Proceedings DARPA Information Survivability Conference and Exposition II. DISCEX'01
DOI: 10.1109/discex.2001.932170
|View full text |Cite
|
Sign up to set email alerts
|

Preventing the execution of unauthorized Win32 applications

Abstract: This paper describes an approach and tool for providing administrative control over the execution of sofhyare on a Windows NTD000 system. The kerneldriver-based approach provides the system administrator with a way of restricting users to running only approved applications. As a result, illegal, pirated, personal, and malicious software executables can be prevented from running on corporate machines. We describe the key issues involved in the development of this tool and the features that make this tool an imp… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2

Citation Types

0
2
0

Publication Types

Select...
3
2
1

Relationship

0
6

Authors

Journals

citations
Cited by 9 publications
(2 citation statements)
references
References 5 publications
(2 reference statements)
0
2
0
Order By: Relevance
“…Through the use of a kernel driver, all new process creation is controlled. (Schmid et al, 2001) Microsoft added a technology called group policy to its Active Directory environments. An administrator can control which executables are able to run on a computer through a software restriction policy.…”
Section: Related Workmentioning
confidence: 99%
“…Through the use of a kernel driver, all new process creation is controlled. (Schmid et al, 2001) Microsoft added a technology called group policy to its Active Directory environments. An administrator can control which executables are able to run on a computer through a software restriction policy.…”
Section: Related Workmentioning
confidence: 99%
“…The closest work on binary authentication in Windows is the Emu system in by Schmid et al [13]. They intercept process creation by intercepting the NtCreateProcess system call.…”
Section: Related Workmentioning
confidence: 99%