首页> 外国专利> Securely and efficiently providing user notifications about security actions

Securely and efficiently providing user notifications about security actions

机译:安全有效地向用户提供有关安全措施的通知

摘要

A security agent executing in kernel mode may receive a request from the anti-malware component executing with low privileges in user mode, and, in response, the security agent may perform a security action with respect to a malicious file detected on the computing device. The security agent may then assist the anti-malware component in providing a user notification about the security action by obtaining, on behalf of the anti-malware component, a user token associated with the user session in which the malicious file was detected. The anti-malware component can use the obtained user token to request a pointer to a Component Object Model (COM) interface for outputting the notification in context of the appropriate user session, which allows for securely and efficiently providing the user notification.
机译:以内核模式执行的安全代理可以从以用户模式以低特权执行的反恶意软件组件接收请求,并且作为响应,安全代理可以针对在计算设备上检测到的恶意文件执行安全操作。然后,安全代理可以通过代表反恶意软件组件获取与在其中检测到恶意文件的用户会话关联的用户令牌,来协助反恶意软件组件提供有关安全操作的用户通知。防恶意软件组件可以使用获得的用户令牌来请求指向组件对象模型(COM)接口的指针,以在适当的用户会话的上下文中输出通知,从而可以安全有效地提供用户通知。

著录项

  • 公开/公告号US10762202B2

    专利类型

  • 公开/公告日2020-09-01

    原文格式PDF

  • 申请/专利权人 CROWDSTRIKE INC.;

    申请/专利号US201815951025

  • 发明设计人 ION-ALEXANDRU IONESCU;

    申请日2018-04-11

  • 分类号G06F21;G06F21/55;G06F9/54;G06F21/33;G06F21/56;

  • 国家 US

  • 入库时间 2022-08-21 11:29:26

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号