IP Library Granted Patent US 7,895,409
Granted Patent B2
US 7,895,409 · App. 11/888,098 · Granted Feb 22, 2011

Application inspection tool for determining a security partition

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,895,409
App. No.
11/888,098
Granted
Feb 22, 2011
Kind
B2
Abstract

An embodiment of the invention provides an apparatus and method for determining a security partition in a computer for an application. The apparatus and method can determine required system resources, security requirements, and partition rules for an application, can determine allocated system resources, security characteristics, and partitions rules for each security partition in the computer, and can identify at least one proposed security partition for the application.

Claims (36)

1. A method for determining a security partition in a computer for an application, the method comprising:

determining required system resources, security requirements, and partition rules for an application by use of an application analysis tool;

determining allocated system resources, security characteristics, and partition rules for each security partition in the computer;

comparing the required system resources, security requirements, and partition rules for the application to the allocated system resources, security characteristics, and partition rules for each security partition in the computer; and

identifying, by the application analysis tool, at least one proposed security partition for the application based on the comparison.

2. The method of claim 1 , wherein determining the required system resources, security requirements, and partition rules for the application comprises: checking a database that stores configuration information that is associated with the application.

3. The method of claim 1 , wherein determining the required determining system resources, security requirements, and partition rules for the application comprises: checking a file system that stores configuration information that is associated with the application if the application is installed in the computer.

4. The method of claim 1 , further comprising:

selecting, by a user, a proposed security partition for the application.

5. The method of claim 1 , wherein the required system resources for the application comprise a CPU resource, memory resource, and disk input/output bandwidth.

6. The method of claim 1 , wherein the security requirements for the application comprise roles and privileges associated with the application.

7. The method of claim 1 , wherein the partition rules for the application comprise constraints on communications by the application.

8. The method of claim 1 , wherein the partition rules for the application comprise permitted access operations by the application on an object in a security partition.

9. The method of claim 1 , further comprising:

transmitting a selected proposed security partition to a partition manager for creating the selected proposed security partition or binding the application to an existing security partition.

10. An apparatus for determining a security partition in a computer for an application, the apparatus comprising:

an application analysis tool configured to determine required system resources, security requirements, and partition rules for an application, determine allocated system resources, security characteristics, and partition rules for each security partition in the computer, compare the required system resources, security requirements, and partition rules for the application to the allocated system resources, security characteristics, and partition rules for each security partition in the computer; and identify at least one proposed security partition for the application based on the comparison.

11. The apparatus of claim 10 , wherein the application analysis tool is configured to check a database that stores configuration information that is associated with the application.

12. The apparatus of claim 10 , wherein the application analysis tool is configured to check a file system that stores configuration information that is associated with the application if the application is installed in the computer.

13. The apparatus of claim 10 , wherein a user selects a proposed security partition for the application.

14. The apparatus of claim 10 , wherein the required system resources for the application comprise a CPU resource, memory resource, and disk input/output bandwidth.

15. The apparatus of claim 10 , wherein the security requirements for the application comprise roles and privileges associated with the application.

16. The apparatus of claim 10 , wherein the partition rules for the application comprise constraints on communications by the application.

17. The apparatus of claim 10 , wherein the partition rules for the application comprise permitted access operations by the application on an object in a security partition.

18. The apparatus of claim 10 , wherein the application analysis tool is configured to transmit a selected proposed security partition to a partition manager for creating the selected proposed security partition or binding the application to an existing security partition.

19. An apparatus for determining a security partition in a computer for an application, the apparatus comprising:

means for determining required system resources, security requirements, and partition rules for an application;

means for determining allocated system resources, security characteristics, and partition rules for each security partition in the computer;

means for comparing the required system resources, security requirements, and partition rules for the application to the allocated system resources, security characteristics, and partition rules for each security partition in the computer; and

means for identifying at least one proposed security partition for the application based on the comparison.

20. An article of manufacture comprising:

a machine-readable medium having stored thereon instructions to:

determine required system resources, security requirements, and partition rules for an application;

determine allocated system resources, security characteristics, and partition rules for each security partition in the computer;

compare the required system resources, security requirements, and partition rules for the application to the allocated system resources, security characteristics, and partition rules for each security partition in the computer; and

identify at least one proposed security partition for the application based on the comparison.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 18, 2021
From: OT PATENT ESCROW, LLC
To: VALTRUS INNOVATIONS LIMITED
Reel/Frame 058897/0262 →
PATENT ASSIGNMENT, SECURITY INTEREST, AND LIEN AGREEMENT Recorded Jan 26, 2021
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP; HEWLETT PACKARD ENTERPRISE COMPANY
To: OT PATENT ESCROW, LLC
Reel/Frame 055269/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2007
From: MENDONCA, JOHN J.
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 019689/0553 →