Inventors:
Roberto A. Franco - Seattle WA, US
Anantha P Ganjam - Sammamish WA, US
John G. Bedworth - Redmond WA, US
Peter T. Brundrett - Seattle WA, US
Roland K Tokumi - Issaquah WA, US
Jeremiah S. Epling - Kirkland WA, US
Daniel Sie - Bellevue WA, US
Jianrong Gu - Bellevue WA, US
Marc Silbey - Seattle WA, US
Vidya Nallathimmayyagari - Redmond WA, US
Bogdan Tepordei - Sammamish WA, US
Assignee:
Microsoft Corporation - Redmond WA
International Classification:
G06F 15/173
G06F 15/16
Abstract:
In various embodiments, applications that are configured to interact with the Internet in some way are executed in a restricted process with a reduced privilege level that can prohibit the application from accessing portions of an associated computing device. For example, in some embodiments, the restricted process can prohibit applications from read and write access to portions of a system's computer-readable media, such as the hard disk, that contains administrative data and settings information and user data and settings. In these embodiments, a special portion of the disk, termed a “containment zone”, is designated and used by applications in this restricted process.