INSTRUMENTED VERSIONS OF EXECUTABLE FILES
Examples described herein include receiving a loading request of an executable file from a requester. The executable file may include original content. Examples described herein also include determining an instrumented version of the executable file to provide to the requester based on a security policy, determining an existence of the instrumented version of the executable file on a storage, and providing the instrumented version of the executable file to the requester. The instrumented version may include protective content in addition to the original content of the executable file.
1 . A non-transitory machine-readable storage medium comprising instructions that, when executed, cause a processing resource to:
receive a loading request of an executable file from a requestor, the executable file comprising original content;
determine an instrumented version of the executable file to provide to the requestor based on a security policy, wherein the instrumented version of the executable file comprises protective content in addition to the original content of the executable file;
determine an existence of the instrumented version of the executable file on a storage; and
provide the instrumented version of the executable file to the requestor.
2 . The non-transitory machine-readable storage medium of claim 1 , wherein the protective content comprises a call-out to a protective instruction.
3 . The non-transitory machine-readable storage medium of claim 2 , wherein the instructions to provide the instrumented version of the executable file comprises:
instructions to generate the instrumented version of the executable file.
4 . The non-transitory machine-readable storage medium of claim 3 , wherein the instructions to generate the instrumented version of executable file comprises:
instructions to select the protective instruction; and
instructions to augment the original content of the executable file with the call-out to the protective instruction.
5 . The non-transitory machine-readable storage medium of claim 4 , wherein the instructions to generate the instrumented version of the executable file comprises:
instructions to store the instrumented version of the executable file in the storage.
6 . The non-transitory machine-readable storage medium of claim 5 , comprises:
instructions to update a reference dataset regarding the generation of the instrumented version of the executable file,
7 . The non-transitory machine-readable storage medium of claim 1 , comprising:
instructions to receive an updated security policy;
instructions to determine a second instrumented version of the executable file based on the updated security policy;
instructions to generate the second instrumented version of the executable file; and
instructions to store the second instrumented version of the executable file in the storage.
8 . The non-transitory machine-readable storage medium of claim 1 , wherein the instructions to determine an existence of the instrumented version of the executable file comprises instructions to query a reference dataset.
9 . A method comprising:
receiving a loading request of an executable file, the executable file comprising original content;
determining an instrumented version of the executable file based on a security policy, wherein the instrumented version comprises protective content in addition to the original content of the executable file;
querying a reference dataset for an existence of the instrumented version of the executable file; and
providing the instrumented version of the executable file to be loaded.
10 . The method of claim 9 , wherein the reference dataset reflects instrumented files stored on a first storage.
11 . The method of claim 10 , wherein the providing of the instrumented version of the executable file to be loaded comprises reading the instrumented version of the executable file from the first storage.
12 . The method of claim 10 , comprising:
generating the instrumented version of the executable file; and
storing the instrumented version of the executable file on the first storage.
13 . The method of claim 12 , wherein the generating of the instrumented version of the executable file comprises:
reading the original content of the executable file from a second storage; and
augmenting the original content of the executable file with the protective content,
14 . The method of claim 13 , wherein the protective content comprises a call-out to protective instructions.
15 . The method of claim 10 , comprising:
updating the security policy;
determining a second instrumented version of the executable file based on the updated security policy;
generating the second instrumented version of the executable file;
storing the second instrumented version of the executable file on the first storage; and
providing the second instrumented version of the executable file to be loaded.
16 . A computing device comprising:
a policy engine to set a security policy;
a runtime engine to
receive a loading request of an executable file, the executable file comprising original content;
determine an instrumented version of the executable file based on the security policy, wherein the instrumented version of the executable file comprises protective content in addition to the original content of the executable file;
determine an existence of the instrumented version of the executable file; and
a loading engine to load the instrumented version of the executable file.
17 . The computing device of claim 15 , comprising an instrumentation engine to generate the instrumented version of the executable file.
18 . The computing device of claim 17 ,
wherein the policy engine is to set a new security policy;
wherein the runtime engine is to determine a second instrumented version of the executable file based on the new security policy; and
wherein the instrumentation engine is to generate the second instrumented version of the executable file and store the second instrumented version.
19 . The computing device of claim 16 , wherein the runtime engine is to query a reference dataset to determine an existence of the instrumented version of the executable file.
20 . The computing device of claim 16 , wherein the runtime engine is to query a reference dataset to determine the instrumented version of the executable file.