IP Library Granted Patent US 9,558,343
Granted Patent B2
US 9,558,343 · App. 14/502,845 · Granted Jan 31, 2017

Methods and systems for controlling access to resources and privileges per process

Inventors: Peter David Beauregard (Dover, NH); Andrey Kolishchak (Luxembourg, LU); Shannon E. Jennings (Exeter, NH); Robert F. Hogan (Portsmouth, NH)
Assignee: BeyondTrust Software, Inc.
G06F21/44G06F9/468G06F21/31G06F21/604G06F21/6209
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,558,343
App. No.
14/502,845
Granted
Jan 31, 2017
Kind
B2
Abstract

To control privileges and access to resources on a per-process basis, an administrator creates a rule that may be applied to modify a token of a process. The rule may include an application-criterion set and changes to be made to the groups and/or privileges of the token. The rule may be set as a policy within a group policy object (GPO), where a GPO is associated with one or more groups of computers or users. When a GPO containing a rule is applied to a computer, a driver installed on the computer may access the rule(s) anytime a logged-on user executes a process. If the executed process satisfies the criterion set of a rule, the changes contained within the rule are made to the process token, and the user has expanded and/or contracted access and/or privileges for only that process.

Claims (47)

1. A method comprising:

detecting execution of a command to execute a child process;

determining, before execution of the child process, if one or more rules apply to the child process based on one or more criteria, the one or more criteria facilitating blocking or allowing inheritance by the child process of a parent process token of a parent process;

modifying, in accordance with the one or more applicable rules, a child process token of the child process to change a security parameter with which to execute the child process, the security parameter comprising a permission, a privilege, and an integrity level with which to execute the child process;

wherein the modification of the child process token for the security parameter is performed by a user via a privilege manager;

wherein the user sets the integrity level;

verifying an identity of the user setting the integrity level;

requesting a justification from the user setting the integrity level;

accessing the modified child process token of the child process to determine the security parameter; and

executing the child process, the child process being executed using the modified child process token; and

allowing access to an object based, at least in part, on the execution of the child process.

2. The method of claim 1 , wherein determining, before the execution of the child process, if the one or more rules apply to the child process based on the one or more criteria comprises determining if at least one of a hash rule, a path rule, a folder rule, an MSI Path rule, an MSI folder rule, an ActiveX rule, a certificate rule, a shell rule, and a CD/DVD rule is satisfied based on all or part of the detected command.

3. The method of claim 1 , wherein allowing access to the object based, at least in part, on the execution of the child process, comprises authenticating a user and allowing the user access to the object based on the authentication and the modified child process token.

4. The method of claim 1 , wherein the one or more applicable rules require that the child process token is modified if one or more of the child process and the parent process is associated with an Administrators Group.

5. The method of claim 1 , wherein if the one or more rules apply to the child process based on the one or more criteria, the method further comprises applying at least one of the one or more applicable rules to multiple programs in a specified folder.

6. The method of claim 1 ,

wherein the one or more criteria comprises the user matching a user identifier; and

wherein the user identifier is selected from the group of user identifiers consisting of: a password and a biometric scan.

7. The method of claim 6 , wherein determining, before execution of the child process, if one or more rules apply to the child process based on the one or more criteria comprises determining if a user associated with execution of the command to execute the child process is identified by the one or more criteria.

8. The method of claim 7 , wherein the child process token, before modification, indicates that the user does not have permission to execute the application.

9. The method of claim 8 , wherein the child process token, after modification, indicates that the user has permission to execute the application.

10. The method of claim 1 , wherein determining, before execution of the child process, if one or more rules apply to the child process based on the one or more criteria comprises determining if a particular command line argument is a part of the command and modifying the child process token based on the determination.

11. The method of claim 1 , wherein the setting of the integrity level for the security parameter does not modify the integrity level of one or more other processes.

12. The method of claim 1 , wherein determining, before the execution of the child process, if the one or more rules apply to the child process based on the one or more criteria comprises hooking the child process using a driver.

13. A non-transitory computer readable medium comprising executable instructions, the instructions being executable by a processor to perform a method, the method comprising:

detecting execution of a command to execute a child process;

determining, before execution of the child process, if one or more rules apply to the child process based on one or more criteria, the one or more criteria facilitating blocking or allowing inheritance by the child process of a parent process token of a parent process;

modifying, in accordance with the one or more applicable rules, a child process token of the child process to change a security parameter with which to execute the child process, the security parameter comprising a permission, a privilege, and an integrity level with which to execute the child process;

wherein the modification of the child process token for the security parameter is performed by a user via a privilege manager;

wherein the user sets the integrity level;

verifying an identity of the user setting the integrity level;

requesting a justification from the user setting the integrity level;

accessing the modified child process token of the child process to determine the security parameter with which to execute the child process;

executing the child process, the child process being executed using the modified child process token; and

allowing access to an object based, at least in part, on the execution of the child process.

14. The non-transitory computer readable medium of claim 13 , wherein determining, before the execution of the child process, if the one or more rules apply to the child process based on the one or more criteria comprises determining if at least one of a hash rule, a path rule, a folder rule, an MSI Path rule, an MSI folder rule, an ActiveX rule, a certificate rule, a shell rule, and a CD/DVD rule is satisfied based on all or part of the detected command.

15. The non-transitory computer readable medium of claim 13 , wherein allowing access to the object based, at least in part, on the execution of the child process, comprises authenticating a user and allowing the user access to the object based on the authentication and the modified child process token.

16. The non-transitory computer readable medium of claim 13 , wherein the one or more applicable rules require that the child process token is modified if one or more of the child process and the parent process is associated with an Administrators Group.

17. The non-transitory computer readable medium of claim 13 , wherein if the one or more rules apply to the child process based on the one or more criteria, the method further comprises applying at least one of the one or more applicable rules to multiple programs in a specified folder.

18. The non-transitory computer readable medium of claim 13 , wherein the one or more criteria comprises the user matching a user identifier; and

wherein the user identifier is selected from the group of user identifiers consisting of: a password and a biometric scan.

19. The non-transitory computer readable medium of claim 18 , wherein determining, before execution of the child process, if one or more rules apply to the child process based on the one or more criteria comprises determining if a user associated with execution of the command to execute the child process is identified by the one or more criteria.

20. The non-transitory computer readable medium of claim 19 , wherein the child process token, before modification, indicates that the user does not have permission to execute the application.

21. The non-transitory computer readable medium if claim 20 , wherein the child process token, after modification, indicates that the user has permission to execute the application.

22. The non-transitory computer readable medium of claim 13 , wherein determining, before execution of the child process, if one or more rules apply to the child process based on the one or more criteria comprises determining if a particular command line argument is a part of the command and modifying the child process token based on the determination.

23. The non-transitory computer readable medium of claim 13 , wherein setting of the integrity level for the security parameter does not modify the integrity level of one or more other processes.

24. The non-transitory computer readable medium of claim 13 , wherein determining, before the execution of the child process, if the one or more rules apply to the child process based on the one or more criteria comprises hooking the child process using a driver.

Assignments (7)
RELEASE OF FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 28, 2023
From: JEFFERIES FINANCE LLC
To: BEYONDTRUST SOFTWARE, INC.
Reel/Frame 065696/0798 →
RELEASE OF SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 28, 2023
From: JEFFERIES FINANCE LLC,
To: BEYONDTRUST SOFTWARE, INC.
Reel/Frame 065697/0345 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 4, 2018
From: BEYONDTRUST SOFTWARE, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 047195/0252 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 3, 2018
From: BEYONDTRUST SOFTWARE, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 047190/0238 →
RELEASE OF SECURITY INTEREST UNDER REEL/FRAME NO. 044496/0009 Recorded Oct 3, 2018
From: ARES CAPITAL CORPORATION
To: BEYONDTRUST SOFTWARE, INC.
Reel/Frame 047189/0516 →
PATENT SECURITY AGREEMENT Recorded Nov 21, 2017
From: BEYONDTRUST SOFTWARE, INC.
To: ARES CAPITAL CORPORATION
Reel/Frame 044496/0009 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 24, 2014
From: BEAUREGARD, PETER DAVID; KOLISHCHAK, ANDREY; JENNINGS, SHANNON E.; HOGAN, ROBERT F.
To: BEYONDTRUST SOFTWARE, INC.
Reel/Frame 034034/0393 →
Continuity (3)
Continuation 12772914 · May 3, 2010
Provisional Application 61174513 · May 1, 2009
Related Publication 20150074828A1 · Mar 12, 2015