WO2011019177A3 - 가상 환경을 이용한 데이터 보호 방법과 장치 - Google Patents

가상 환경을 이용한 데이터 보호 방법과 장치 Download PDF

Info

Publication number
WO2011019177A3
WO2011019177A3 PCT/KR2010/005215 KR2010005215W WO2011019177A3 WO 2011019177 A3 WO2011019177 A3 WO 2011019177A3 KR 2010005215 W KR2010005215 W KR 2010005215W WO 2011019177 A3 WO2011019177 A3 WO 2011019177A3
Authority
WO
WIPO (PCT)
Prior art keywords
virtual environment
data
prevented
protecting data
access
Prior art date
Application number
PCT/KR2010/005215
Other languages
English (en)
French (fr)
Other versions
WO2011019177A2 (ko
Inventor
강경완
김광태
박희안
Original Assignee
주식회사 안철수연구소
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 주식회사 안철수연구소 filed Critical 주식회사 안철수연구소
Priority to US13/389,883 priority Critical patent/US8782798B2/en
Publication of WO2011019177A2 publication Critical patent/WO2011019177A2/ko
Publication of WO2011019177A3 publication Critical patent/WO2011019177A3/ko

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1416Event detection, e.g. attack signature detection
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/52Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity ; Preventing unwanted data erasure; Buffer overflow
    • G06F21/53Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity ; Preventing unwanted data erasure; Buffer overflow by executing in a restricted environment, e.g. sandbox or secure virtual machine
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00Arrangements for program control, e.g. control units
    • G06F9/06Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
    • G06F9/44Arrangements for executing specific programs
    • G06F9/455Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines
    • G06F9/45533Hypervisors; Virtual machine monitors
    • G06F9/45558Hypervisor-specific management and integration aspects
    • G06F2009/45587Isolation or security of virtual machine instances

Abstract

본 발명은 가상 환경을 이용한 데이터 보호 방법과 장치에 관한 것으로, 컴퓨터에서 운용하는 응용 프로그램의 실행을 지원할 수 있는 안전한 가상 환경을 만들고 중요한 데이터는 가상 환경의 내부에서만 입력 또는 출력을 처리하여 가상 환경의 외부에서는, 즉 일반적 로컬 환경에서는 해당 데이터에 접근할 수 없도록 함으로써, 해당 데이터에 대한 외부 유출을 원천적으로 차단하여 보호할 수 있으며, 사용자는 컴퓨터를 일반적인 사용 방식과 마찬가지로 사용하면서 원하는 작업을 수행할 수 있는 편의성을 제공한다.
PCT/KR2010/005215 2009-08-11 2010-08-10 가상 환경을 이용한 데이터 보호 방법과 장치 WO2011019177A2 (ko)

Priority Applications (1)

Application Number Priority Date Filing Date Title
US13/389,883 US8782798B2 (en) 2009-08-11 2010-08-10 Method and apparatus for protecting data using a virtual environment

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
KR1020090073831A KR101047884B1 (ko) 2009-08-11 2009-08-11 가상 환경을 이용한 데이터 보호 방법과 장치 및 이 방법을 수행하는 프로그램이 기록된 컴퓨터로 읽을 수 있는 기록매체
KR10-2009-0073831 2009-08-11

Publications (2)

Publication Number Publication Date
WO2011019177A2 WO2011019177A2 (ko) 2011-02-17
WO2011019177A3 true WO2011019177A3 (ko) 2011-05-19

Family

ID=43586626

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/KR2010/005215 WO2011019177A2 (ko) 2009-08-11 2010-08-10 가상 환경을 이용한 데이터 보호 방법과 장치

Country Status (3)

Country Link
US (1) US8782798B2 (ko)
KR (1) KR101047884B1 (ko)
WO (1) WO2011019177A2 (ko)

Families Citing this family (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102314373B (zh) * 2011-07-07 2013-12-18 胡建斌 一种基于虚拟化技术实现安全工作环境的方法
KR101394369B1 (ko) * 2012-11-13 2014-05-13 주식회사 파수닷컴 가상 폴더를 이용한 보안 콘텐츠 관리 장치 및 방법
TW201427366A (zh) * 2012-12-28 2014-07-01 Ibm 企業網路中為了資料外洩保護而解密檔案的方法與資訊裝置
BR112015026372B8 (pt) 2013-04-18 2024-02-15 Facecon Co Ltd Dispositivo de comunicação que reforça a segurança para um arquivo armazenado em uma unidade virtual
KR101599740B1 (ko) * 2014-07-17 2016-03-04 한국전자통신연구원 전자문서 불법 유출 방지 방법 및 장치
CN107392062A (zh) * 2017-07-28 2017-11-24 宣以政 一种为普通移动存储设备增加数据泄漏防护功能的方法、系统和装置

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5555385A (en) * 1993-10-27 1996-09-10 International Business Machines Corporation Allocation of address spaces within virtual machine compute system
KR20010109271A (ko) * 1999-10-01 2001-12-08 추후제출 데이터보안 제공을 위한 시스템과 방법
US6725289B1 (en) * 2002-04-17 2004-04-20 Vmware, Inc. Transparent address remapping for high-speed I/O
KR20050085015A (ko) * 2002-11-18 2005-08-29 에이알엠 리미티드 보안 도메인과 비보안 도메인을 갖는 시스템 내에서 가상메모리 어드레스의 물리적 메모리 어드레스로의 매핑
US20070067435A1 (en) * 2003-10-08 2007-03-22 Landis John A Virtual data center that allocates and manages system resources across multiple nodes
KR20070049885A (ko) * 2005-11-09 2007-05-14 삼성전자주식회사 가상 메모리를 제어하는 장치 및 방법

Family Cites Families (14)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6553466B1 (en) 1999-10-01 2003-04-22 Infraworks Corporation Shared memory blocking method and system
US6922774B2 (en) * 2001-05-14 2005-07-26 The United States Of America As Represented By The National Security Agency Device for and method of secure computing using virtual machines
EP1349033B1 (en) * 2002-03-26 2004-03-31 Soteres GmbH A method of protecting the integrity of a computer program
US7117284B2 (en) 2002-11-18 2006-10-03 Arm Limited Vectored interrupt control within a system having a secure domain and a non-secure domain
EP1760619A1 (en) * 2005-08-19 2007-03-07 STMicroelectronics Ltd. System for restricting data access
US8046837B2 (en) * 2005-08-26 2011-10-25 Sony Corporation Information processing device, information recording medium, information processing method, and computer program
US7594072B2 (en) 2006-09-15 2009-09-22 Hitachi, Ltd. Method and apparatus incorporating virtualization for data storage and protection
US8458695B2 (en) * 2006-10-17 2013-06-04 Manageiq, Inc. Automatic optimization for virtual systems
JP2008187338A (ja) * 2007-01-29 2008-08-14 Hewlett-Packard Development Co Lp 制御システムおよびその方法。
US7840839B2 (en) * 2007-11-06 2010-11-23 Vmware, Inc. Storage handling for fault tolerance in virtual machines
US8799892B2 (en) * 2008-06-09 2014-08-05 International Business Machines Corporation Selective memory donation in virtual real memory environment
CN101414277B (zh) * 2008-11-06 2010-06-09 清华大学 一种基于虚拟机的按需增量恢复容灾系统及方法
US20100199351A1 (en) * 2009-01-02 2010-08-05 Andre Protas Method and system for securing virtual machines by restricting access in connection with a vulnerability audit
US8391494B1 (en) * 2009-02-26 2013-03-05 Symantec Corporation Systems and methods for protecting enterprise rights management keys

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5555385A (en) * 1993-10-27 1996-09-10 International Business Machines Corporation Allocation of address spaces within virtual machine compute system
KR20010109271A (ko) * 1999-10-01 2001-12-08 추후제출 데이터보안 제공을 위한 시스템과 방법
US6725289B1 (en) * 2002-04-17 2004-04-20 Vmware, Inc. Transparent address remapping for high-speed I/O
KR20050085015A (ko) * 2002-11-18 2005-08-29 에이알엠 리미티드 보안 도메인과 비보안 도메인을 갖는 시스템 내에서 가상메모리 어드레스의 물리적 메모리 어드레스로의 매핑
US20070067435A1 (en) * 2003-10-08 2007-03-22 Landis John A Virtual data center that allocates and manages system resources across multiple nodes
KR20070049885A (ko) * 2005-11-09 2007-05-14 삼성전자주식회사 가상 메모리를 제어하는 장치 및 방법

Also Published As

Publication number Publication date
WO2011019177A2 (ko) 2011-02-17
US20120144500A1 (en) 2012-06-07
KR101047884B1 (ko) 2011-07-08
US8782798B2 (en) 2014-07-15
KR20110016227A (ko) 2011-02-17

Similar Documents

Publication Publication Date Title
WO2011019177A3 (ko) 가상 환경을 이용한 데이터 보호 방법과 장치
WO2016094840A3 (en) System, method & computer readable medium for software protection via composable process-level virtual machines
EP2579817A4 (en) IMPLANT COMPONENTS AND METHODS
HUE037421T2 (hu) Eljárás megmunkáló egységek mûveleteinek ábrázolására és üzemadatok kinyerése a felhasználó által szolgáltatott adatokból
IL237627B (en) Data processing device and method for securing data and software code against unsecured access when switching from a secure domain to a less secure domain
GB2481563A (en) Method and apparatus to provide secure application execution
WO2012048162A8 (en) System and method for extending a visualization platform
EP4099137A3 (en) Systems and methods of secure domain isolation
WO2011140311A3 (en) Electronic device case and method of use
EP2219130A4 (en) METHOD AND APPARATUS FOR DETECTING THE MALICIOUS BEHAVIOR OF A COMPUTER PROGRAM
PL2269189T3 (pl) Urządzenie, sposób i program komputerowy do generowania reprezentacji sygnału o rozszerzonym paśmie w oparciu o reprezentację sygnału wejściowego z użyciem kombinacji harmonicznego rozszerzania pasma z nieharmonicznym rozszerzaniem pasma
WO2009108504A3 (en) Universal language input
EP2345977A4 (en) CLIENT COMPUTER FOR PROTECTING A CONFIDENTIAL FILE, ASSOCIATED SERVER COMPUTER, ASSOCIATED METHOD, AND COMPUTER PROGRAM
GB2497693A (en) Managing a user interface for an application program
TWI366778B (en) Hotkey processing method and computer system
WO2011031093A3 (ko) 가상화 기술을 이용한 디지털 저작권 관리 장치 및 방법
WO2013130561A3 (en) Method of operating a computing device, computing device and computer program
GB2458426A (en) Password protection system and method
GB2459033B (en) Method, device and computer program for reducing the resolution of an input image
EP2548114A4 (en) APPARATUS AND METHOD FOR ACCESSING A COMPUTER PRE-BOOST ROUTINE
BRPI1002810A2 (pt) dispositivos e método de reprodução, programa que faz um computador executar processamento, e, dispositivo e método de processamento de informação.
GB2478878B (en) System and method for booting a computer system using preboot data
EP2109824A4 (en) PERIPHERAL COMPUTER DEVICE IMPLEMENTED AS OPTICAL STORAGE DEVICE AND / OR SOFTWARE DEPOSITED DISK AND METHOD FOR IMPLEMENTING SAME
EP2208303A4 (en) METHOD AND SYSTEM FOR PROTECTING A COMPUTER FROM HARMFUL SOFTWARE
BR112014003000A2 (pt) método para fornecer um acesso de lançamento rápido; dispositivo eletrônico; aparelho eletrônico; e meio de armazenamento

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 10808326

Country of ref document: EP

Kind code of ref document: A2

WWE Wipo information: entry into national phase

Ref document number: 13389883

Country of ref document: US

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 22/05/2012)

122 Ep: pct application non-entry in european phase

Ref document number: 10808326

Country of ref document: EP

Kind code of ref document: A2