Invention Grant
- Patent Title: Application-level sandboxing
-
Application No.: US15691792Application Date: 2017-08-31
-
Publication No.: US10887346B2Publication Date: 2021-01-05
- Inventor: Frederico Araujo , Douglas Lee Schales , Marc Philippe Stoecklin , Teryl Paul Taylor
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Jeffrey S. LaBaw; David H. Judson
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/53 ; G06F21/54 ; G06F21/56 ; G06F9/455

Abstract:
Rapid deployments of application-level deceptions (i.e., booby traps) implant cyber deceptions into running legacy applications both on production and decoy systems. Once a booby trap is tripped, the affected code is moved into a decoy sandbox for further monitoring and forensics. To this end, this disclosure provides for unprivileged, lightweight application sandboxing to facilitate monitoring and analysis of attacks as they occur, all without the overhead of current state-of-the-art approaches. Preferably, the approach transparently moves the suspicious process to an embedded decoy sandbox, with no disruption of the application workflow (i.e., no process restart or reload). Further, the action of switching execution from the original operating environment to the sandbox preferably is triggered from within the running process.
Public/Granted literature
- US20190068641A1 Application-level sandboxing Public/Granted day:2019-02-28
Information query