MECHANISM TO FREE UP THE OVERLAY OF A FILE-BASED WRITE FILTER

    公开(公告)号:US20180217940A1

    公开(公告)日:2018-08-02

    申请号:US15422012

    申请日:2017-02-01

    Abstract: An overlay of a file-based write filter can be freed up to thereby minimize the likelihood that the overlay will become full and force a system reboot. An overlay-managing write filter can be employed in conjunction with the file-based write filter to monitor files that are stored in the overlay and move files that are not currently being accessed. If a request is made to access a moved file, the overlay-managing write filter can modify the request so that it targets the location of the moved file rather than the location of the original file on the protected volume. In this way, the fact that modified files are being moved from the overlay but not discarded can be hidden from the file-based write filter. As a result, the effective size of the overlay will be increased while still allowing the file-based write filter to function in a normal fashion.

    SECURING ACCESS TO FUNCTIONALITY OF A FILE-BASED WRITE FILTER

    公开(公告)号:US20180217996A1

    公开(公告)日:2018-08-02

    申请号:US15418074

    申请日:2017-01-27

    CPC classification number: G06F21/00 G06F16/1734 G06F21/6218 G06F21/79

    Abstract: Access to functionality of a file-based write filter can be secured. A policy-based filter can be configured to monitor and filter calls to APIs that access functionality of the file-based write filter. Based on policy, the policy-based filter can selectively block such calls to ensure that only permitted applications and/or users are allowed to access the functionality of the file-based write filter. In some cases, the policy-based filter can be configured to communicate with a server component to determine whether a particular attempt to access the functionality of the file-based write filter should be allowed.

    RESTRICTING APPLICATIONS AND USERS THAT CAN MAKE PERSISTENT CHANGES TO ARTIFACTS

    公开(公告)号:US20180217946A1

    公开(公告)日:2018-08-02

    申请号:US15418011

    申请日:2017-01-27

    CPC classification number: G06F12/1458 G06F12/1433 G06F21/79 G06F2212/1052

    Abstract: Applications and users can be restricted from making persistent changes to artifacts on a protected volume. In Windows-based systems that include a file-based write filter, a policy-based write filter can be positioned below the file-based write filter and can examine any write requests that target artifacts of a protected volume and are not redirected by the file-based write filter. The policy-based write filter can examine the write requests against any applicable policies to determine whether the write requests should be allowed to proceed. If the policy-based write filter determines that a write request is not allowed by policy, it can fail the write request to thereby prevent the targeted artifact from being updated in the protected volume.

Patent Agency Ranking