Elevated security execution mode for network-accessible devices
US-2024411878-A1 · Dec 12, 2024 · US
US9262597B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9262597-B2 |
| Application number | US-201313842350-A |
| Country | US |
| Kind code | B2 |
| Filing date | Mar 15, 2013 |
| Priority date | Mar 15, 2013 |
| Publication date | Feb 16, 2016 |
| Grant date | Feb 16, 2016 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A request that includes an indication of an execution context and data that represents executable code is obtained. An analysis of the data is initiated based on generating a first templatized representation of the executable code. A list of clearance indicators that indicate a blocking status associated with respective forms of templatized representations is accessed. A workflow policy is determined based on the accessing of the list of clearance indicators. The list of clearance indicators is updated, based on a result of the analysis of the data.
Opening claim text (preview).
What is claimed is: 1. A system comprising: a device that includes at least one processor, and a computer readable storage medium storing instructions for execution by one or more of the at least one processor, for implementing a code validation engine that includes: a request acquisition component that obtains a request that includes an indication of an execution context and data that represents executable code, the execution context including descriptive information for identification of a source of the request; a data analysis component that initiates a first analysis of the data based on generating a first templatized representation of the executable code; a list access component that accesses a list of one or more clearance indicators that indicate a blocking status associated with respective forms of templatized representations; a workflow policy component that determines a first workflow policy based on the accessing of the list of clearance indicators; and a list update component that initiates a first update to the list of one or more clearance indicators, based on a result of the first analysis of the data, and based on a result of obtaining a count of a number of occurrences of determinations of unacceptability associated with other requests previously obtained from the source of the request, based on the descriptive information in the execution context, the one or more of the at least one processor initiating control of execution of the executable code represented by the data, in accordance with a result of the accessing the list of one or more clearance indicators. 2. The system of claim 1 , further comprising: a template comparison component that initiates a comparison of the first templatized representation of the executable code with one or more entries in the list of clearance indicators. 3. The system of claim 2 , wherein: the data analysis component determines the first templatized representation of the executable code based on parsing a Structured Query Language (SQL) query included in the request, and determining a first templatized representation of the SQL query, based on the parsing of the SQL query, wherein the system further includes a query comparison component that initiates a comparison of the first templatized representation of the SQL query with one or more entries in the list of one or more clearance indicators, wherein the list of clearance indicators includes one or more of: an allow list of clearance indicators that indicate a non-blocked status associated with at least a first portion of the respective forms of templatized representations, or a deny list of clearance indicators that indicate a blocked status associated with at least a second portion of the respective forms of templatized representations, wherein the query comparison component is configured to initiate the comparison of the first templatized representation of the SQL query with one or more entries in the list of clearance indicators based on one or more of: initiating a structural comparison of the first templatized representation of the SQL query with one or more entries in the allow list of clearance indicators, or initiating a structural comparison of the first templatized representation of the SQL query with one or more entries in the deny list of clearance indicators. 4. The system of claim 2 , wherein: the data analysis component determines the first templatized representation of the executable code based on parsing dynamic language code that is embedded in a web page, and determining a templatized form of the embedded dynamic language code, wherein the system further includes a dynamic language comparison component that initiates a comparison of the templatized form of the embedded dynamic language code with one or more entries in the list of one or more clearance indicators. 5. The system of claim 4 , wherein: the dynamic language code includes one or more of: script code, or script code that is embedded within a web page that includes markup language. 6. A method comprising: obtaining a request that includes an indication of an execution context and data that represents executable code, the execution context including descriptive information for identification of a source of the request; initiating a first analysis of the data based on generating a first templatized representation of the executable code; accessing a list of one or more clearance indicators that indicate a blocking status associated with respective forms of templatized representations; determining a first workflow policy based on the accessing of the list of clearance indicators; initiating a first update to the list of one or more clearance indicators, based on a result of the first analysis of the data, and based on a result of obtaining a determination of a level of unacceptability associated with other requests previously obtained from the specific source of the request, based on the descriptive information in the execution context; and initiating control of execution of the executable code represented by the data, in accordance with a result of the accessing the list of one or more clearance indicators. 7. The method of claim 6 , wherein: the first analysis is performed on a client device, or the first analysis is performed on a server. 8. The method of claim 6 , further comprising: determining a second workflow policy based on user input from a query requesting a blocking decision; and initiating a second update to the list of one or more clearance indicators, based on the user input. 9. The method of claim 6 , further comprising: initiating a second analysis that includes: initiating configuration of a runtime environment for dynamic analysis, initiating a conversion of the data to an executable code format, and initiating execution of the executable code format corresponding to the converted data; and initiating a second update to the list of one or more clearance indicators, based on a result of the second analysis. 10. The method of claim 9 , wherein: initiating the second update to the list of one or more clearance indicators is based on detecting one or more exceptions that occur during execution of the executable code format corresponding to the converted data. 11. The method of claim 9 , wherein: a decision to initiate execution of the executable code format corresponding to the converted data is based on: determining a permission status associated with avoidance of configuration of the runtime environment and conversion of the data to an executable code format, based on the obtained workflow policy, or determining a permission status associated with granting permission to initiate configuration of the runtime environment and conversion of the data to an executable code format, based on the obtained workflow policy. 12. The method of claim 6 , further comprising: determining a matching status of the first templatized representation of the executable code with an entry in the list of one or more clearance indicators, based on a matching algorithm, wherein determining the first workflow policy includes obtaining the first workflow policy based on the determined matching status. 13. The method of claim 6 , wherein: the list of clearance indicators includes one or more of: an allow list of clearance indicators that indicate a non-blocked status associated with at least a first portion of the respective forms of templatized representations, or a deny list of clearance indicators that indicate a blocked status associated with at least a second portion of the respective forms of templatized representa
during program execution, e.g. stack integrity {; Preventing unwanted data erasure; Buffer overflow} · CPC title
Authenticating web pages, e.g. with suspicious links · CPC title
by executing in a restricted environment, e.g. sandbox or secure virtual machine · CPC title
Test or assess software · CPC title
Protecting distributed programs or content, e.g. vending or licensing of copyrighted material (protection in video systems or pay television H04N7/16) {; Digital rights management [DRM]} · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.