首页> 外国专利> APPROACHES FOR SECURING AN INTERNET ENDPOINT USING FINE-GRAINED OPERATING SYSTEM VIRTUALIZATION

APPROACHES FOR SECURING AN INTERNET ENDPOINT USING FINE-GRAINED OPERATING SYSTEM VIRTUALIZATION

机译:利用精细的操作系统虚拟化保护互联网端点的方法

摘要

Approaches for executing untrusted software on a client without compromising the client using micro-virtualization to execute untrusted software in isolated contexts. A template for instantiating a virtual machine on a client is identified in response to receiving a request to execute an application. After the template is identified, without human intervention, a virtual machine is instantiated, using the template, in which the application is to be executed. The template may be selected from a plurality of templates based on the nature of the request, as each template describe characteristics of a virtual machine suitable for a different type of activity. Selected resources such as files are displayed to the virtual machines according to user and organization policies and controls. When the client determines that the application has ceased to execute, the client ceases execution of the virtual machine without human intervention.
机译:在客户端上执行不受信任的软件而又不损害客户端的方法,使用微虚拟化在隔离的上下文中执行不受信任的软件。响应于接收到执行应用程序的请求,识别用于实例化客户端上的虚拟机的模板。识别模板后,无需人工干预,即可使用模板实例化虚拟机,在该虚拟机中执行应用程序。可以基于请求的性质从多个模板中选择模板,因为每个模板都描述了适用于不同类型活动的虚拟机的特征。根据用户和组织的策略和控制,选定的资源(例如文件)将显示给虚拟机。当客户端确定应用程序已停止执行时,客户端将在无需人工干预的情况下停止执行虚拟机。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号