRATION DATA WITH REQUEST SUPPORT, FACILATING COMPUTER NETWORK SAFETY | 2007 |
|
RU2424568C2 |
CONTROL AND CONTAINERS DISPATCHING SYSTEM | 2015 |
|
RU2666475C1 |
CONTAINER CONTROL AND DISPATCHING SYSTEM | 2015 |
|
RU2704734C2 |
SYSTEM AND METHOD FOR TARGET INSTALLATION OF CONFIGURED SOFTWARE | 2012 |
|
RU2523113C1 |
FILE MANAGEMENT USING PLACEHOLDERS | 2013 |
|
RU2646334C2 |
Authors
Dates
2015-12-20—Published
2013-12-27—Filed