发明名称 SECURE SYSTEM FOR ALLOWING THE EXECUTION OF AUTHORIZED COMPUTER PROGRAM CODE
摘要 Systems and methods for allowing authorized code to execute on a computer system are provided. According to one embodiment, file or operating system activity relating to a code module is intercepted. A cryptographic hash value of the code module is authenticated with reference to a multi-level whitelist, which includes a remote global whitelist and a local whitelist. The remote global whitelist is maintained by a trusted service provider and contains cryptographic hash values of approved code modules known not to contain malicious code. The local whitelist is accessible by computer systems within the LAN and contains cryptographic hash values of a subset of the approved code modules. The cryptographic hash value is checked against the local whitelist. If no match is found, it is checked against the global whitelist. The code module is allowed to be loaded and executed if the cryptographic hash value corresponds to an approved code module.
申请公布号 US2011167050(A1) 申请公布日期 2011.07.07
申请号 US201113029119 申请日期 2011.02.17
申请人 FORTINET, INC. 发明人 FANTON ANDREW F.;GANDEE JOHN J.;LUTTON WILLIAM H.;HARPER EDWIN L.;GODWIN KURT E.;ROZGA ANTHONY A.
分类号 G06F17/30 主分类号 G06F17/30
代理机构 代理人
主权项
地址