Execution environment file inventory
Abstract
A method is described to maintain (including generate) an inventory of a system of a plurality of containers accessible by a computer system. At least one container is considered to determine whether the container is executable in at least one of a plurality of execution environments characterizing the computer system. Each execution environment is in the group comprising a native binary execution environment configured to execute native machine language instructions and a non-native execution environment configured to execute at least one program to process non-native machine language instructions to yield native machine language instructions. The inventory is maintained based on a result of the considering step. The inventory may be used to exercise control over what executables are allowed to execute on the computer system.
Claims
exact text as granted — not AI-modified1 .- 28 . (canceled)
29 . An apparatus, comprising:
a computer system that includes:
an execution unit;
a storage system that couples to the execution unit and that includes a plurality of containers that collectively form at least a portion of an inventory for the computer system; a native binary execution environment; and a non-native binary execution environment, wherein a request to run an executable file is authorized based on criteria, the request being intercepted before the executable file is run, and wherein a determination is made as to whether the request results in an object of the inventory being changed as a result of running the executable file.
30 . The apparatus of claim 29 , wherein the request is authorized if the object of the inventory is not changed.
31 . The apparatus of claim 29 , wherein the change is associated with a writing operation, a renaming operation, a moving operation, or a deleting operation of the object.
32 . The apparatus of claim 29 , wherein the criteria include a particular program implicated by the request and associated with changing the object.
33 . The apparatus of claim 29 , wherein the criteria includes a particular user associated with the request that changes the object.
34 . The apparatus of claim 29 , wherein the request is associated with an updater that determines whether the request is authorized.
35 . The apparatus of claim 34 , wherein the updater is an anytime updater that is authorized to make changes to files within the inventory at any time.
36 . The apparatus of claim 34 , wherein the updater is a sometime updater that is authorized to make changes to files within the inventory provided the computer system is in an update mode.
37 . The apparatus of claim 34 , wherein the updater is a non-updater that is prohibited from making changes to files within the inventory of the computer system.
38 . The apparatus of claim 34 , wherein the updater is a signed updater that includes a digital signature or that includes a public/private key pair.
39 . The apparatus of claim 29 , wherein a tracking mode is used for the computer system such that attempts to run a non-inventoried executable file are permitted and logged.
40 . The apparatus of claim 29 , wherein the authorization of the request is dependent on a particular date and time at which the request is received by the computer system.
41 . The apparatus of claim 29 , wherein the authorization of the request is associated with particular attributes of an object to be changed as a result of the executable file being run.
42 . The apparatus of claim 29 , wherein the inventory is compared to a gold image inventory in order to identify a particular delta between the inventories, and wherein updates for the computer system are blocked if the updates cause the delta to exceed a predetermined threshold.
43 . The apparatus of claim 29 , wherein the containers include one or more files that can be accessed by the execution unit.
44 . The apparatus of claim 29 , wherein the native binary execution environment includes a database management system (DBMS).
45 . The apparatus of claim 29 , wherein the native binary execution environment is associated with a Java archive (JAR) file that includes compressed information associated with a Java program.
46 . The apparatus of claim 29 , wherein a centrally maintained inventory for a plurality of hosts is used to authorize additional requests that can change one or more objects relating to the computer system.
47 . The apparatus of claim 46 , wherein the centrally maintained inventory indicates a union of executables of the plurality of hosts, and wherein the centrally maintained inventory is scanned by antivirus or anti-malware code.
48 . The apparatus of claim 46 , wherein a result of the scan is used to perform actions on a selected one of the plurality of hosts.
49 . The apparatus of claim 46 , wherein the centrally maintained inventory is checked against a record of licenses in order to determine which of the hosts are using particular licenses.Join the waitlist — get patent alerts
Track US2011138461A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.