IP Library Patent Application 13022148
Patent Application
App. No. 13/022,148

EXECUTION ENVIRONMENT FILE INVENTORY

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
13/022,148
Abstract

A method is described to maintain (including generate) an inventory of a system of a plurality of containers accessible by a computer system. At least one container is considered to determine whether the container is executable in at least one of a plurality of execution environments characterizing the computer system. Each execution environment is in the group comprising a native binary execution environment configured to execute native machine language instructions and a non-native execution environment configured to execute at least one program to process non-native machine language instructions to yield native machine language instructions. The inventory is maintained based on a result of the considering step. The inventory may be used to exercise control over what executables are allowed to execute on the computer system.

Claims (27)

1 .- 28 . (canceled)

29 . An apparatus, comprising:

a computer system that includes:

an execution unit;

a storage system that couples to the execution unit and that includes a plurality of containers that collectively form at least a portion of an inventory for the computer system;

a native binary execution environment; and

a non-native binary execution environment, wherein a request to run an executable file is authorized based on criteria, the request being intercepted before the executable file is run, and wherein a determination is made as to whether the request results in an object of the inventory being changed as a result of running the executable file.

30 . The apparatus of claim 29 , wherein the request is authorized if the object of the inventory is not changed.

31 . The apparatus of claim 29 , wherein the change is associated with a writing operation, a renaming operation, a moving operation, or a deleting operation of the object.

32 . The apparatus of claim 29 , wherein the criteria include a particular program implicated by the request and associated with changing the object.

33 . The apparatus of claim 29 , wherein the criteria includes a particular user associated with the request that changes the object.

34 . The apparatus of claim 29 , wherein the request is associated with an updater that determines whether the request is authorized.

35 . The apparatus of claim 34 , wherein the updater is an anytime updater that is authorized to make changes to files within the inventory at any time.

36 . The apparatus of claim 34 , wherein the updater is a sometime updater that is authorized to make changes to files within the inventory provided the computer system is in an update mode.

37 . The apparatus of claim 34 , wherein the updater is a non-updater that is prohibited from making changes to files within the inventory of the computer system.

38 . The apparatus of claim 34 , wherein the updater is a signed updater that includes a digital signature or that includes a public/private key pair.

39 . The apparatus of claim 29 , wherein a tracking mode is used for the computer system such that attempts to run a non-inventoried executable file are permitted and logged.

40 . The apparatus of claim 29 , wherein the authorization of the request is dependent on a particular date and time at which the request is received by the computer system.

41 . The apparatus of claim 29 , wherein the authorization of the request is associated with particular attributes of an object to be changed as a result of the executable file being run.

42 . The apparatus of claim 29 , wherein the inventory is compared to a gold image inventory in order to identify a particular delta between the inventories, and wherein updates for the computer system are blocked if the updates cause the delta to exceed a predetermined threshold.

43 . The apparatus of claim 29 , wherein the containers include one or more files that can be accessed by the execution unit.

44 . The apparatus of claim 29 , wherein the native binary execution environment includes a database management system (DBMS).

45 . The apparatus of claim 29 , wherein the native binary execution environment is associated with a Java archive (JAR) file that includes compressed information associated with a Java program.

46 . The apparatus of claim 29 , wherein a centrally maintained inventory for a plurality of hosts is used to authorize additional requests that can change one or more objects relating to the computer system.

47 . The apparatus of claim 46 , wherein the centrally maintained inventory indicates a union of executables of the plurality of hosts, and wherein the centrally maintained inventory is scanned by antivirus or anti-malware code.

48 . The apparatus of claim 46 , wherein a result of the scan is used to perform actions on a selected one of the plurality of hosts.

49 . The apparatus of claim 46 , wherein the centrally maintained inventory is checked against a record of licenses in order to determine which of the hosts are using particular licenses.