Invention Grant
- Patent Title: Inhibiting denial-of-service attacks using group controls
- Patent Title (中): 使用组控制来禁止拒绝服务攻击
-
Application No.: US13029702Application Date: 2011-02-17
-
Publication No.: US09027151B2Publication Date: 2015-05-05
- Inventor: Daniel J. Walsh
- Applicant: Daniel J. Walsh
- Applicant Address: US NC Raleigh
- Assignee: Red Hat, Inc.
- Current Assignee: Red Hat, Inc.
- Current Assignee Address: US NC Raleigh
- Agency: Lowenstein Sandler LLP
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/53 ; H04L29/06

Abstract:
A sandbox tool can cooperate with components of a secure operating system (OS) to create an isolated execution environment for accessing content without exposing other processes and resources of the computing system to the untrusted content. The sandbox tool can utilize task control groups (cgroups) of the secure OS with the isolated execution environment. A cgroup defines the hardware resources that can be accessed and utilized by the isolated execution environment. The cgroups can define accessible hardware resources by particular hardware resources, amount of hardware resources, and/or components of the hardware resources. Once a cgroup is applied to the isolated execution environment, any processes running in the isolated execution environment will be confined to the hardware resources defined by the applied cgroup. If a process running in the isolated execution environment attempts to utilize hardware resources outside the definition of the cgroup, the secure OS can block the usage.
Public/Granted literature
- US20120216285A1 SYSTEMS AND METHODS FOR INHIBITNG DENIAL-OF-SERVICE ATTACKS USING GROUP CONTROLS Public/Granted day:2012-08-23
Information query