Protected shell for risk validation

US10452850B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10452850-B2
Application numberUS-201414462203-A
CountryUS
Kind codeB2
Filing dateAug 18, 2014
Priority dateAug 18, 2014
Publication dateOct 22, 2019
Grant dateOct 22, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

On a computer system, a shell is invoked, through which a plurality of commands and/or scripts can be executed. Individual ones of the plurality of commands and/or scripts are validated. Given individual ones of the plurality of commands and/or scripts, for which the validation is successful, are executed via the shell.

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising: invoking, on a computer system, a shell through which a plurality of at least one of commands and scripts can be executed; validating individual ones of said plurality of at least one of commands and scripts at least in part by simulating execution of said individual ones of said plurality of at least one of commands and scripts to estimate effects of said execution on a configuration of said computer system; and executing, via said shell, given individual ones of said plurality of at least one of commands and scripts, for which said validation is successful. 2. The method of claim 1 , wherein said validating is carried out based on user roles, policies, and a configuration profile. 3. The method of claim 2 , further comprising: obtaining change tickets; and accessing said configuration profile based on said change tickets. 4. The method of claim 3 , wherein said accessing comprises choosing an existing configuration profile based on said change tickets. 5. The method of claim 3 , wherein said accessing comprises building a new configuration profile based on said change tickets. 6. The method of claim 3 , wherein said validating is carried out at shell level by said shell. 7. The method of claim 6 , wherein said validating comprises: assigning each individual one of said plurality of at least one of commands and scripts to a category, said categories comprising at least a GO category and a NO GO category; accepting individual ones of said plurality of at least one of commands and scripts in said GO category; and rejecting individual ones of said plurality of at least one of commands and scripts in said NO GO category. 8. The method of claim 7 , wherein, in said assigning step, said categories further comprise a NOT SURE category, further comprising: accepting individual ones of said plurality of at least one of commands and scripts in said NOT SURE category if policy-compliant; and rejecting individual ones of said plurality of at least one of commands and scripts in said NO GO category if not policy-compliant. 9. The method of claim 3 , wherein said validating is carried out at operating system level. 10. The method of claim 9 , wherein said validating comprises, for a plurality of system calls associated with said plurality of at least one of commands and scripts: accepting non-intrusive ones of said system calls; accepting intrusive ones of said system calls, if policy-compliant; and rejecting intrusive ones of said system calls, if not policy-compliant. 11. The method of claim 1 , wherein said executing comprises changing said configuration of said computer system. 12. A computer system comprising: a memory; and at least one processor, coupled to said memory, and operative to: invoke a shell through which a plurality of at least one of commands and scripts can be executed; validate individual ones of said plurality of at least one of commands and scripts at least in part by simulating execution of said individual ones of said plurality of at least one of commands and scripts to estimate effects of said execution on a configuration of said computer system; and execute, via said shell, given individual ones of said plurality of at least one of commands and scripts, for which said validation is successful. 13. The computer system of claim 12 , wherein said at least one processor is operative to validate based on user roles, policies, and a configuration profile. 14. The computer system of claim 13 , wherein said at least one processor is further operative to: obtain change tickets; and access said configuration profile based on said change tickets. 15. The computer system of claim 14 , wherein said at least one processor is operative to access by choosing an existing configuration profile based on said change tickets. 16. The computer system of claim 14 , wherein said at least one processor is operative to access by building a new configuration profile based on said change tickets. 17. A computer program product, the computer program product comprising a computer readable storage medium having program instructions embodied therewith, wherein the computer readable storage medium is not a transitory signal per se, the program instructions executable by a computer system to cause the computer system to perform a method comprising: invoking, on the computer system, a shell through which a plurality of at least one of commands and scripts can be executed; validating individual ones of said plurality of at least one of commands and scripts at least in part by simulating execution of said individual ones of said plurality of at least one of commands and scripts to estimate effects of said execution on a configuration of said computer system; and executing, via said shell, given individual ones of said plurality of at least one of commands and scripts, for which said validation is successful. 18. The computer program product of claim 17 , wherein said validating is carried out based on user roles, policies, and a configuration profile. 19. The computer program product of claim 18 , wherein the program instructions are executable by the computer system to cause the computer system to perform said method, said method further comprising: obtaining change tickets; and accessing said configuration profile based on said change tickets. 20. The computer program product of claim 19 , wherein said accessing comprises choosing an existing configuration profile based on said change tickets. 21. The computer program product of claim 19 , wherein said accessing comprises building a new configuration profile based on said change tickets.

Assignees

Inventors

Classifications

  • Test or assess software · CPC title

  • by source code analysis · CPC title

  • G06F21/577Primary

    Assessing vulnerabilities and evaluating computer system security · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10452850B2 cover?
On a computer system, a shell is invoked, through which a plurality of commands and/or scripts can be executed. Individual ones of the plurality of commands and/or scripts are validated. Given individual ones of the plurality of commands and/or scripts, for which the validation is successful, are executed via the shell.
Who is the assignee on this patent?
IBM
What technology area does this patent fall under?
Primary CPC classification G06F21/577. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Oct 22 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).