Invention Grant
- Patent Title: Filtering kernel-mode network communications
- Patent Title (中): 过滤内核模式网络通信
-
Application No.: US14480640Application Date: 2014-09-09
-
Publication No.: US09590993B2Publication Date: 2017-03-07
- Inventor: David Abzarian , Salahuddin Khan , Eran Yariv , Gerardo Diaz Cuellar
- Applicant: Microsoft Corporation
- Applicant Address: US WA Redmond
- Assignee: Microsoft Technology Licensing, LLC
- Current Assignee: Microsoft Technology Licensing, LLC
- Current Assignee Address: US WA Redmond
- Agent John Jardine; Judy Yee; Micky Minhas
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/74

Abstract:
Some embodiments of the invention are directed to techniques for determining whether a process on a computer system that is sending or receiving data, or is attempting to send or receive data, with another computer system is executing in kernel mode or user mode and providing an indicator of this determination to a security engine. In some embodiments, such an indication is provided to a security engine (e.g., a firewall) that implements a security policy based at least in part on whether the sending or receiving process is in kernel mode or user mode, and filter communications based on a process' operating mode. This enables a security engine to maintain security policies of greater specificity and thus improve security of a computer system.
Public/Granted literature
- US20150058628A1 FILTERING KERNEL-MODE NETWORK COMMUNICATIONS Public/Granted day:2015-02-26
Information query