发明名称 REAL TIME LOCKDOWN
摘要 A system and method that trusts software executables existent on a machine prior to activation for different types of accesses e.g. execution, network, and registry. The system detects new executables added to the machine as well as previously existent executables that have been modified, moved, renamed or deleted. In certain embodiments, the system will tag the file with a flag as modified or newly added. Once tagged, the system intercepts particular types of file accesses for execution, network or registry. The system determines if the file performing the access is flagged and may apply one or more policies based on the requested access. In certain embodiments, the system intercepts I/O operations by file systems or file system volumes and flags metadata associated with the file. For example, the NT File System and its extended attributes and alternate streams may be utilized to implement the system.
申请公布号 WO2008016379(A2) 申请公布日期 2008.02.07
申请号 WO2006US49149 申请日期 2006.12.22
申请人 WEBSENSE, INC.;SHARMA, RAJESH KUMAR;LO, WINPING;PAPA, JOSEPH 发明人 SHARMA, RAJESH KUMAR;LO, WINPING;PAPA, JOSEPH
分类号 主分类号
代理机构 代理人
主权项
地址