Invention Grant
US07913092B1 System and method for enforcing application security policies using authenticated system calls
有权
使用经过身份验证的系统调用实施应用程序安全策略的系统和方法
- Patent Title: System and method for enforcing application security policies using authenticated system calls
- Patent Title (中): 使用经过身份验证的系统调用实施应用程序安全策略的系统和方法
-
Application No.: US11321479Application Date: 2005-12-29
-
Publication No.: US07913092B1Publication Date: 2011-03-22
- Inventor: Matti Aarno Hiltunen , Mohan Rajagopalan , Richard Dale Schlichting , Trevor Jim
- Applicant: Matti Aarno Hiltunen , Mohan Rajagopalan , Richard Dale Schlichting , Trevor Jim
- Applicant Address: US GA Atlanta
- Assignee: AT&T Intellectual Property II, L.P.
- Current Assignee: AT&T Intellectual Property II, L.P.
- Current Assignee Address: US GA Atlanta
- Main IPC: G06F11/30
- IPC: G06F11/30

Abstract:
Disclosed is an approach to system call monitoring in which authenticated system calls from an application are easily verified by an operating system kernel. The authenticated system call may be a system call augmented with extra arguments, which specify the policy for that call as well as a cryptographic message authentication code (MAC) that guarantees the integrity of the policy and the system call arguments. This extra information is used by the operating system kernel to verify the system call with little processing overhead. Versions of the applications in which regular system calls have been replaced by authenticated calls are generated automatically by a trusted installer program that reads the application binary, uses static analysis to generate policies, and then rewrites the binary with the authenticated calls. As a result, hacker attacks, malicious software and the like are less likely to be successful in compromising any computers or networks that employ such authenticated system calls.
Information query