IP Library Granted Patent US 8,060,937
Granted Patent B2
US 8,060,937 · App. 10/710,491 · Granted Nov 15, 2011

System for protecting domain system configurations from users with local privilege rights

Assignee: Lieberman Software Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,060,937
App. No.
10/710,491
Granted
Nov 15, 2011
Kind
B2
Abstract

A group change lockout system for protecting the configuration of a securable object in an operating system from members of a locally privileged group, such as the local administrators group, when a security descriptor exists for the securable object that includes a discretionary access control list (DACL). A copy of the security descriptor is made. Then a new access control entry (ACE) is added to the DACL in the copy. This new ACE specifies denying the local administrators group an access right to the securable object. Then the security descriptor in the operating system is overwritten with the copy.

Claims (45)

1. A method for protecting the configuration of a securable object in an operating system from members of a locally privileged group, wherein a security descriptor for the securable object includes a discretionary access control list (DACL), the method comprising:

making a copy of the security descriptor;

adding a new access control entry (ACE) to the DACL in said copy, wherein said new ACE specifies denying the locally privileged group an access right to the securable object; and

overwriting the security descriptor in the operating system with said copy.

2. The method of claim 1 , further comprising:

determining a relative identifier (RID) of the securable object; and

finding the security descriptor for the securable object based on said RID.

3. The method of claim 1 , further comprising examining the DACL to discover whether said access right is already denied.

4. The method of claim 1 , wherein said new ACE is added as a first ACE in the DACL.

5. The method of claim 1 , wherein the securable object is a group other than a local administrators group.

6. The method of claim 5 , wherein said group is a domain administrator group.

7. The method of claim 6 , wherein said domain administrator group is a remotely hosted group, and the method further comprising adding said new ACEs to the DACL in said copy to deny all local groups said access right to the securable object.

8. The method of claim 5 , wherein said access right includes a right to change permissions of said group.

9. The method of claim 7 , wherein said access right also includes a right to view permissions of said group.

10. The method of claim 1 , wherein a single software tool performs the method.

11. A non-transitory computer program, embodied on a computer readable storage medium, for protecting the configuration of a securable object in an operating system from members of a locally privileged group, wherein a security descriptor for the securable object includes a discretionary access control list (DACL), the computer program comprising:

a code segment makes a copy of the security descriptor;

a code segment that adds a new access control entry (ACE) to the DACL in said copy, wherein said new ACE specifies denying the locally privileged group an access right to the securable object; and

a code segment that overwrites the security descriptor in the operating system with said copy.

12. The computer program of claim 11 , further comprising:

a code segment that determines a relative identifier (RID) of the securable object; and

a code segment that finds the security descriptor for the securable object based on said RID.

13. The computer program of claim 11 , further comprising a code segment that examines the DACL to discover whether said access right is already denied.

14. The computer program of claim 11 , further comprising a code segment that provides that said new ACE is added as a first ACE in the DACL.

15. The computer program of claim 11 , wherein the securable object is a group other than a local administrators group.

16. The computer program of claim 15 , wherein said group is a domain administrator group.

17. The computer program of claim 16 , wherein said domain administrator group is a remotely hosted group, and said code segment that adds further adds said new ACEs to the DACL in said copy to deny all local groups said access right to the securable object.

18. The computer program of claim 15 , wherein said access right includes a right to change permissions of said group.

19. The computer program of claim 18 , wherein said access right also includes a right to view permissions of said group.

20. The computer program of claim 11 , wherein all said code segments are part of a single software tool.

21. A system for protecting the configuration of a securable object in an operating system of a computer from members of a locally privileged group, wherein a security descriptor for the securable object includes a discretionary access control list (DACL), the system comprising:

means for making a copy of the security descriptor;

means for adding a new access control entry (ACE) to the DACL in said copy, wherein said new ACE specifies denying the locally privileged group an access right to the securable object; and

means for overwriting the security descriptor in the operating system of the computer with said copy.

22. The system of claim 21 , further comprising:

means for determining a relative identifier (RID) of the securable object; and

means for finding the security descriptor for the securable object based on said RID.

23. The system of claim 21 , further comprising means for examining the DACL to discover whether said access right is already denied.

24. The system of claim 21 , further comprising means for providing that said new ACE is added as a first ACE in the DACL.

25. The system of claim 21 , wherein the securable object is a group other than a local administrators group.

26. The system of claim 25 , wherein said group is a domain administrator group.

27. The system of claim 26 , wherein said domain administrator group is a remotely hosted group, and said means that adds further adds said new ACEs to the DACL in said copy to deny all local groups said access right to the securable object.

28. The system of claim 25 , wherein said access right includes a right to change permissions of said group.

29. The system of claim 28 , wherein said access right also includes a right to view permissions of said group.

30. The system of claim 21 , wherein said means are comprised within a single software tool.

Assignments (15)
MERGER Recorded Dec 5, 2023
From: BEYONDTRUST SOFTWARE, INC.
To: BEYONDTRUST CORPORATION
Reel/Frame 065764/0741 →
RELEASE OF SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 28, 2023
From: JEFFERIES FINANCE LLC
To: BEYONDTRUST CORPORATION (FORMERLY KNOWN AS BOMGAR CORPORATION)
Reel/Frame 065697/0361 →
RELEASE OF FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 28, 2023
From: JEFFERIES FINANCE LLC
To: BEYONDTRUST CORPORATION (FORMERLY KNOWN AS BOMGAR CORPORATION)
Reel/Frame 065696/0991 →
SECURITY INTEREST Recorded Nov 28, 2023
From: BEYONDTRUST CORPORATION
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 065682/0447 →
RELEASE OF FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 28, 2023
From: JEFFERIES FINANCE LLC
To: BEYONDTRUST SOFTWARE, INC.
Reel/Frame 065696/0901 →
RELEASE OF SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 28, 2023
From: JEFFERIES FINANCE LLC,
To: BEYONDTRUST SOFTWARE, INC.
Reel/Frame 065697/0345 →
CHANGE OF NAME Recorded Mar 15, 2019
From: BOMGAR CORPORATION
To: BEYONDTRUST CORPORATION
Reel/Frame 048614/0633 →
SECURITY INTEREST - SECOND LIEN PATENT SECURITY AGREEMENT Recorded Feb 12, 2019
From: BEYONDTRUST SOFTWARE, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 048304/0426 →
SECURITY INTEREST Recorded Feb 11, 2019
From: BEYONDTRUST SOFTWARE, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 048296/0322 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2019
From: BEYONDTRUST CORPORATION
To: BEYONDTRUST SOFTWARE, INC.
Reel/Frame 048215/0512 →
MERGER Recorded Jan 31, 2019
From: LIEBERMAN SOFTWARE CORPORATION
To: BEYONDTRUST CORPORATION
Reel/Frame 048208/0372 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Apr 20, 2018
From: BOMGAR CORPORATION
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 045786/0068 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Apr 19, 2018
From: BOMGAR CORPORATION
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 045985/0413 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 14, 2018
From: LIEBERMAN SOFTWARE CORPORATION
To: BOMGAR CORPORATION
Reel/Frame 044923/0205 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 27, 2007
From: CARROLL, NICHOLAS M.
To: LIEBERMAN SOFTWARE CORPORATION
Reel/Frame 019619/0081 →
Continuity (1)
Related Publication 20060015741A1 · Jan 19, 2006