IP Library Granted Patent US 10,452,838
Granted Patent B2
US 10,452,838 · App. 15/661,715 · Granted Oct 22, 2019

Providing joint access to an isolated computer object by both an isolated computer application and a non-isolated computer application

Inventor: Mark Kennedy (Gardena, CA)
Assignee: SYMANTEC CORPORATION
G06F21/53G06F21/552G06F21/10G06F21/31G06F21/55G06F21/6209G06F21/6263G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,452,838
App. No.
15/661,715
Granted
Oct 22, 2019
Kind
B2
Abstract

Providing joint access to an isolated computer object by both an isolated computer application and a non-isolated computer application. In one embodiment, a method may include executing a first computer application as a virtualized first computer application in an isolation layer, executing a second computer application as an actual second computer application in an operating system outside the isolation layer, creating a virtualized second computer object in the isolation layer in a location accessible to the virtualized first computer application, creating a gateway third computer object associated with the virtualized second computer object, storing the gateway third computer object outside the isolation layer in a location accessible to the operating system, and enabling joint access to the gateway third computer object by both the virtualized first computer application and the actual second computer application.

Claims (36)

1. A computer-implemented method for providing joint access to an isolated computer object by both an isolated computer application and a non-isolated computer application, at least a portion of the method being performed by a computing device comprising at least one processor, the method comprising:

executing a first computer application as a virtualized first computer application in an isolation layer;

executing a second computer application as an actual second computer application in an operating system outside the isolation layer;

creating a virtualized second computer object in the isolation layer in a location accessible to the virtualized first computer application, the virtualized second computer object being created based on an actual first computer object stored outside the isolation layer in a location accessible to the operating system, the actual first computer object remaining unmodified upon the creating of the virtualized second computer object;

creating a gateway third computer object associated with the virtualized second computer object, the actual first computer object remaining unmodified upon the creating of the gateway third computer object;

storing the gateway third computer object outside the isolation layer in a location accessible to the operating system, the gateway third computer object being an actual computer object or being a reference to a view of the virtualized second computer object that enables the operating system to interact with the virtualized second computer object as though it were an actual computer object;

enabling joint access to the gateway third computer object by both the virtualized first computer application and the actual second computer application; and

allowing the virtualized first computer application and/or the actual second computer application to modify the gateway third computer object outside the isolation layer without modifying the actual first computer object.

2. The method of claim 1 , wherein any modification of the gateway third computer object, by either the virtualized first computer application or the actual second computer application, results in a corresponding modification to the virtualized second computer object.

3. The method of claim 2 , wherein: the virtualized first computer application is not capable of modifying the actual first computer object; and

the actual second computer application is capable of modifying the actual first computer object.

4. The method of claim 1 , further comprising: prior to the executing of the first computer application as the virtualized first computer application in the isolation layer, identifying the first computer application as a potentially malicious computer application.

5. The method of claim 1 , wherein the isolation layer prevents any virtualized computer application executing therein from modifying the operating system and from communicating with any actual computer application executing outside of the isolation layer.

6. The method of claim 1 , wherein: the virtualized second computer object is a virtualized file; and

the gateway third computer object is a file stored in a file system.

7. The method of claim 1 , wherein the virtualized second computer object is one of a virtualized file system, a virtualized file stored in the virtualized file system, a virtualized network connection, a virtualized portion of memory, a virtualized remote procedure call, and a virtualized registry entry.

8. A computer-implemented method for providing joint access to an isolated computer object by both an isolated computer application and a non-isolated computer application, at least a portion of the method being performed by a computing device comprising at least one processor, the method comprising:

executing a first computer application as a virtualized first computer application in an isolation layer;

executing a second computer application as an actual second computer application in an operating system outside the isolation layer;

creating a virtualized second computer object in the isolation layer in a location accessible to the virtualized first computer application, based on an actual first computer object stored outside the isolation layer in a location accessible to the operating system, and without modifying the actual first computer object;

creating a gateway third computer object, associated with the virtualized second computer object, and without modifying the actual first computer object;

storing the gateway third computer object outside the isolation layer in a location accessible to the operating system, the gateway third computer object being an actual computer object or being a reference to a view of the virtualized second computer object that enables the operating system to interact with the virtualized second computer object as though it were an actual computer object; and

enabling modifications to the gateway third computer object by both the virtualized first computer application and the actual second computer application, with any modification of the gateway third computer object, by either the virtualized first computer application or the actual second computer application, resulting in a corresponding modification to the virtualized second computer object.

9. The method of claim 8 , wherein: the virtualized first computer application is not capable of modifying the actual first computer object; and

the actual second computer application is capable of modifying the actual first computer object.

10. The method of claim 8 , wherein: the virtualized second computer object is a file; and

the gateway third computer object is a file stored in a file system.

11. One or more non-transitory computer-readable media comprising one or more computer-readable instructions that, when executed by one or more processors of one or more computing devices, cause the one or more computing devices to perform a method for providing joint access to an isolated computer object by both an isolated computer application and a non-isolated computer application, the method comprising:

executing a first computer application as a virtualized first computer application in an isolation layer;

executing a second computer application as an actual second computer application in an operating system outside the isolation layer;

creating a virtualized second computer object in the isolation layer in a location accessible to the virtualized first computer application, based on an actual first computer object stored outside the isolation layer in a location accessible to the operating system, and without modifying the actual first computer object;

creating a gateway third computer object, associated with the virtualized second computer object, and without modifying the actual first computer object;

storing the gateway third computer object outside the isolation layer in a location accessible to the operating system, the gateway third computer object being an actual computer object or being a reference to a view of the virtualized second computer object that enables the operating system to interact with the virtualized second computer object as though it were an actual computer object; and

enabling modifications to the gateway third computer object by both the virtualized first computer application and the actual second computer application, with any modification of the gateway third computer object, by either the virtualized first computer application or the actual second computer application, resulting in a corresponding modification to the virtualized second computer object.

12. The one or more non-transitory computer-readable media of claim 11 , wherein: the virtualized first computer application is not capable of modifying the actual first computer object; and

the actual second computer application is capable of modifying the actual first computer object.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 27, 2017
From: KENNEDY, MARK
To: SYMANTEC CORPORATION
Reel/Frame 043120/0052 →
Continuity (1)
Related Publication 20190034622A1 · Jan 31, 2019