EP1596557A2

Checking the security of web services configurations

Abstract

Systems and methods for checking security goals of a distributed system are described. In one aspect, detailed security policies are converted into a model. The detailed security policies are enforced during exchange of messages between one or more endpoints. The one or more endpoints host respective principals networked in a distributed operating environment. The model is evaluated to determine if the detailed security policies enforce one or more security goals of at least one of the one or more endpoints.

EP1596557A2, drawing sheet 1
Sheet 1 of 59

Term

Term ended

Projected expiry passed 2 May 2025, 1.4 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

20 claims: 3 independent, 17 dependent

  1. 1
    A computer-implemented method comprising:translating detailed security policies into a model, the detailed security policies being enforced during exchange of messages between one or more endpoints, the one or more endpoints hosting respective principals networked in a distributed operating environment;andevaluating the model to determine if the detailed security policies enforce one or more security goals of at least one of the one or more endpoints.
  2. 13
    A computer-readable medium comprising computer-program instructions executable by a processor for:converting detailed security policies into a model, the detailed security policies being enforced during exchange of messages between one or more endpoints, the one or more endpoints hosting respective principals networked in a distributed operating environment;andevaluating the model to determine if the detailed security policies enforce one or more security goals of at least one of the one or more endpoints.
  3. 18
    A computer-implemented method comprising:querying detailed security policies with one or more of a schema checking or identifier scoping query, an endpoint configuration setting query, a policy dispatch query, an individual policy query, a policy compatibility query, or a custom query, the security policies associated with exchange of message(s) between one or more endpoints hosting respective principals networked in a distributed operating environment;andresponsive to the querying, generating a positive or a negative security report.