发明名称 Computer security system and method
摘要 A method is provided for protecting a computer system, comprising: attaching a security descriptor to a process running on a processor of the computer system; associating with the security descriptor an isolation indicator that indicates the process runs in an isolation mode; calling a system routine by the isolated process that is also callable by a process that is not running in isolation mode; attempting to write to an object of a disk or a registry by the system routine called by the isolated process; determining whether the system routine is requesting the write on behalf of the isolated process or not; if the write is requested on behalf of the isolated process, then performing the write in a pseudo storage area; and if the write is requested on behalf of the non-isolated process, then performing the write in an actual storage area in which the disk or registry resides.
申请公布号 US8429429(B1) 申请公布日期 2013.04.23
申请号 US20100911184 申请日期 2010.10.25
申请人 KARGMAN JAMES B.;SCOTT PETER;BROMBERGER JEFFREY;SECURE VECTOR, INC. 发明人 KARGMAN JAMES B.;SCOTT PETER;BROMBERGER JEFFREY
分类号 G06F9/44;G06F12/06;G06F12/14 主分类号 G06F9/44
代理机构 代理人
主权项
地址