Software application environment
Abstract
The invention contains an application operating environment in which acceptable and/or suspect activities may be defined for an application so that unacceptable application behavior can be prevented. This is done by providing a definition table identifying the types of access and actions that the application is allowed and preventing it from carrying out other types of access and actions. The definition table may be built up using a learning process during use of the application. The environment also provides a means of checking information output to a network against a list of confidential information.
Claims
exact text as granted — not AI-modified1 . A method for blocking forbidden access behavior of a program, the method comprising:
providing a list of access permissions of said program to sectors of data storage; monitoring requests of said program to access data storage; and upon receiving an indication from said monitoring of a request to access a sector of data storage which is forbidden according to said list, blocking said request.
2 . A method according to claim 1 , wherein said monitoring includes monitoring requests of a child application of said program to access data storage.
3 . A method according to claim 1 , further comprising amending said list by a user thereof.
4 . A method according to claim 1 , wherein said list includes at least one allowed access permission.
5 . A method according to claim 1 , wherein said list includes at least one forbidden access permission.
6 . A method according to claim 1 , wherein said list includes a plurality of access level permissions.
7 . A method according to claim 1 , wherein said data storage is a path.
8 . A method according to claim 1 , wherein said data storage is a file.
9 . A method according to claim 1 , wherein said access requests are stored in communication packets.
10 . A method according to claim 1 , wherein said data storage is volatile.
11 . A method according to claim 1 , wherein said data storage is non-volatile.
12 . A method according to claim 1 , wherein said data storage is a physical location.
13 . A method according to claim 1 , wherein said data storage is a logical location.
14 . A method according to claim 1 , wherein said requests include requests to access data storage areas on a remote computer.
15 . A method according to claim 1 , wherein said requests to access data storage include requests to download data via the Internet.
16 . A method according to claim 1 , further comprising the step of automatically updating said list.
17 . A method according to claim 1 , wherein said blocking said request also comprises:
prompting a user of said program to allow said forbidden access; and upon receipt of permission from said user, processing said request.Join the waitlist — get patent alerts
Track US2006179434A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.