IP Library Granted Patent US 7,870,387
Granted Patent B1
US 7,870,387 · App. 11/400,085 · Granted Jan 11, 2011

Program-based authorization

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,870,387
App. No.
11/400,085
Granted
Jan 11, 2011
Kind
B1
Abstract

Techniques which allow definition and enforcement of program-based action authorization policies. On a computer, an action or execution attempt is intercepted in real-time. The subject process, the program file of the subject process, the attempted action and the object of the attempted action are determined. An authorization policy considering the program file indicates whether the attempted action is authorized or not. In a tracking mode, the attempted action and its authorization are logged and the attempted action is allowed to proceed. In an enforcement mode, unauthorized attempts are blocked and logged, thereby enforcing the authorization policy.

Claims (28)

1. A method for authorizing file system actions on a computer, comprising:

intercepting a file system action attempt indicating an action by a process on a file;

determining a program file representing code being executed by the process;

allowing the action to proceed when it is authorized, as indicated by an authorization policy, wherein a first log is generated for the action, and wherein a first set of attributes is identified as being associated with the action, the first set of attributes including an action type, a request type, a date and a time at which the action is being attempted, and a set of differences between one or more parts of content of an object sought to be altered by the action, and wherein the differences identify changes between the content before and after the action; and

blocking the action when it is not authorized and when a first mode is being used, and wherein a second mode is configured to allow the action when it is not authorized according to the authorization policy and a second log is subsequently generated to identify the unauthorized action as having occurred;

wherein the authorization policy indicates whether the process is authorized to perform the action on the file.

2. A method as recited in claim 1 , wherein the determining step further determines one or more attributes of the processor of the program file.

3. A method as recited in claim 1 , wherein the action indicates a read operation on the file.

4. A method as recited in claim 1 , wherein the action indicates a write, append or truncate operation on the file.

5. A method as recited in claim 1 , wherein the action indicates a delete, move or rename operation on the file.

6. A method for authorizing registry actions on a computer, comprising:

intercepting a registry action attempt indicating an action by a process on a registry entry;

determining a program file representing code being executed by the process;

allowing the action to proceed when it is authorized, as indicated by an authorization policy, wherein a first log is generated for the action, and wherein a first set of attributes is identified as being associated with the action, the first set of attributes including an action type, a request type, a date and a time at which the action is being attempted, and a set of differences between one or more parts of content of an object sought to be altered by the action, and wherein the differences identify changes between the content before and after the action; and

blocking the action when it is not authorized according to the authorization policy and when a first mode is being used, and wherein a second mode is configured to allow the action when it is not authorized and a second log is subsequently generated to identify the unauthorized action as having occurred;

wherein the authorization policy indicates whether the process is authorized to perform the action on the registry entry.

7. A method as recited in claim 6 , wherein the determining step further determines one or more attributes of the process or of the program file.

8. A method as recited in claim 6 , wherein the action indicates a read, retrieve, write, create or delete operation on the registry entry.

9. A method for authorizing executions on a computer, comprising:

intercepting an execution attempt indicating a process attempting to execute an executable file;

determining a program file representing code being executed by the process;

allowing the execution to proceed when it is authorized, as indicated by an authorization policy, wherein a first log is generated for the action, and wherein a first set of attributes is identified as being associated with the action, the first set of attributes including an action type, a request type, a date and a time at which the action is being attempted, and a set of differences between one or more parts of content of an object sought to be altered by the action, and wherein the differences identify changes between the content before and after the action; and

blocking the execution when it is not authorized according to the authorization policy and when a first mode is being used, and wherein a second mode is configured to allow the action when it is not authorized and a second log is subsequently generated to identify the unauthorized action as having occurred;

wherein the authorization policy indicates whether the process is authorized to execute the executable file.

10. A method as recited in claim 9 , wherein the determining step further determines one or more attributes of the process or of the program file.

11. A method as recited in claim 9 , wherein the authorization policy authorizes the execution when the executable file was created by the process.

12. A method as recited in claim 9 , wherein the authorization policy authorizes the execution when the executable file was created by any process executing the program file.

13. A method as recited in claim 9 , wherein the authorization policy authorizes the execution when the executable file was created by the process or by an ancestor process of the process.

Assignments (11)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
MERGER Recorded Jul 20, 2009
From: SOLIDCORE SYSTEMS, INC.
To: MCAFEE, INC.
Reel/Frame 022973/0458 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2006
From: BHARGAVA, RISHI; SEBES, E. JOHN
To: SOLIDCORE SYSTEMS, INC.
Reel/Frame 017773/0068 →