IP Library Granted Patent US 12,149,623
Granted Patent B2
US 12,149,623 · App. 17/836,714 · Granted Nov 19, 2024

Security privilege escalation exploit detection and mitigation

Inventors: Andrew Sandoval (San Antonio, TX); Eric Klonowski (Broomfield, CO)
Assignee: OPEN TEXT INC.
H04L9/3213G06F9/44521G06F21/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,149,623
App. No.
17/836,714
Granted
Nov 19, 2024
Kind
B2
Abstract

Examples of the present disclosure describe systems and methods for monitoring the security privileges of a process. In aspects, when a process is created, the corresponding process security token and privilege information is detected and recorded. At subsequent “checkpoints,” the security token is evaluated to determine whether the security token has been replaced, or whether new or unexpected privileges have been granted to the created process. When a modification to the security token is determined, a warning or indication of the modification is generated and the process may be terminated to prevent the use of the modified security token.

Claims (42)

1. A system comprising:

a processor; and

a memory coupled to the processor, the memory comprising computer executable instructions that, when executed by the processor, performs a method comprising:

receiving a notification associated with an execution of a process on a device;

identifying privilege information associated with the process, including identifying a first security token for the process;

periodically evaluating an attribute of the privilege information, including periodically comparing a current security token associated with the process with the first security token;

determining that the attribute of the privilege information has been modified from a previous state of the attribute; and

upon determining that the attribute of the privilege information has been modified from the previous state of the attribute, performing a corrective action relating to the execution of the process on the device.

2. The system of claim 1 , wherein the computer executable instructions are further executable to register to receive the notification from an operating system of the device.

3. The system of claim 1 , wherein the notification is indicative of at least one of: a process creation, a creation of a thread, a DLL loading event, or a system registry activity.

4. The system of claim 1 , wherein determining that the attribute of the privilege information has been modified from the previous state of the attribute comprises determining that a security token attribute of the current security token is modified compared to the first security token.

5. The system of claim 1 , wherein determining that the attribute of the privilege information has been modified from the previous state of the attribute comprises at least one of: determining that an address of the current security token has been modified from the first security token, determining that an integrity level of the current security token has been modified from the first security token, determining that a privilege level granted by the current security token has been modified from the first security token.

6. The system of claim 1 , wherein determining that the attribute of the privilege information has been modified from the previous state comprises identifying a privilege escalation exploit.

7. The system of claim 1 , wherein the corrective action comprises at least one of: displaying warnings indicating a current state of the privilege information has been modified, deleting the privilege information, replacing the privilege information with a previous version of the privilege information, or terminating the process.

8. A method comprising:

receiving a notification associated with an execution of a process on a device;

identifying privilege information associated with the process, including identifying a first security token for the process;

periodically evaluating an attribute of the privilege information, including periodically comparing a current security token associated with the process with the first security token;

determining that the attribute of the privilege information has been modified from a previous state of the attribute; and

upon determining that the attribute of the privilege information has been modified from the previous state of the attribute, performing a corrective action relating to the execution of the process on the device.

9. The method of claim 8 , wherein the notification is indicative of at least one of: a process creation, a creation of a thread, a DLL loading event, or a system registry activity.

10. The method of claim 8 , wherein determining that the attribute of the privilege information has been modified from the previous state of the attribute comprises determining that a security token attribute of the current security token has been modified compared to the first security token.

11. The method of claim 8 , wherein determining that the attribute of the privilege information has been modified from the previous state of the attribute comprises at least one of: determining that an address of the current security token has been modified from the first security token, determining that an integrity level of the current security token has been modified from the first security token, determining that a privilege level granted by the current security token has been modified from the first security token.

12. The method of claim 8 , wherein determining that the attribute of the privilege information has been modified from the previous state comprises identifying a privilege escalation exploit.

13. The method of claim 8 , wherein the corrective action comprises at least one of: displaying warnings indicating a current state of the privilege information has been modified, deleting the privilege information, replacing the privilege information with a previous version of the privilege information, or terminating the process.

14. A non-transitory, computer-readable media encoding computer executable instructions which, when executed by a processor, performs a method comprising:

receiving a notification associated with an execution of a process on a device;

identifying privilege information associated with the process, including identifying a first security token for the process;

periodically evaluating an attribute of the privilege information, including periodically comparing a current security token associated with the process with the first security token;

determining that the attribute of the privilege information has been modified from a previous state of the attribute; and

upon determining that the attribute of the privilege information has been modified from the previous state of the attribute, performing a corrective action relating to the execution of the process on the device.

15. The non-transitory, computer-readable media of claim 14 , wherein the method further comprises registering to receive the notification from an operating system of the device.

16. The non-transitory, computer-readable media of claim 14 , wherein the notification is indicative of at least one of: a process creation, a creation of a thread, a DLL loading event, or a system registry activity.

17. The non-transitory, computer-readable media of claim 14 , wherein an evaluation of the attribute of the privilege information is performed at a time corresponding to at least one of: a process creation, a creation of a thread, a DLL loading event, or a system registry activity.

18. The non-transitory, computer-readable media of claim 14 , wherein determining that the attribute of the privilege information has been modified from the previous state of the attribute comprises determining that a security token attribute of the current security token has been modified compared to the first security token.

19. The non-transitory, computer-readable media of claim 14 , wherein determining that the attribute of the privilege information has been modified from the previous state of the attribute comprises at least one of: determining that an address of the current security token has been modified from the first security token, determining that an integrity level of the current security token has been modified from the first security token, determining that a privilege level granted by the current security token has been modified from the first security token.

20. The non-transitory, computer-readable media of claim 14 , wherein determining that the attribute of the privilege information has been modified from the previous state comprises identifying a privilege escalation exploit.

21. The non-transitory, computer-readable media of claim 14 , wherein the corrective action comprises at least one of: displaying warnings indicating a current state of the privilege information has been modified, deleting the privilege information, replacing the privilege information with a previous version of the privilege information, or terminating the process.

22. The system of claim 1 , wherein the processor and the memory are local to the device.

23. The system of claim 1 , wherein the processor and the memory are remote from the device.

24. The method of claim 8 , wherein an evaluation of the attribute of the privilege information is performed at a time corresponding to at least one of: a process creation, a creation of a thread, a DLL loading event, or a system registry activity.

25. The method of claim 8 , further comprising registering to receive the notification from an operating system of the device.

Assignments (4)
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Jul 6, 2023
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 064351/0178 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: WEBROOT LLC
To: CARBONITE, LLC
Reel/Frame 064167/0129 →
CERTIFICATE OF CONVERSION Recorded Jun 29, 2023
From: WEBROOT INC.
To: WEBROOT LLC
Reel/Frame 064176/0622 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2022
From: SANDOVAL, ANDREW; KLONOWSKI, ERIC
To: WEBROOT INC.
Reel/Frame 060229/0191 →
Continuity (3)
Continuation 16903535 · Jun 17, 2020
Continuation 15903303 · Feb 23, 2018
Related Publication 20220303136A1 · Sep 22, 2022
Cited By (1)
US 12,316,674