- 专利标题: Sandboxing for multi-tenancy
-
申请号: US13330682申请日: 2011-12-20
-
公开(公告)号: US10467058B2公开(公告)日: 2019-11-05
- 发明人: Girish Mittur Venkataramanappa , Mandyam Kishore , Andreas Ulbrich , Aarthi Rajmohan Saravanakumar , Chandra Prasad , Yann Christensen , Dharma Shukla , Amol Kulkarni
- 申请人: Girish Mittur Venkataramanappa , Mandyam Kishore , Andreas Ulbrich , Aarthi Rajmohan Saravanakumar , Chandra Prasad , Yann Christensen , Dharma Shukla , Amol Kulkarni
- 申请人地址: US WA Redmond
- 专利权人: MICROSOFT TECHNOLOGY LICENSING, LLC
- 当前专利权人: MICROSOFT TECHNOLOGY LICENSING, LLC
- 当前专利权人地址: US WA Redmond
- 代理机构: Ray Quinney & Nebeker P.C
- 代理商 James Bullough
- 主分类号: G06F9/50
- IPC分类号: G06F9/50 ; G06F11/34 ; G06F21/53
摘要:
Systems and methods according to various embodiments disclose a worker process manager adapted to spawn one or more worker processes on a server and to load an application on each of the worker processes. The worker process manager is adapted to isolate the one or more worker processes from each other and to control resource usage by the worker processes. A resource manager is adapted to detect applications that overuse system resources. The worker process manager is adapted to isolate worker processes and to control resource usage using one or more of the following techniques: least-privilege execution, messaging isolation, credentials isolation, data isolation, network isolation, fair share resource usage, and managed runtime security. Heuristic algorithms are used to detect applications that frequently overuse system resources that are unchargeable and that cause system unresponsiveness.
公开/授权文献
- US20130160115A1 SANDBOXING FOR MULTI-TENANCY 公开/授权日:2013-06-20
信息查询