US2019166147A1PendingUtilityA1
Secure computing environment
Est. expiryJun 8, 2035(~8.9 yrs left)· nominal 20-yr term from priority
H04L 63/1433H04L 63/1425H04L 63/20
46
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Methods and systems for providing secure computing environments. Features of the present invention use a plurality of integrated security controls to ensure security of a computing environment. More specifically, features of the present invention detect discrepancies between a node's behavior and a defined policy to identify and remedy malicious behavior.
Claims
exact text as granted — not AI-modified1 . A method for providing a secure computing environment, the method comprising:
identifying at least one software component of an application, wherein the at least one software component is selected from the group consisting of a block of instructions, a method, a class, and a library of software components; identifying a vulnerability associated with the at least one software component; identifying an acceptable repair strategy that addresses the vulnerability; and executing the identified repair strategy.
2 . The method of claim 1 wherein the acceptable repair strategy is application-agnostic.
3 . The method of claim 1 wherein executing the identified repair strategy includes modifying or removing one or more problematic software components within the application.
4 . The method of claim 3 wherein executing the identified repair strategy further includes inserting at least one new software component into the application.
5 . The method of claim 1 wherein executing the identified repair strategy includes redeploying the application without requiring recompilation or programmer involvement.
6 . The method of claim 1 wherein executing the identified repair strategy includes modifying the application software components in situ using runtime mechanisms.
7 . The method of claim 1 wherein identifying the vulnerability associated with the at least one software component includes identifying a violation of a mandate of a predefined policy.
8 . The method of claim 1 wherein identifying the vulnerability includes examining the application in a detonation chamber.
9 . A method for providing a secure computing environment, the method comprising:
receiving a file annotated with metadata; consulting the metadata associated with the file prior to a process interacting with the file to determine if the interaction would comply with a predetermined policy; examining the file in a detonation chamber before the interaction upon determining the interaction would not comply with the predetermined policy; and performing at least one corrective action after examining the file in the detonation chamber.
10 . The method of claim 9 wherein the file is annotated with provenance data.
11 . The method of claim 9 wherein the detonation chamber includes a reference data set, and examining the file in the detonation chamber includes executing the file autonomously to interact with the reference data.
12 . The method of claim 11 further comprising receiving a summary of changes made to the reference data.
13 . The method of claim 9 wherein performing the at least one corrective action includes quarantining the file.
14 . The method of claim 8 wherein performing the at least one corrective action includes issuing an alert.
15 - 21 . (canceled)Join the waitlist — get patent alerts
Track US2019166147A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.