- 专利标题: HARDWARE-BASED VIRTUALIZED SECURITY ISOLATION
-
申请号: EP17728376.9申请日: 2017-05-25
-
公开(公告)号: EP3465517A1公开(公告)日: 2019-04-10
- 发明人: PAI, Navin Narayan , JEFFRIES, Charles G. , VISWANATHAN, Giridhar , SCHULTZ, Benjamin M. , SMITH, Frederick J. , REUTHER, Lars , EBERSOL, Michael B. , DIAZ CUELLAR, Gerardo , PASHOV, Ivan Dimitrov , GADDEHOSUR, Poornananda R. , PULAPAKA, Hari R. , RAO, Vikram Mangalore
- 申请人: Microsoft Technology Licensing, LLC
- 申请人地址: One Microsoft Way Redmond, Washington 98052-6399 US
- 专利权人: Microsoft Technology Licensing, LLC
- 当前专利权人: Microsoft Technology Licensing, LLC
- 当前专利权人地址: One Microsoft Way Redmond, Washington 98052-6399 US
- 代理机构: CMS Cameron McKenna Nabarro Olswang LLP
- 优先权: US201615171917 20160602
- 国际公布: WO2017210065 20171207
- 主分类号: G06F21/53
- IPC分类号: G06F21/53
摘要:
A host operating system running on a computing device monitors network communications for the computing device to identify network resources that are requested by the computing device. The host operating system compares requested network resources against security policies to determine if the requested network resources are trusted. When an untrusted network resource is identified, the host operating system accesses the untrusted network resource within a container that is isolated from the host operating system kernel using techniques discussed herein. By restricting access to untrusted network resources to isolated containers, the host operating system is protected from even kernel-level attacks or infections that may result from an untrusted network resource.
公开/授权文献
- EP3465517B1 HARDWARE-BASED VIRTUALIZED SECURITY ISOLATION 公开/授权日:2020-05-13
信息查询