Tagging obtained content for white and black listing
Abstract
A system and method for providing enhanced security with regard to obtained files is presented. Upon obtaining a file from an external location, the obtained file is tagged with tagging information regarding the origin of the obtained file. Additionally, an operating system suitable for execution on a computing device is also presented. The operating system includes at least one application-callable function (API) for obtaining content from an external location. Each application-callable function for obtaining content from an external location is configured to associate tagging information with each obtained file, the tagging information comprising the origin of the obtained file. The origin of the obtained file can be used for subsequent security policy decisions, such as whether to allow or block execution or rendering of the content, as well as whether the content will be accessed in a constrained environment such as a “sandbox” or virtual machine.
Claims
exact text as granted — not AI-modifiedThe embodiments of the invention in which an exclusive property or privilege is claimed are defined as follows:
1 . A computer system for providing enhanced security with regard to obtained files, the computer system configured to:
receive a user-modifiable file; tag the user-modifiable file with tagging information, the tagging information associated with a source of the user-modifiable file; determine a trustworthiness of the user-modifiable file based at least in part on the tagging information; and process the user-modifiable file based at least in part on the trustworthiness.
2 . The computer system of claim 1 , wherein the computer system is configured to act upon a received user-modifiable file according to a rule in a rules data store corresponding to a particular trustworthiness determined for the received user-modifiable file.
3 . The computer system of claim 1 further comprising a black-list data store comprising information regarding untrustworthy sources, wherein the computer system is configured to determine the trustworthiness by determining whether the source of the user-modifiable file, as described in the tagging information, is included in the black-list data store.
4 . The computer system of claim 1 further comprising a white-list data store comprising information regarding trustworthy sources, wherein the computer system is configured to determine the trustworthiness by determining whether the source of the user-modifiable file, as described in the tagging information, is included in the white-list data store.
5 . The computer system of claim 1 , wherein the computer system is configured to tag the user-modifiable file with the tagging information by storing information regarding the source as one or more separate data streams.
6 . The computer system of claim 1 , wherein the computer system is configured to tag the user-modifiable file with the tagging information by storing information regarding the source as one or more records in a file system database.
7 . The computer system of claim 1 , wherein the computer system is configured to tag the user-modifiable file with the tagging information by storing information regarding the source in a tag store.
8 . The computer system of claim 1 , wherein the computer system is configured to tag the user-modifiable file with the tagging information via an anti-malware component configured to store the tagging information in a data store accessible only to the anti-malware component.
9 . The computer system of claim 1 , wherein the computer system is configured to automatically store tagging information for the user-modifiable file as part of a function of obtaining the user-modifiable file.
10 . The computer system of claim 1 , wherein the computer system is configured to generate the tagging information.
11 . A method for enhancing the security of a computing device with regard to a file obtained from an external source, the method comprising:
receiving a user-modifiable file; tagging the user-modifiable file with tagging information, the tagging information identifying a source of the user-modifiable file; and determining whether to process the user-modifiable file based on a trustworthiness of the user-modifiable file ascertained from the tagging information.
12 . The method of claim 11 further comprising:
processing the user-modifiable file according to predetermined rules corresponding to the trustworthiness.
13 . The method of claim 11 , further comprising ascertaining the trustworthiness by comparing the tagging information to a white-list of trustworthy sources.
14 . The method of claim 11 , further comprising ascertaining the trustworthiness by comparing the tagging information to a black-list of untrustworthy sources.
15 . The method of claim 11 , wherein the tagging further comprises storing the source of the user-modifiable file in an alternate data stream of the user-modifiable file.
16 . The method of claim 11 , wherein the tagging further comprises storing the source of the user-modifiable file via an anti-malware application.
17 . The method of claim 11 , further comprising generating the tagging information.
18 . A computer-readable storage device having encoded thereon instructions that facilitate a plurality of acts, the plurality of acts including:
obtaining a user-modifiable file; tagging the user-modifiable file with source information, the source information identifying an origin of the user-modifiable file; and determining whether to process the user-modifiable file based on a trustworthiness of the user-modifiable file ascertained from the source information.
19 . The computer-readable storage device of claim 18 , wherein the plurality of acts further comprise generating the source information.
20 . The computer-readable storage device of claim 19 , wherein the plurality of acts further comprise ascertaining the origin based at least in part on information regarding an external location from which the user-modifiable file is obtained.Join the waitlist — get patent alerts
Track US2013347115A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.