IP Library Granted Patent US 9,197,660
Granted Patent B2
US 9,197,660 · App. 13/977,014 · Granted Nov 24, 2015

Generic privilege escalation prevention

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,197,660
App. No.
13/977,014
Granted
Nov 24, 2015
Kind
B2
Abstract

An apparatus, method, computer readable storage medium are provided in one or more examples and comprise accessing an application, identifying an access token of the application, determining if the access token is a system token, and responsive to the access token failing to be a system token, enabling a runtime module.

Claims (54)

1. An apparatus for managing an application, comprising:

a memory element coupled to a processing element; and

a protection module, wherein the protection module is configured to:

identify an access token of the application;

determine if the access token is a system token;

responsive to the access token failing to be a system token, enable a runtime module coupled to the processing element;

determine whether the runtime module is enabled, wherein the runtime module is to determine whether the application has the system token;

responsive to determining the application has the system token, terminate the application; and

responsive to determining the application fails to have the system token, allow the application to execute.

2. The apparatus of claim 1 , wherein the protection module is further configured to:

determine whether the application is a protected application and responsive to the application being a protected application, access the application.

3. The apparatus of claim 1 , wherein the protection module is further configured to:

responsive to the access token being a system token, disable the runtime module.

4. The apparatus of claim 1 , wherein the protection module is further configured to:

monitor a plurality of API locations with a plurality of hooks;

identify an execution of a hook of the plurality of hooks, wherein determining whether the runtime module is enabled is responsive to the execution of the hook.

5. The apparatus of claim 4 , wherein the protection module is further configured to:

responsive to the runtime module being disabled, allow the application to execute.

6. The apparatus of claim 1 , further comprising:

the processing element coupled to the protection module.

7. At least one non-transitory computer readable storage medium that includes code for execution for managing an application, and when executed by a processing element is operable to:

identify an access token of the application;

determine if the access token is a system token;

responsive to the access token failing to be a system token, enable a runtime module;

determine whether the runtime module is enabled, wherein the runtime module is to determine whether the application has the system token;

responsive to determining the application has the system token, terminate the application; and

responsive to determining the application fails to have the system token, allow the application to execute.

8. The at least one non-transitory computer readable storage medium of claim 7 , wherein the code includes further code for execution and when executed by the processing element is operable to:

determine whether the application is a protected application; and

responsive to the application being a protected application, access the application.

9. The at least one non-transitory computer readable storage medium of claim 7 , wherein the code includes further code for execution and when executed by the processing element is operable to:

responsive to the access token being a system token, disable the runtime module.

10. The at least one non-transitory computer readable storage medium of claim 7 , wherein the code further includes code for execution and when executed by the processing element is operable to:

monitor a number of API locations for a plurality of hooks;

identify an execution of a hook of the plurality of hooks, wherein determining whether the runtime module is enabled is responsive to the execution of the hook.

11. The at least one non-transitory computer readable storage medium of claim 10 , wherein the code further includes code for execution and when executed by the processing element is operable to:

responsive to the runtime module being disabled, allow the application to execute.

12. A method for managing an application, comprising:

identifying an access token of the application;

determining if the access token is a system token; and

responsive to the access token failing to be a system token, enabling a runtime module coupled to a processing element;

determining whether the runtime module is enabled, wherein the runtime module is to determine whether the application has the system token;

responsive to determining the application has the system token, terminating the application; and

responsive to determining the application fails to have the system token, allowing the application to execute.

13. The method of claim 12 , further comprising:

determining whether the application is a protected application; and

responsive to the application being a protected application, accessing the application.

14. The method of claim 12 , further comprising:

responsive to the access token being a system token, disabling the runtime module.

15. The method of claim 12 , further comprising:

monitoring a number of API locations for a plurality of hooks;

identifying an execution of a hook of the plurality of hooks, wherein determining whether the runtime module is enabled is responsive to the execution of the hook.

16. The method of claim 15 , further comprising:

responsive to the runtime module being disabled, allowing the application to execute.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2015
From: SUN, BING; XU, CHONG; HETZLER, JEFF; BU, ZHENG
To: MCAFEE, INC.
Reel/Frame 036157/0001 →