-
公开(公告)号:US20060161988A1
公开(公告)日:2006-07-20
申请号:US11035584
申请日:2005-01-14
Applicant: Mihai Costea , Adrian Marinescu , Anil Thomas , Gheorghe Gheorghescu , Kyle Larsen , Vadim Bluvstein
Inventor: Mihai Costea , Adrian Marinescu , Anil Thomas , Gheorghe Gheorghescu , Kyle Larsen , Vadim Bluvstein
IPC: G06F11/00
CPC classification number: G06F21/56 , G06F21/6209 , G06F21/64
Abstract: The present invention provides a system, method, and computer-readable medium for quarantining a file. Embodiments of the present invention are included in antivirus software that maintains a user interface. From the user interface, a user may issue a command to quarantine a file or the quarantine process may be initiated automatically by the antivirus software after malware is identified. When a file is marked for quarantine, aspects of the present invention encode file data with a function that is reversible. Then a set of metadata is identified that describes attributes of the file including any heightened security features that are used to limit access to the file. The metadata is moved to a quarantine folder, while the encoded file remains at the same location in the file system. As a result, the encoded file maintains the same file attributes as the original, non-quarantined file, including any heightened security features.
Abstract translation: 本发明提供了用于隔离文件的系统,方法和计算机可读介质。 本发明的实施例包括在维护用户界面的防病毒软件中。 从用户界面,用户可能会发出隔离文件的命令,或者在识别恶意软件后,防病毒软件可以自动启动隔离进程。 当文件被标记为隔离区时,本发明的方面用可逆的功能对文件数据进行编码。 然后识别一组描述文件属性的元数据,包括用于限制对文件访问的任何更高级的安全功能。 元数据移动到隔离文件夹,而编码文件保留在文件系统中的相同位置。 因此,编码文件保持与原始,未隔离文件相同的文件属性,包括任何更高级的安全功能。