IP Library Granted Patent US 9,977,896
Granted Patent B2
US 9,977,896 · App. 14/878,415 · Granted May 22, 2018

Systems and methods for generating policies for an application using a virtualized environment

Inventor: John C. Fox (Needham, MA)
Assignee: DIGITAL GUARDIAN, INC.
G06F21/53G06F21/566H04L63/20G06F2221/033H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,977,896
App. No.
14/878,415
Granted
May 22, 2018
Kind
B2
Abstract

Provided herein are systems and methods for generating policies for a new application using a virtualized environment. Prior to allowing a new application to operate on a host system, the new application may be installed in a virtual environment. A first program execution restrictor of the virtualized environment may determine a set of policies for the new application. The set of policies may allow the new application to add specific program elements during installation and execution in the virtualized environment. The first program execution restrictor may verify an absence of malicious behavior from the new application while the new application executes in the virtualized environment. The new application may be executed on the host system responsive to the verification. The host system may have a second program execution restrictor that applies the set of policies when the new application is allowed to execute on the host system.

Claims (31)

1. A method for generating policies for a new application using a virtualized environment prior to executing on a host operating system of a client device, the method comprising:

installing, responsive to a request to install a new application on a host system and prior to allowing the new application to operate on the host system, the new application in a virtualized environment for execution;

determining, for a first program execution restrictor of the virtualized environment, a set of policies for the new application, the set of policies allowing the new application to add specific program elements during execution of the new application in the virtualized environment;

detecting, by the first program execution restrictor, that the specific program elements are added to the new application during execution of the new application in the virtualized environment;

verifying, via the first program execution restrictor applying the set of policies, an absence of malicious behavior from the specific program elements detected to be added to the new application during execution of the new application in the virtualized environment, wherein malicious behavior includes accessing a memory address restricted from the new application; and

executing, responsive to the verification, the new application on the host system, the host system having a second program execution restrictor that applies the set of policies when the new application executes on the host system.

2. The method of claim 1 , further comprising intercepting, by an agent executing on the host system, the request to install the new application on the host system.

3. The method of claim 1 , further comprising directing, by an agent executing on the host system, the new application to the virtualized environment for installation responsive to the request to install the new application on the host system.

4. The method of claim 1 , further comprising using a process monitor of the virtualized environment to detect for malicious behavior by the new application in the virtualized environment.

5. The method of claim 1 , further comprising generating, by the first program execution restrictor, a log record of actions by the new application to add program elements during installation and execution of the new application.

6. The method of claim 5 , further comprising determining, by a policy generator, the set of policies using the generated log record.

7. The method of claim 1 , wherein determining the set of policies comprises detecting an attempt by the new application to add a first program element, and generating a first policy that allows the new application to add the first program element if the first program element is known to be safe.

8. The method of claim 1 , wherein the verifying comprises detecting if the new application attempts to add a program element that is at least one of unknown or potentially unsafe for the host system.

9. The method of claim 1 , further comprising providing, by the virtualization environment, the set of policies to the second program execution restrictor of the host system responsive to the verification.

10. The method of claim 1 , further comprising requesting, by an agent executing on the host system, the virtualization environment to transition the new application to the host system after verifying the absence of malicious behavior.

11. A system for generating policies for a new application using a virtualized environment prior to executing on a host operating system of a client device, the system comprising:

a virtualized environment executed on a computing device having one or more processors, configured to install a new application in the virtualized environment for execution, responsive to a request to install the new application on a host system and prior to allowing the new application to operate on the host system;

a first program execution restrictor executing in the virtualized environment, the first program execution restrictor configured to:

determine a set of policies for the new application, the set of policies allowing the new application to add specific program elements during execution of the new application in the virtualized environment;

detect that the specific program elements are added to the new application during execution of the new application in the virtualized environment; and

verify, via the set of policies, an absence of malicious behavior from the specific program elements detected to be added to the new application during execution of the new application in the virtualized environment, wherein malicious behavior includes accessing a memory address restricted from the new application, wherein the new application is allowed to execute on the host system responsive to the verification; and

a second program execution restrictor executing on the host system, the second program execution restrictor configured to apply the set of policies when the new application executes on the host system.

12. The system of claim 11 , further comprising an agent executing on the host system, the agent configured to intercept the request to install the new application on the host system.

13. The system of claim 11 , further comprising an agent executing on the host system, the agent configured to direct the new application to the virtualized environment for installation responsive to the request to install the new application on the host system.

14. The system of claim 11 , further comprising a process monitor of the virtualized environment, the process monitor utilized to detect for malicious behavior by the new application in the virtualized environment.

15. The system of claim 11 , wherein the first program execution restrictor is configured to generate a log record of actions by the new application to add program elements during installation execution of the new application.

16. The system of claim 15 , further comprising a policy generator configured to determine, using the generated log record, the set of policies.

17. The system of claim 11 , wherein the first program execution restrictor is configured to detect an attempt by the new application to add a first program element, and to determine a first policy that allows the new application to add the first program element if the first program element is known to be safe.

18. The system of claim 11 , wherein the first program execution restrictor is configured to detect, as part of the verification, if the new application attempts to add a program element that is at least one of unknown or potentially unsafe for the host system.

19. The system of claim 11 , wherein the virtualization environment is configured to provide the set of policies to the second program execution restrictor of the host system responsive to the verification.

20. The system of claim 11 , further comprising an agent executing on the host system, the agent configured to request the virtualization environment to transition the new application to the host system after verifying the absence of malicious behavior.

Assignments (15)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 58892/0766 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 073783/0619 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 58892/0945 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 073663/0411 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: DIGITAL GUARDIAN LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0844 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: DIGITAL GUARDIAN LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0050 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
RELEASE OF SECURITY INTEREST Recorded May 3, 2022
From: GOLUB CAPITAL LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 059802/0303 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 28, 2022
From: DIGITAL GUARDIAN, LLC
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 058892/0945 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 28, 2022
From: DIGITAL GUARDIAN, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 058892/0766 →
SECOND AMENDED AND RESTATED INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2021
From: DIGITAL GUARDIAN LLC
To: GOLUB CAPITAL LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 055207/0012 →
AMENDED AND RESTATED INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 29, 2019
From: DIGITAL GUARDIAN LLC
To: GOLUB CAPITAL LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 050305/0418 →
CHANGE OF NAME Recorded May 21, 2019
From: DIGITAL GUARDIAN, INC.
To: DIGITAL GUARDIAN LLC
Reel/Frame 049240/0514 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 23, 2018
From: DIGITAL GUARDIAN, INC.
To: GOLUB CAPITAL LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 046419/0207 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 8, 2015
From: FOX, JOHN C.
To: DIGITAL GUARDIAN, INC.
Reel/Frame 036758/0899 →
Continuity (1)
Related Publication 20170103201A1 · Apr 13, 2017