Isolated Software Package
US20260086839A1
Abstract
A computer-implemented operation method is provided for isolating a software application from operating system software, including: installing a configuration file; installing a plurality of detectors; and installing and executing a monitoring software program. The configuration file enables interaction with the application. The detectors analyze input to the application. The input either belongs to an authorization list or else is absent therefrom. Executing the monitoring software program loads the detectors, receives application information from the configuration file, and activates an alert in response to the input being absent from said authorization list.
Description (excerpt)
STATEMENT OF GOVERNMENT INTEREST The invention described was made in the performance of official duties by one or more employees of the Department of the Navy, and thus, the invention herein may be manufactured, used or licensed by or for the Government of the United States of America for governmental purposes without the payment of any royalties thereon or therefor. BACKGROUND The invention relates generally to software. In particular, software protection from interference during execution within a host operating system. SUMMARY Conventional software protection yield disadvantages addressed by various exemplary embodiments of the present invention. In particular, various exemplary embodiments provide a technique for isolating a software application from operating system software, including: installing a configuration file; installing a plurality of detectors; and installing and executing a monitoring software program. The configuration file prescribes the expected interactions with the application. The detectors analyze input to the application. The input either belongs to an authorization list or is absent therefrom. Executing the monitoring software program loads the detectors, receives application information from the configuration file, and initiates an action in response to the input being absent from said authorization list. Such action can for example, be an alert. BRIEF DESCRIPTION OF THE DRAWINGS These and various other features and aspects of various exemplary embodiments will be readily understood with reference to the following detailed description taken in conjunction with the accompanying drawings, in which like or similar numbers are used throughout, and in which: FIG. 1 is a block diagram view of a host platform with protection software for an application; FIGS. 2 A and 2 B are block diagram views of the host and/or application including intrusion detection; FIG. 3 is a block diagram view of the protection software; FIGS. 4 A and 4 B are code instruction views of detectors and actions; FIG. 5 is a block diagram view of the protection software with the host in operation; FIG. 6 is a code instruction view of a java command; FIG. 7 is a code instruction view of a test mount; FIG. 8 is a logic flow diagram view of a mount process; FIG. 9 is a code instruction view of variable labeling; FIG. 10 is a logic flow diagram view of an environment process; FIG. 11 is a code instruction view of an expected process; FIG. 12 is a logic flow diagram view of user and process identification; FIG. 13 is a code instruction view of for an expected port access; FIG. 14 is a logic flow diagram view of communication sockets; FIG. 15 is a block diagram view of a host and a virtual machine with main and logging containers; FIG. 16<
Filing details
- Inventors
- Matthew R. Semich
- Assignee
- United States Of America, As Represented By The Secretary Of The Navy
- Filed
- Sep 26, 2024
- Granted
- Application pending
Bibliographic data and excerpted text sourced from Google Patents (public record) as part of IP TechMatch's current-filings monitor. This filing is not part of the 2019 historical archive. For the authoritative full text, drawings, and legal status, see the source links above or consult USPTO records directly.