×

RESTRICTION OF PROGRAM PROCESS CAPABILITIES

  • US 20080127292A1
  • Filed: 08/04/2006
  • Published: 05/29/2008
  • Est. Priority Date: 08/04/2006
  • Status: Active Grant
First Claim
Patent Images

1. A method of operating a computing device having an operating system defining kernel space and user space, comprising the acts of:

  • causing a program to be operated by the computing device, the program having a plurality of intended functionalities, the program further having a set of policies associated therewith;

    monitoring calls attempted by the program, the monitoring performed by monitoring operations in the kernel initiated in response to the calls, the monitoring comprising intercepting a kernel operation at a point at which one or more arguments associated with the call have been resolved in the kernel for the kernel operation;

    determining whether at least one intercepted kernel operation initiated in response to the program is consistent with the policies associated with the program; and

    after determining that an intercepted kernel operation initiated in response to the program is consistent with the policies associated with the program, allowing execution of the intercepted kernel operation.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×