- 专利标题: Securely and efficiently providing user notifications about security actions
-
申请号: US17008038申请日: 2020-08-31
-
公开(公告)号: US11687649B2公开(公告)日: 2023-06-27
- 发明人: Ion-Alexandru Ionescu
- 申请人: Crowdstrike, Inc.
- 申请人地址: US CA Irvine
- 专利权人: Crowdstrike, Inc.
- 当前专利权人: Crowdstrike, Inc.
- 当前专利权人地址: US CA Irvine
- 代理机构: Lee & Hayes, P.C.
- 主分类号: G06F21/00
- IPC分类号: G06F21/00 ; G06F21/55 ; G06F9/54 ; G06F21/33 ; G06F21/56
摘要:
A security agent executing in kernel mode may receive a request from the anti-malware component executing with low privileges in user mode, and, in response, the security agent may perform a security action with respect to a malicious file detected on the computing device. The security agent may then assist the anti-malware component in providing a user notification about the security action by obtaining, on behalf of the anti-malware component, a user token associated with the user session in which the malicious file was detected. The anti-malware component can use the obtained user token to request a pointer to a Component Object Model (COM) interface for outputting the notification in context of the appropriate user session, which allows for securely and efficiently providing the user notification.
信息查询