IP Library Granted Patent US 8,839,422
Granted Patent B2
US 8,839,422 · App. 12/827,203 · Granted Sep 16, 2014

Virtual browsing environment

Inventors: Anup K Ghosh (Centreville, VA); Sushil Jajodia (Oakton, VA); Yih Huang (Fairfax, VA); Jiang Wang (Fairfax, VA)
Assignee: George Mason Research Foundation, Inc.
G06F9/54G06F21/56H04L63/1483G06F21/53
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,839,422
App. No.
12/827,203
Granted
Sep 16, 2014
Kind
B2
Abstract

An embodiment for providing a secure virtual browsing environment includes creating a virtual browsing environment with a virtualized operating system sharing an operating system kernel of a supporting operating system and executing the browser application within the virtual browsing environment. Another embodiment includes receiving a website selection within a browser application, determining if the website selection corresponds to a secure bookmark, and creating a second virtual browsing environment and executing the browser application within the second virtual browsing environment to access the website selection when the website selection corresponds to a website specified as a secure bookmark. Yet another embodiment includes monitoring operation of the operating system within the at least one virtual browsing environment, determining when the operation of the operating system includes potential malicious activity, and terminating the virtual browsing environment when the operation includes potential malicious activity.

Claims (39)

1. A tangible non-transitory processor-readable medium containing instructions that when executed by one or more processors, performs a method comprising:

upon initiation of at least one browser application, creating at least one virtual browsing environment with at least one operating system and executing the at least one browser application within the at least one virtual browsing environment;

monitoring operation of the at least one operating system within the at least one virtual browsing environment;

determining when an operation of the at least one operating system within the at least one virtual browsing environment includes potential malicious activity;

terminating the at least one virtual browsing environment when the operation includes potential malicious activity; and

transmitting information to at least one collection computer about potential malicious activity when the operation of the at least one operating system of the at least one virtual browsing environment includes potential malicious activity, the information including at least one website address and an indication of an operation of the at least one operating system when the at least one browser application executed within the at least one virtual browsing environment accessed at least one website at the at least one website address.

2. The tangible non-transitory processor-readable medium of claim 1 , wherein the method further comprises displaying information about potential malicious activity to at least one user when the operation of the at least one operating system of the at least one virtual browsing environment includes potential malicious activity.

3. The tangible non-transitory processor-readable medium of claim 1 , wherein the method further comprises creating at least one second virtual browsing environment after terminating the at least one virtual browsing environment.

4. The tangible non-transitory processor-readable medium of claim 3 , wherein the method further comprises taking at least one snapshot of the at least one virtual browsing environment upon creation.

5. The tangible non-transitory processor-readable medium of claim 4 , wherein the creating the at least one second virtual browsing environment after terminating the at least one virtual browsing environment includes restoring the at least one virtual browsing environment using the at least one snapshot.

6. The tangible non-transitory processor-readable medium of claim 1 , wherein the method further comprises terminating the at least one virtual browsing environment after at least one predetermined period of time.

7. The tangible non-transitory processor-readable medium of claim 1 , wherein the method further comprises receiving a website selection within the at least one browser application and determining if the website selection corresponds to a website specified as a secure bookmark.

8. The tangible non-transitory processor-readable medium of claim 7 , wherein the method further comprises:

when the website selection corresponds to a website specified as a secure bookmark, creating at least one second virtual browsing environment with at least one operating system, executing at least one browser application within the at least one second virtual browsing environment, and accessing the website selection within the at least one browser application executed within the at least one second virtual browsing environment.

9. The tangible non-transitory processor-readable medium of claim 1 , wherein the at least one operating system of the at least one virtual browsing environment includes at least one virtualized operating system sharing at least one kernel of at least one supporting operating system.

10. The tangible non-transitory processor-readable medium of claim 9 , wherein the method further comprises creating at least one virtual computer including the at least one supporting operating system with the at least one kernel and creating the at least one virtual browsing environment within the at least one virtual computer.

11. A tangible non-transitory processor-readable medium containing instructions that when executed by one or more processors perform a method comprising:

upon initiation of at least one browser application, creating at least one first virtual browsing environment with at least one operating system and executing the at least one browser application within the at least one first virtual browsing environment;

receiving a website selection within the at least one browser application;

determining if the website selection corresponds to a website specified as a secure bookmark;

when the website selection corresponds to a website specified as a secure bookmark, creating at least one second virtual browsing environment with at least one operating system, executing at least one browser application within the at least one second virtual browsing environment, and accessing the website selection within the at least one browser application executed within the at least one second virtual browsing environment; and

when the website selection does not correspond to a website specified as a secure bookmark, accessing the website selection with the at least one browser application executed within the at least first virtual browsing environment.

12. The tangible non-transitory processor-readable medium of claim 11 , wherein the method further comprises modifying the at least one browser application executed within the at least one second virtual browsing environment to prevent the at least one browser application executed within the at least one second virtual browsing environment from being directed to a website different from the website selection.

13. The tangible non-transitory processor-readable medium of claim 12 , wherein the modifying the at least one browser application includes setting an address line of the at least one browser application executed within the at least one second virtual browsing environment to be read-only.

14. The tangible non-transitory processor-readable medium of claim 12 , wherein the modifying the at least one browser application includes disabling toolbar options within the at least one browser application executed within the at least one second virtual browsing environment that allow a user to select a website to access.

15. The tangible non-transitory processor-readable medium of claim 11 , wherein the determining if the website selection corresponds to a website specified as a secure bookmark includes comparing the website selection to at least one file of secure bookmarks.

16. The tangible non-transitory processor-readable medium of claim 15 , wherein the method further comprises receiving at least one indication to set the website as a secure bookmark and updating the at least one file of secure bookmarks based on the at least one indication.

17. The tangible non-transitory processor-readable medium of claim 11 , wherein the at least one operating system of the at least one first virtual browsing environment and the at least one operating system of the at least one second virtual browsing environment include at least one virtualized operating system sharing at least one kernel of at least one supporting operating system.

18. The tangible non-transitory processor-readable medium of claim 17 , wherein the method further comprises creating at least one virtual computer including the at least one supporting operating system with the at least one kernel and creating the at least one first virtual browsing environment and the at least one second virtual browsing environment within the at least one virtual computer.

19. The tangible non-transitory processor-readable medium of claim 11 , wherein the method further comprises monitoring operation of the at least one operating system within the at least one second virtual browsing environment, determining if the operation of the at least one operating system within the at least one second virtual browsing environment includes potential malicious activity, and terminating the at least one second virtual browsing environment when the operation includes potential malicious activity.

20. A tangible non-transitory processor-readable medium containing instructions that when executed by one or more processors, performs a method comprising:

upon initiation of at least one browser application, creating at least one virtual browsing environment with at least one operating system and executing the at least one browser application within the at least one virtual browsing environment;

taking at least one snapshot of the at least one virtual browsing environment upon creation;

monitoring operation of the at least one operating system within the at least one virtual browsing environment;

determining when the operation of the at least one operating system within the at least one virtual browsing environment includes potential malicious activity;

terminating the at least one virtual browsing environment when the operation includes potential malicious activity;

transmitting information to at least one collection computer about potential malicious activity when the operation of the at least one operating system within the at least one virtual browsing environment includes potential malicious activity, the information including at least one website address and an indication of an operation of the at least one operating system when the at least one browser application executed within the at least one virtual browsing environment accessed at least one website at the at least one website address;

creating at least one second virtual browsing environment after terminating the at least one virtual browsing environment; and

restoring the at least one virtual browsing environment using the at least one snapshot.

Assignments (3)
CHANGE OF NAME Recorded Oct 3, 2013
From: GEORGE MASON INTELLECTUAL PROPERTIES, INC.
To: GEORGE MASON RESEARCH FOUNDATION, INC.
Reel/Frame 031336/0195 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 13, 2010
From: GHOSH, ANUP K.; JAJODIA, SUSHIL; WANG, JIANG; HUANG, YIH
To: GEORGE MASON UNIVERSITY
Reel/Frame 024834/0514 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 13, 2010
From: GEORGE MASON UNIVERSITY
To: GEORGE MASON INTELLECTUAL PROPERTIES, INC.
Reel/Frame 024834/0801 →
Continuity (2)
Provisional Application 61221749 · Jun 30, 2009
Related Publication 20110167492A1 · Jul 7, 2011