发明名称 Execution environment file inventory
摘要 A method is described to maintain (including generate) an inventory of a system of a plurality of containers accessible by a computer system. At least one container is considered to determine whether the container is executable in at least one of a plurality of execution environments characterizing the computer system. Each execution environment is in the group comprising a native binary execution environment configured to execute native machine language instructions and a non-native execution environment configured to execute at least one program to process non-native machine language instructions to yield native machine language instructions. The inventory is maintained based on a result of the considering step. The inventory may be used to exercise control over what executables are allowed to execute on the computer system.
申请公布号 US9576142(B2) 申请公布日期 2017.02.21
申请号 US201314045208 申请日期 2013.10.03
申请人 McAfee, Inc. 发明人 Bhargava Rishi;Sebes E. John
分类号 G06F9/44;G06F21/62;G06F21/55;G06F21/56;G06F21/60 主分类号 G06F9/44
代理机构 Patent Capital Group 代理人 Patent Capital Group
主权项 1. One or more non-transitory computer readable media having container management and protection logic encoded therein for managing a system of containers accessible to a computer system, wherein the container management and protection logic, when executed by one or more processors, is to: intercept, dynamically, an operation request in the computer system that is to affect a targeted container in the system of containers; identify the targeted container of the intercepted operation request; analyze an inventory of a plurality of protected containers in the system of containers to determine if an identifier of one of the plurality of protected containers corresponds to an identifier of the targeted container; identify an entity associated with an initiation of the operation request; analyze, if the identifier of one of the plurality of protected containers corresponds to the identifier of the targeted container, one or more change authorization policies to determine whether the identified entity is authorized to update the targeted container; allow the operation request to be performed if it is determined that the identified entity is authorized to update the targeted container; generate a new identifier for the targeted container after the operation request is performed; and update the inventory with the new identifier, wherein the new identifier is useable to verify integrity of the targeted container.
地址 Santa Clara CA US