发明名称 Cloud-based application whitelisting
摘要 Systems and methods for allowing authorized code to execute on a computer system are provided. According to one embodiment, an in-memory cache is maintained having entries containing execution authorization information regarding recently used modules. After verifying a module, its execution authorization information is added to the cache. Activity relating to a module is intercepted. A hash value of the module is generated. The module is verified with reference to a multi-level whitelist including a global whitelist, a local whitelist and the cache. The verification includes first consulting the cache and if the module is not found, then looking up its hash value in the local whitelist and if it is not found, then looking it up in the global whitelist. Finally, the module is allowed to be executed if the code module is approved by the multi-level whitelist database architecture.
申请公布号 US8195938(B2) 申请公布日期 2012.06.05
申请号 US201113305740 申请日期 2011.11.28
申请人 FANTON ANDREW F.;GANDEE JOHN J.;LUTTON WILLIAM H.;HARPER EDWIN L.;GODWIN KURT E.;ROZGA ANTHONY A.;FORTINET, INC. 发明人 FANTON ANDREW F.;GANDEE JOHN J.;LUTTON WILLIAM H.;HARPER EDWIN L.;GODWIN KURT E.;ROZGA ANTHONY A.
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址