发明名称 FILTERING KERNEL-MODE NETWORK COMMUNICATIONS
摘要 Some embodiments of the invention are directed to techniques for determining whether a process on a computer system that is sending or receiving data, or is attempting to send or receive data, with another computer system is executing in kernel mode or user mode and providing an indicator of this determination to a security engine. In some embodiments, such an indication is provided to a security engine (e.g., a firewall) that implements a security policy based at least in part on whether the sending or receiving process is in kernel mode or user mode, and filter communications based on a process' operating mode. This enables a security engine to maintain security policies of greater specificity and thus improve security of a computer system.
申请公布号 US2013152186(A1) 申请公布日期 2013.06.13
申请号 US201213690528 申请日期 2012.11.30
申请人 MICROSOFT CORPORATION;MICROSOFT CORPORATION 发明人 ABZARIAN DAVID;KHAN SALAHUDDIN;YARIV ERAN;CUELLAR GERARDO DIAZ
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址