Invention Grant
US08950007B1 Policy-based whitelisting with system change management based on trust framework
有权
基于信任框架的基于策略的白名单与系统变更管理
- Patent Title: Policy-based whitelisting with system change management based on trust framework
- Patent Title (中): 基于信任框架的基于策略的白名单与系统变更管理
-
Application No.: US12695816Application Date: 2010-01-28
-
Publication No.: US08950007B1Publication Date: 2015-02-03
- Inventor: Daniel M. Teal , Wesley G. Miller , Charisse Castagnoli , Toney Jennings , Todd Schell , Richard S. Teal
- Applicant: Daniel M. Teal , Wesley G. Miller , Charisse Castagnoli , Toney Jennings , Todd Schell , Richard S. Teal
- Applicant Address: US AZ Scottsdale
- Assignee: Lumension Security, Inc.
- Current Assignee: Lumension Security, Inc.
- Current Assignee Address: US AZ Scottsdale
- Agency: Greenberg Traurig, LLP
- Main IPC: G06F21/10
- IPC: G06F21/10

Abstract:
Techniques have been developed to allow runtime extensions to a whitelist that locks down a computational system. For example, executable code (including e.g., objects such as a script or active content that may be treated as an executable) is not only subject to whitelist checks that allow (or deny) its execution, but is also subject to checks that determine whether a whitelisted executable is itself trusted to introduce further executable code into the computational system in which it is allowed to run. In general, deletion and/or modification of instances of code that are already covered by the whitelist are also disallowed in accordance with a security policy. Accordingly, an executable that is trusted may be allowed to delete and/or modify code instances covered by the whitelist. In general, trust may be coded for a given code instance that seeks to introduce, remove or modify code (e.g., in the whitelist itself).
Public/Granted literature
- US1260737A Kodak-case. Public/Granted day:1918-03-26
Information query