发明授权
- 专利标题: Restriction of program process capabilities
- 专利标题(中): 限制程序处理能力
-
申请号: US13591690申请日: 2012-08-22
-
公开(公告)号: US08635663B2公开(公告)日: 2014-01-21
- 发明人: Simon Cooper , Nick Lane-Smith , Joshua Osborne
- 申请人: Simon Cooper , Nick Lane-Smith , Joshua Osborne
- 申请人地址: US CA Cupertino
- 专利权人: Apple Inc.
- 当前专利权人: Apple Inc.
- 当前专利权人地址: US CA Cupertino
- 代理机构: Womble Carlyle Sandridge & Rice LLP
- 主分类号: G06F17/00
- IPC分类号: G06F17/00 ; G06F3/00
摘要:
This document describes systems and methods for restricting program process capabilities. In some implementations, the capabilities are restricted by limiting the rights or privileges granted to an application. A plurality of rules may be established for a program, or for a group of programs, denying that program the right to take actions which are outside of the actions needed to implement its intended functionality. A security policy is implemented to test actions initiated in response to an application against the rules to enable decisions restricting the possible actions of the program. Embodiments are disclosed which process the majority of decisions regarding actions against a security profile through use of a virtual machine. In some embodiments, the majority of decisions are resolved within the kernel space of an operating system.
公开/授权文献
- US20130055341A1 RESTRICTION OF PROGRAM PROCESS CAPABILITIES 公开/授权日:2013-02-28
信息查询