×

Restriction of program process capabilities

  • US 8,272,048 B2
  • Filed: 08/04/2006
  • Issued: 09/18/2012
  • Est. Priority Date: 08/04/2006
  • Status: Active Grant
First Claim
Patent Images

1. A method of operating a computing device having an operating system defining a kernel space and user space, comprising the acts of:

  • causing the computing device to operate a program, the program having a plurality of intended functionalities, the program further having a set of one or more security profiles associated with the program;

    monitoring calls attempted by the program, the monitoring performed by monitoring operations in the kernel initiated in response to the attempted calls, the monitoring comprising intercepting a kernel operation at a point at which one or more arguments associated with the attempted calls have been resolved in the kernel for the kernel operation;

    determining whether the intercepted kernel operation initiated in response to the program is consistent with the security profiles associated with the program; and

    after determining that the intercepted kernel operation initiated in response to the program is consistent with the security profiles associated with the program, allowing execution of the intercepted kernel operation;

    wherein the act of determining whether the operation initiated in response to a program call is consistent with the security profiles associated with the program comprises correlating the intercepted kernel operation with the security profiles and determining if the attempted call operation is allowed by the security profiles.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×