Electronic computer system secured from unauthorized access to and manipulation of data
Abstract
In general, the invention relates to a method for securing a computer system. The method includes monitoring an operating system in the computer system and trapping, in response to the monitoring, a process system call where the process system call originated in a host executing in the computer system. Responsive to the trapping, an isolated user environment (IUE) is created in the computer system. Creating the IUE includes allocating memory and persistent storage for the IUE. In addition, the IUE includes a file system filter driver (FSFD) configured to redirect Input/Output (I/O) calls originating from the IUE to the persistent storage, and a network interface/NDIS hook component configured to control network traffic originating from the IUE and destined for the IUE. The method further includes, after creating the IUE, loading the process system call into the IUE and executing the process system call in the IUE.
Claims
exact text as granted — not AI-modified1 .- 19 . (canceled)
20 . A method for securing a computer system, comprising:
monitoring an operating system executing on a processor in the computer system; trapping, in response to the monitoring, a process system call to execute a program, wherein the process system call originated in a host executing in the computer system; responsive to the trapping, creating an isolated user environment (IUE) in the computer system, wherein creating the IUE comprises allocating memory and persistent storage for the IUE, and wherein the IUE comprises:
a file system filter driver (FSFD) configured to redirect Input/Output (I/O) calls originating from the IUE to the persistent storage, and
a network interface/NDIS hook component configured to control network traffic originating from the IUE and destined for the IUE;
after creating the IUE, loading an executable image corresponding to the program into the IUE; and executing the program using the executable image in the IUE using the processor, wherein the IUE enables a user to provide input to the program during execution.
21 . The method of claim 20 , further comprising:
responsive to the executing, issuing an I/O call from the IUE to a file system of the host; and redirecting, by the FSFD, the I/O call to the persistent storage, wherein the persistent storage comprises a file system of the IUE.
22 . The method of claim 21 , wherein a hierarchy of the file system of the IUE mirrors a hierarchy of the file system of the host.
23 . The method of claim 21 , wherein the FSFD is configured to limit the portions of the file system of the host which processes executing in the IUE may access.
24 . The method of claim 20 , further comprising:
responsive to the executing, issuing an I/O call from the IUE to a registry of the host; and redirecting, by a system call hook component, the I/O call to the persistent storage, which includes a registry of the IUE.
25 . The method of claim 24 , wherein the registry of the IUE is a mirror of the registry of the host.
26 . The method of claim 24 , wherein the system call hook component is configured to query the registry of the IUE prior to querying the registry of the host when locating a registry key.
27 . The method of claim 20 , further comprising:
responsive to the executing, storing data in the persistent storage; after executing the process system call, closing the IUE; and responsive to closing the IUE, terminating all processes executing the IUE, deallocating the memory and unmounting the persistent storage.
28 . The method of claim 27 , further comprising:
creating a new IUE after closing the IUE, wherein the data in the persistent storage is accessible through the new IUE.
29 . The method of claim 20 , wherein the process system call is associated with a user, wherein the persistent storage comprises a file system for the user and wherein the IUE comprises a file system block device driver component configured to mount and unmount the file system for the user.
30 . The method of claim 29 , wherein the file system for the user is stored as a flat file in the persistent storage after the IUE is closed.
31 . The method of claim 20 , wherein the process system call corresponds to a call to open a web browser and access a website external to the host via the web browser.
32 . The method of claim 20 , wherein the host is associated with a first TCP/IP stack and the IUE is associated with a second TCP/IP stack, wherein the first TCP/IP stack is distinct from the second TCP/IP stack.
33 . The method of claim 20 , wherein the IUE is associated with a job object component configured to create a restricted process in the IUE, wherein execution of the restricted process is limited to the IUE.
34 . The method of claim 33 , wherein the process system call is associated with a job object, wherein the job object is associated with the IUE and wherein job objects not associated with the IUE are hidden from the restricted process.
35 . The method of claim 20 , wherein the IUE is associated with a virtual adapter, wherein the virtual adapter is associated with an IP address which is distinct from the IP address associated with a physical adapter connected to the host.Join the waitlist — get patent alerts
Track US2010205666A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.