US2011138461A1PendingUtilityA1

Execution environment file inventory

Assignee: MCAFEE INC A DELAWARE CORPPriority: Mar 27, 2006Filed: Feb 7, 2011Published: Jun 9, 2011
Est. expiryMar 27, 2026(expired)· nominal 20-yr term from priority
G06F 21/554G06F 21/44G06F 2221/2149G06F 21/60G06F 21/31G06F 21/56G06F 21/566G06F 21/53G06F 21/6218
51
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method is described to maintain (including generate) an inventory of a system of a plurality of containers accessible by a computer system. At least one container is considered to determine whether the container is executable in at least one of a plurality of execution environments characterizing the computer system. Each execution environment is in the group comprising a native binary execution environment configured to execute native machine language instructions and a non-native execution environment configured to execute at least one program to process non-native machine language instructions to yield native machine language instructions. The inventory is maintained based on a result of the considering step. The inventory may be used to exercise control over what executables are allowed to execute on the computer system.

Claims

exact text as granted — not AI-modified
1 .- 28 . (canceled) 
     
     
         29 . An apparatus, comprising:
 a computer system that includes:
 an execution unit; 
   a storage system that couples to the execution unit and that includes a plurality of containers that collectively form at least a portion of an inventory for the computer system;   a native binary execution environment; and   a non-native binary execution environment, wherein a request to run an executable file is authorized based on criteria, the request being intercepted before the executable file is run, and wherein a determination is made as to whether the request results in an object of the inventory being changed as a result of running the executable file.   
     
     
         30 . The apparatus of  claim 29 , wherein the request is authorized if the object of the inventory is not changed. 
     
     
         31 . The apparatus of  claim 29 , wherein the change is associated with a writing operation, a renaming operation, a moving operation, or a deleting operation of the object. 
     
     
         32 . The apparatus of  claim 29 , wherein the criteria include a particular program implicated by the request and associated with changing the object. 
     
     
         33 . The apparatus of  claim 29 , wherein the criteria includes a particular user associated with the request that changes the object. 
     
     
         34 . The apparatus of  claim 29 , wherein the request is associated with an updater that determines whether the request is authorized. 
     
     
         35 . The apparatus of  claim 34 , wherein the updater is an anytime updater that is authorized to make changes to files within the inventory at any time. 
     
     
         36 . The apparatus of  claim 34 , wherein the updater is a sometime updater that is authorized to make changes to files within the inventory provided the computer system is in an update mode. 
     
     
         37 . The apparatus of  claim 34 , wherein the updater is a non-updater that is prohibited from making changes to files within the inventory of the computer system. 
     
     
         38 . The apparatus of  claim 34 , wherein the updater is a signed updater that includes a digital signature or that includes a public/private key pair. 
     
     
         39 . The apparatus of  claim 29 , wherein a tracking mode is used for the computer system such that attempts to run a non-inventoried executable file are permitted and logged. 
     
     
         40 . The apparatus of  claim 29 , wherein the authorization of the request is dependent on a particular date and time at which the request is received by the computer system. 
     
     
         41 . The apparatus of  claim 29 , wherein the authorization of the request is associated with particular attributes of an object to be changed as a result of the executable file being run. 
     
     
         42 . The apparatus of  claim 29 , wherein the inventory is compared to a gold image inventory in order to identify a particular delta between the inventories, and wherein updates for the computer system are blocked if the updates cause the delta to exceed a predetermined threshold. 
     
     
         43 . The apparatus of  claim 29 , wherein the containers include one or more files that can be accessed by the execution unit. 
     
     
         44 . The apparatus of  claim 29 , wherein the native binary execution environment includes a database management system (DBMS). 
     
     
         45 . The apparatus of  claim 29 , wherein the native binary execution environment is associated with a Java archive (JAR) file that includes compressed information associated with a Java program. 
     
     
         46 . The apparatus of  claim 29 , wherein a centrally maintained inventory for a plurality of hosts is used to authorize additional requests that can change one or more objects relating to the computer system. 
     
     
         47 . The apparatus of  claim 46 , wherein the centrally maintained inventory indicates a union of executables of the plurality of hosts, and wherein the centrally maintained inventory is scanned by antivirus or anti-malware code. 
     
     
         48 . The apparatus of  claim 46 , wherein a result of the scan is used to perform actions on a selected one of the plurality of hosts. 
     
     
         49 . The apparatus of  claim 46 , wherein the centrally maintained inventory is checked against a record of licenses in order to determine which of the hosts are using particular licenses.

Join the waitlist — get patent alerts

Track US2011138461A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.