发明名称 System and method for identity decisions and invalidation
摘要 A system and method for identity decisions and invalidation. Modified objects (e.g., files, executables, etc.) are flagged for reevaluation. Privileges associated with the object are only persisted if the modifications are determined to be authorized (e.g., updates and patches). In one embodiment, a tagging system registers to be notified of all writes, renames, truncations, moves, deletions, or any other relevant modifications to objects. If the tagging system detects a modification operation targeting the object, it invalidates all identity decisions cached with the object. The next time the object runs, the system does not recognize the object and it is forced to reevaluate its identity. Thus, patching and other write operations are still permitted, but the system detects the changed object and reevaluates the identity.
申请公布号 US7756841(B2) 申请公布日期 2010.07.13
申请号 US20050087222 申请日期 2005.03.22
申请人 MICROSOFT CORPORATION 发明人 PROBERT DAVID B.;LI ERIC;FERNANDES GENEVIEVE;RECTOR JOHN
分类号 G06F17/30 主分类号 G06F17/30
代理机构 代理人
主权项
地址