- 专利标题: Application-level sandboxing
-
申请号: US15691792申请日: 2017-08-31
-
公开(公告)号: US10887346B2公开(公告)日: 2021-01-05
- 发明人: Frederico Araujo , Douglas Lee Schales , Marc Philippe Stoecklin , Teryl Paul Taylor
- 申请人: International Business Machines Corporation
- 申请人地址: US NY Armonk
- 专利权人: International Business Machines Corporation
- 当前专利权人: International Business Machines Corporation
- 当前专利权人地址: US NY Armonk
- 代理商 Jeffrey S. LaBaw; David H. Judson
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; G06F21/53 ; G06F21/54 ; G06F21/56 ; G06F9/455
摘要:
Rapid deployments of application-level deceptions (i.e., booby traps) implant cyber deceptions into running legacy applications both on production and decoy systems. Once a booby trap is tripped, the affected code is moved into a decoy sandbox for further monitoring and forensics. To this end, this disclosure provides for unprivileged, lightweight application sandboxing to facilitate monitoring and analysis of attacks as they occur, all without the overhead of current state-of-the-art approaches. Preferably, the approach transparently moves the suspicious process to an embedded decoy sandbox, with no disruption of the application workflow (i.e., no process restart or reload). Further, the action of switching execution from the original operating environment to the sandbox preferably is triggered from within the running process.
公开/授权文献
- US20190068641A1 Application-level sandboxing 公开/授权日:2019-02-28
信息查询