发明授权
- 专利标题: MIME handling security enforcement
- 专利标题(中): MIME处理安全执行
-
申请号: US10873576申请日: 2004-06-22
-
公开(公告)号: US07660999B2公开(公告)日: 2010-02-09
- 发明人: Venkatraman V. Kudallur , Shankar Ganesh , Roberto A. Franco , Vishu Gupta , John G. Bedworth
- 申请人: Venkatraman V. Kudallur , Shankar Ganesh , Roberto A. Franco , Vishu Gupta , John G. Bedworth
- 申请人地址: US WA Redmond
- 专利权人: Microsoft Corporation
- 当前专利权人: Microsoft Corporation
- 当前专利权人地址: US WA Redmond
- 主分类号: G06F12/14
- IPC分类号: G06F12/14 ; G06F12/16 ; G06F15/16
摘要:
A model restricts un-trusted data/objects from running on a user's machine without permission. The data is received by a protocol layer that reports a MIME type associated with the DATA, and caches the data and related cache file name (CFN). A MIME sniffer is arranged to identify a sniffed MIME type based on the cached data, the CFN, and the reported MIME type. Reconciliation logic evaluates the sniffed MIME type and the CFN to determine a reconciled MIME type, and to update the CFN. A class ID sniffer evaluates the updated CFN, the cached data, and the reconciled MIME type to determine an appropriate class ID. Security logic evaluates the updated CFN, the reported class ID, and other related system parameters to build a security matrix. Parameters from the security matrix are used to intercept data/objects before an un-trusted data/object can create a security breach on the machine.
公开/授权文献
- US20060010241A1 MIME handling security enforcement 公开/授权日:2006-01-12
信息查询