发明名称 Secure system for allowing the execution of authorized computer program code
摘要 Systems and methods are described for allowing the execution of authorized computer program code and for protecting computer systems and networks from unauthorized code execution. In one embodiment, a multi-level proactive whitelist approach is employed to secure a computer system by allowing only the execution of authorized computer program code thereby protecting the computer system against the execution of malicious code such as viruses, Trojan horses, spy-ware, and/or the like. Various embodiments use a kernel-level driver, which intercepts or “hooks” certain system Application Programming Interface (API) calls in order to monitor the creation of processes prior to code execution. The kernel-level driver may also intercept and monitor the loading of code modules by running processes, and the passing of non-executable code modules, such as script files, to approved or running code modules via command line options, for example. Once intercepted, a multi-level whitelist approach may be used to authorize the code execution.
申请公布号 US7698744(B2) 申请公布日期 2010.04.13
申请号 US20050296094 申请日期 2005.12.05
申请人 WHITECELL SOFTWARE INC. 发明人 FANTON ANDREW F.;GANDEE JOHN J.;LUTTON WILLIAM H.;HARPER EDWIN L.;GODWIN KURT E.;ROZGA ANTHONY A.
分类号 G06F7/04;G06F17/30 主分类号 G06F7/04
代理机构 代理人
主权项
地址