发明名称 Policies for secure software execution
摘要 A system and method that automatically, transparently and securely controls software execution by identifying and classifying software, and locating a rule and associated security level for executing executable software. The security level may disallow the software's execution, restrict the execution to some extent, or allow unrestricted execution. To restrict software, a restricted access token may be computed that reduces software's access to resources, and/or removes privileges, relative to a user's normal access token. The rules that control execution for a given machine or user may be maintained in a restriction policy, e.g., locally maintained and/or in a group policy object distributable over a network. Software may be identified/classified by a hash of its content, by a digital signature, by its file system or network path, and/or by its URL zone. For software having multiple classifications, a precedence mechanism is provided to establish the applicable rule/security level.
申请公布号 US7350204(B2) 申请公布日期 2008.03.25
申请号 US20010877710 申请日期 2001.06.08
申请人 MICROSOFT CORPORATION 发明人 LAMBERT JOHN J.;GARG PRAERIT;LAWSON JEFFREY A.
分类号 G06F9/45;G06F21/00 主分类号 G06F9/45
代理机构 代理人
主权项
地址
您可能感兴趣的专利