IP Library Patent Application 14265297
Patent Application
App. No. 14/265,297

WHITE LISTS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/265,297
Abstract

A computer has an operating system having a kernel. The operating system is configured to prevent running of software not identified in a list of approved software referred to as a white list. The computer is linked by a communications link to a server which has a comparison program which compares the identities of software present on the computer with software identified in the list to determine what software installed on the computer is not on the white list. A risk determination program determines for each software not on the list whether the software complies with a plurality of risk criteria, and automatically adds to the list the identity of any software determined to be of low risk according to a risk calculation. The list is supplied to the computer. Software absent from the list is prevented from running by the kernel of the operating system.

Claims (26)

1 . A method of controlling a first computer in a communications network, the first computer having an operating system having a kernel, the operating system being configured to prevent running of software not identified in a list of approved software, the method comprising:

running a monitoring program on the first computer which provides to a second computer data relating to items of software installed on the first computer;

running on the second computer a comparison program which compares the identities of the items of software present on the first computer with approved software identified in the list of approved software, and a risk determination program which determines for each item of software present on the first computer and not on the list of approved software whether it poses a high risk or a low risk, wherein the determination is based on a plurality of risk criteria, and automatically adds to the list of approved software the identity of any item of software present on the first computer determined to be of low risk; and

supplying the list of approved software to the first computer whereby the operating system of the first computer prevents the running any item of software absent from the list.

2 . The method of claim 1 , wherein the risk determination is further based on a calculated risk metric dependent on the plurality of risk criteria.

3 . The method of claim 2 , wherein the calculated risk metric is a weighted sum of confidence values associated with the respective criteria.

4 . The method of claim 1 , wherein the plurality of risk criteria include whether the software has a compile time populated producer name, product name, version name and date.

5 . The method of claim 1 , wherein plurality of risk criteria include whether the software has a security certificate.

6 . The method of claim 1 , wherein plurality of risk criteria include the identity of where the software runs from on the first computer.

7 . The method of claim 1 , wherein the criteria include whether the software on the first computer runs from the network.

8 . The method of claim 1 , wherein the communications network includes a network management system, and wherein the network management system includes an installation system, and wherein the plurality of risk criteria include whether the software on the first computer was installed using the installation system or independently of the network management system.

9 . The method of claim 8 , wherein plurality of risk criteria include whether the software on the first computer has a software identification code associated with the installation system.

10 . The method of claim 7 , wherein the communications network includes a plurality of first computers and includes a computer having a global active directory and storing in association with the directory a global list of approved software, and the second computer has a comparison program for comparing lists of approved software of first computers of the network, the method comprising using the monitoring program to monitor the approved lists of the first computers on the network, determine the proportion of lists listing the same item of software, updating the global list to include that item if the proportion exceeds a predetermined amount, the operating system of each first computer preventing running of software absent from the combination of the global list and its local list.

11 . A non-transitory computer readable medium comprising computer-executable instructions which, when executed by a processor, cause a computing device to perform a method for controlling a first computer having an operating system having a kernel, the operating system being configured to prevent running of software not identified in a list of approved software, the method comprising:

receiving from the first computer data relating to software installed on the first computer;

comparing the identities of software present on the first computer with software identified in the list,

determining for each software on the first computer and not on the list whether the software on the first computer complies with a plurality of risk criteria, and automatically add to the list the identity of any software on the first computer determined to be of low risk; and

sending the list to the first computer.

12 . The non-transitory computer-readable medium of claim 11 , wherein the risk determination program calculates a risk metric dependent on the risk criteria.

13 . The non-transitory computer-readable medium of claim 11 , wherein the risk metric is a weighted sum of confidence values associated with the respective criteria.

14 . The non-transitory computer-readable medium of claim 11 , wherein criteria include whether the software on the first computer has a compile time populated producer name, product name, version name and date.

15 . The non-transitory computer-readable medium of claim 11 , wherein criteria include whether the software on the first computer has a security certificate.

16 . The non-transitory computer-readable medium of claim 11 , wherein criteria include the identity of where the software on the first computer runs from on the computer.

17 . The non-transitory computer-readable medium of claim 11 , for use wherein the first computer is in a network and the criteria include whether the software on the first computer runs from the network.

18 . The non-transitory computer-readable medium of claim 11 , for use wherein first computer is in a network having a network management system including an installation system and the criteria include whether the software on the first computer was installed using the installation system or independently of the network management system.

19 . The non-transitory computer-readable medium of claim 18 , wherein criteria include whether the software on the first computer has a software identification code associated with the installation system

Assignments (4)
RELEASE BY DECLARATION RECORDED AT REEL 041984, FRAME 0904 Recorded Jan 21, 2025
From: SILICON VALLEY BANK
To: IE LIMITED
Reel/Frame 069986/0908 →
SECURITY INTEREST Recorded Apr 12, 2017
From: 1E LIMITED
To: SILICON VALLEY BANK
Reel/Frame 041984/0904 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2014
From: THRELKELD, RICHARD; GREENWOOD, ADRIAN
To: 1E INC.
Reel/Frame 033801/0017 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2014
From: 1E INC.
To: 1E LIMITED
Reel/Frame 033801/0031 →