Process blacklist and whitelist control method based on Windows system
A control method, black and white list technology, applied in the fields of instruments, digital data processing, platform integrity maintenance, etc., can solve problems such as inability to identify correctly, reduce the probability of viruses or illegal intrusions, ensure effectiveness, and ensure security. Effect
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment Construction
[0034] The present invention adopts PsSetCreateProcessNotifyRoutine registration process notification callback, hooks NtCreateSection, NtClose, NtCreateProcess functions, and is used for intercepting and monitoring process creation process. The purpose of intercepting the NtCreateSection and NtClose functions is to ensure the correctness of the obtained process path. At the same time, it is also necessary to intercept the functions NtCreateProcess and NtCreateProcessEx executed when creating a process, to judge whether the created process is allowed to run, and to intercept illegal process creation. When the system calls the "process notification callback function", it will judge the process being created again to ensure that the user name corresponding to the process can be accurately obtained, and realize whether the process is allowed to run according to the user. In summary, in order to achieve effective process control, it is necessary to hook the NtCreateSection, NtClose...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com