发明名称 0-touch and 1-touch techniques for improving the availability of computer programs under protection without compromising security
摘要 Protected software, such as an application and/or DLL, is monitored by protective software to guard against attacks, while distinguishing spurious, benign events from attacks. In a 1-touch approach, the protected software is monitored in a testing environment to detect spurious, benign events caused by, e.g., incompatibility or interoperability problems. The spurious events can be remediated in different ways, such as by applying a relaxed security policy. In a production mode, or 0-touch mode, when the protected software is subject to attacks, the corresponding remediation can be applied when the spurious events are again detected. Security events which occur in production mode can also be treated as benign when they occur within a specified time window. The applications and/or DLLs can further be classified according to whether they are known to have bad properties, known to be well-behaved, or unknown. Appropriate treatment is provided based on the classification.
申请公布号 US7735136(B2) 申请公布日期 2010.06.08
申请号 US20060406063 申请日期 2006.04.18
申请人 VMWARE, INC. 发明人 MANTRIPRAGADA SRINIVAS;GARNETT TIM;BRUENING DEREK;KIRIANSKY VLADIMIR;CHANDRAMOHAN BHARATH;BRINK JAMES;AMARASINGHE SAMAN P.;WILBOURN SANDY
分类号 G06F12/14 主分类号 G06F12/14
代理机构 代理人
主权项
地址