会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 5. 发明申请
    • SECURITY SYSTEM TO PROTECT SYSTEM SERVICES BASED ON USER DEFINED POLICIES
    • 基于用户定义的政策来保护系统服务的安全系统
    • US20110154364A1
    • 2011-06-23
    • US12644060
    • 2009-12-22
    • Murali Vaddagiri
    • Murali Vaddagiri
    • G06F9/54
    • G06F21/6218G06F9/468
    • System Services to be protected, and corresponding user defined Policies are provided in a table. A module is provided in the operating system with instructions to intercept messages requesting use of System Services, correlate parameters from the messages with the table, and issue an error message signifying denial to a requesting entity if the parameters do not match an entry in the table. If the parameters match an entry in the table, the module generates, and issues a message, to the requesting entity, allowing access to the requested System Service. Optionally, the event may be logged in a memory, and the administrator is notified.
    • 要保护的系统服务以及相应的用户定义的策略在表中提供。 在操作系统中提供了用于拦截请求使用系统服务的消息的指令的模块,将来自消息的参数与表相关联,并且如果参数与表中的条目不匹配,则向请求实体发出表示拒绝的错误消息 。 如果参数与表中的条目匹配,则该模块生成并发出消息给请求实体,允许访问所请求的系统服务。 可选地,事件可以被记录在存储器中,并且通知管理员。
    • 7. 发明授权
    • System and method for dynamic creation of privileges to secure system services
    • 用于动态创建安全系统服务权限的系统和方法
    • US08359635B2
    • 2013-01-22
    • US12036318
    • 2008-02-25
    • Saurabh DesaiMurali Vaddagiri
    • Saurabh DesaiMurali Vaddagiri
    • G06F7/04G06F15/16G06F17/30G06F12/00G06F12/14G06F13/00G06F3/00G06F9/44G06F9/46H04L29/06G11C7/00
    • G06F21/6218G06F9/468G06F21/604G06F21/6281
    • A system, method, and program product is provided that allows new privileges to be dynamically added to an operating system. Entities are assigned roles and these roles are associated with various authorizations. Authorizations are associated with privileges, including the new privilege. A request is received to dynamically add the new privilege to the operating system. The operating system then dynamically adds the new privilege to the system. A software service is installed that requires the new privilege. A request to execute the installed software service is received from an entity that is running on the operating system. The operating system allows the entity to execute the installed software service in response to determining that the entity has been granted the privilege. However, if the entity has not been granted the new privilege, then the operating system inhibits execution of the software service by the entity.
    • 提供了一种允许动态添加到操作系统的新特权的系统,方法和程序产品。 实体被分配角色,这些角色与各种授权相关联。 授权与权限相关联,包括新特权。 收到请求以动态添加新的特权到操作系统。 操作系统然后动态地将新的权限添加到系统。 安装了需要新特权的软件服务。 从操作系统上运行的实体接收到执行安装的软件服务的请求。 操作系统允许实体响应于确定实体已被授予特权而执行安装的软件服务。 但是,如果实体尚未被授予新的权限,则操作系统将禁止该实体对软件服务的执行。
    • 10. 发明申请
    • Managing Memory
    • 管理记忆
    • US20110125812A1
    • 2011-05-26
    • US12623738
    • 2009-11-23
    • Madhusudanan KandasamyVidya RanganathanMurali Vaddagiri
    • Madhusudanan KandasamyVidya RanganathanMurali Vaddagiri
    • G06F12/02G06F12/00
    • G06F12/0284G06F9/45537
    • Methods, systems, and products for managing memory. In one general embodiment, the method includes assigning an isolated virtual heap in a global kernel heap of a global operating system environment to each of a plurality of isolated virtual operating system environments operating in a global operating system environment; and in response to an invocation of kernel heap memory allocation from one of the isolated virtual operating system environments, dynamically allocating memory to the invoking isolated virtual operating system environment from the virtual kernel heap assigned to the invoking isolated virtual operating system environment. The method may also include running the plurality of isolated virtual operating system environments in the global operating system environment. The plurality of isolated virtual operating system environments may share a single common kernel. The isolated virtual operating system environments may run under the same operating system image.
    • 用于管理内存的方法,系统和产品。 在一个一般实施例中,该方法包括将全局操作系统环境的全局内核堆中的隔离的虚拟堆分配给在全局操作系统环境中操作的多个孤立的虚拟操作系统环境中的每一个; 并且响应于从隔离的虚拟操作系统环境之一调用内核堆内存分配,从分配给调用的隔离虚拟操作系统环境的虚拟内核堆中动态地将内存分配给调用的隔离虚拟操作系统环境。 该方法还可以包括在全局操作系统环境中运行多个隔离的虚拟操作系统环境。 多个隔离的虚拟操作系统环境可以共享单个公共内核。 隔离的虚拟操作系统环境可以在相同的操作系统映像下运行。