The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Mar. 16, 2021

Filed:

Dec. 13, 2018
Applicants:

Beijing Jingdong Shangke Information Technology Co., Ltd., Beijing, CN;

Jd.com American Technologies Corporation, Mountain View, CA (US);

Inventors:

Junyuan Zeng, Mountain View, CA (US);

Zhenxin Zhan, Mountain View, CA (US);

Yuan Chen, Mountain View, CA (US);

Jimmy Su, Mountain View, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/53 (2013.01); G06F 21/56 (2013.01); G06F 21/64 (2013.01); H04L 12/24 (2006.01); G06F 9/455 (2018.01); G06F 9/54 (2006.01);
U.S. Cl.
CPC ...
G06F 21/53 (2013.01); G06F 9/45558 (2013.01); G06F 9/54 (2013.01); G06F 21/565 (2013.01); G06F 21/64 (2013.01); H04L 41/0893 (2013.01); G06F 2009/45562 (2013.01); G06F 2009/45587 (2013.01); G06F 2009/45591 (2013.01); G06F 2209/542 (2013.01);
Abstract

A system for monitoring file integrity in a host computing device having a process and a storage device storing computer executable code. The computer executable code is configured to: provide containers, an agent external to the containers, and a policy file configuring policy for the containers; intercept a system call indicating mounting, and construct a first correspondence between a container file path and a host file path having mounting correspondence; intercept a system call of the container indicating opening of the policy file, and construct a second correspondence between the container file path and the violation of the container file path; aggregate the first and second correspondences to obtain a correspondence between the host file path and the violation; and monitor file integrity of the container by detecting violation of the host file path.


Find Patent Forward Citations

Loading…