Apparatus and method for monitoring and protecting system resources from web browser
    7.
    发明授权
    Apparatus and method for monitoring and protecting system resources from web browser 有权
    用于从网络浏览器监控和保护系统资源的装置和方法

    公开(公告)号:US08336097B2

    公开(公告)日:2012-12-18

    申请号:US12208401

    申请日:2008-09-11

    IPC分类号: G06F11/00

    摘要: An apparatus and method for preventing an attempt to perform malicious activities using web browser weaknesses are provided. A file protection module monitors attempts to access at least one file resource when the web browser executes a program, and allows or denies access. A registry protection module monitors attempts to access at least one registry resource when the web browser executes a program, and allows or denies access. A process protection module monitors attempts to execute or terminate at least one process when the web browser executes a program, and allows or denies the execution or termination.

    摘要翻译: 提供了一种用于防止尝试使用web浏览器弱点进行恶意活动的装置和方法。 当Web浏览器执行程序并允许或拒绝访问时,文件保护模块监视尝试访问至少一个文件资源。 注册表保护模块监视在Web浏览器执行程序时访问至少一个注册表资源的尝试,并允许或拒绝访问。 当Web浏览器执行程序时,进程保护模块监视执行或终止至少一个进程的尝试,并允许或拒绝执行或终止。

    Apparatus and method of detecting and controlling privilege level violation process
    8.
    发明授权
    Apparatus and method of detecting and controlling privilege level violation process 有权
    检测和控制特权级别违规过程的装置和方法

    公开(公告)号:US08082590B2

    公开(公告)日:2011-12-20

    申请号:US12055381

    申请日:2008-03-26

    IPC分类号: G06F12/14

    CPC分类号: G06F12/1491 G06F21/55

    摘要: Provided are an apparatus and method of detecting and controlling a privilege level violation process. The apparatus monitors whether higher-privileged processes depend on information provided from lower-privileged objects or denies the higher-privileged processes to access the lower-privileged objects. The apparatus is provided in a process, and monitors whether a process accesses to a lower-privileged object. The apparatus gives a warning message or denies an access of the process to the lower-privileged object when it detects that the higher-privileged process access to the lower-privileged object. Therefore, the apparatus of detecting and controlling a privilege level violation process detects weaknesses that may be caused by privilege level violation, thus allowing a system to be safely operated.

    摘要翻译: 提供了一种检测和控制特权级别违反过程的装置和方法。 该设备监控较高权限的进程是否依赖于从较低特权对象提供的信息,或拒绝较高权限的进程访问较低权限的对象。 该设备被提供在一个进程中,并且监视进程是否访问较低特权对象。 当设备检测到较高权限的进程访问较低权限的对象时,该设备会发出警告消息或拒绝对低级特权对象的访问。 因此,检测和控制特权级别违规处理的装置检测可能由特权级别违规引起的弱点,从而允许系统安全地操作。

    File mutation method and system using file section information and mutation rules
    9.
    发明授权
    File mutation method and system using file section information and mutation rules 有权
    文件变异方法和系统使用文件段信息和突变规则

    公开(公告)号:US08010844B2

    公开(公告)日:2011-08-30

    申请号:US12037985

    申请日:2008-02-27

    IPC分类号: G06F11/00

    CPC分类号: G06F11/3684

    摘要: Provided are a file mutation method and a system using file section information and mutation rules. The file mutation system includes: a file section information extraction module obtaining file section information with respect to a sample file of a known file format; a file section information production module producing file section information with respect to a sample file of an unknown format; a mutation rule production module receiving a user input that a mutation rule is applied and producing a mutation rule, the mutation rule defining a mutation function that is to be applied to each data type; and a file mutation module receiving the sample file and producing a plurality of test case files that are created by mutating the sample file through the file section information processed in the file section information extraction module and the file section information production module and the mutation rule from the mutation rule production module.

    摘要翻译: 提供了一种文件变异方法和使用文件段信息和变异规则的系统。 文件突变系统包括:文件部分信息提取模块,获得关于已知文件格式的样本文件的文件部分信息; 文件部分信息生成模块,针对未知格式的样本文件生成文件部分信息; 突变规则生产模块,接收应用了突变规则的用户输入并产生突变规则,该突变规则定义了应用于每个数据类型的突变函数; 以及文件变形模块,其接收所述样本文件,并生成多个测试用例文件,所述多个测试用例文件是通过在所述文件部分信息提取模块和所述文件部分信息生成模块中处理的所述文件部分信息进行突变而产生的, 突变规则生产模块。