IP Library Granted Patent US 12,463,988
Granted Patent B2
US 12,463,988 · App. 18/172,729 · Granted Nov 4, 2025

Arrangement and method of privilege escalation detection in a computer or computer network

Inventor: Jarno Niemelä (Helsinki, FI)
Assignee: WITHSECURE CORPORATION
H04L63/1416H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,463,988
App. No.
18/172,729
Granted
Nov 4, 2025
Kind
B2
Abstract

An arrangement and a method of privilege escalation detection in a computer or computer network. The method comprises examining which executables are running in a target host; searching from a behavioral data source behavioral information of the executables running in the target host; including in a first list identification information of executables running in the target host which the behavioral information indicates are known to run with a first or a higher level privilege; including in a second list identification information of sensitive resources loaded or executed by the executables included in the first list; examining the sensitive resources included in the second list to determine whether that resource is writable by an executable running at a privilege level lower than the first level; and providing an indication of every resource that is loaded by the first or higher level privilege executable but is writable by the executable running at a privilege level lower than the first level as a potential vulnerability.

Claims (44)

1 . A method of privilege escalation detection in a computer or computer network, the method comprising:

examining which executables are running in a target host;

searching from a behavioral data source behavioral information of the executables running in the target host;

including, in a first list, identification information of executables running in the target host which the behavioral information indicates are run with a first- or a higher-level privilege;

including, in a second list, identification information of sensitive resources loaded or executed by the executables included in the first list;

examining the sensitive resources included in the second list to determine whether that resource is writable by an executable running at a privilege level lower than the first level by examining resources existing in the target host, and comparing the examined resources with the sensitive resources in the second list to determine which ones of the resources existing in the target host may be vulnerable; and

providing an indication of every resource that is loaded by the first- or higher-level privilege executable but is writable by the executable running at a privilege level lower than the first level as a potential vulnerability.

2 . The method according to claim 1 , wherein the sensitive resources include at least file paths and/or registry keys.

3 . The method according to claim 1 , further comprising:

including, in the first list, identification information of every executable file run by a high privileged executable, every dynamic link library loaded by a privileged executable, and every registry key value read and executed by a privileged executable.

4 . The method according to claim 2 , further comprising:

including, in the first list, identification information of every executable file run by a high privileged executable, every dynamic link library loaded by a privileged executable, and every registry key value read and executed by a privileged executable.

5 . The method according to claim 1 , wherein the method is performed by the target host.

6 . The method according to claim 5 , wherein the method is performed by a virtual machine or software emulator running on the target host.

7 . The method according to claim 1 , wherein the method is performed by a virtual machine or software emulator running on a server.

8 . The method according to claim 1 , wherein the behavioral data source comprises one or more of the following:

information collected by a backend from one or more target hosts on processes that are run with the first- or a higher-level privilege, and

information collected by a local sensor or a computer on the target host on processes that are run in the target host with the first- or higher-level privilege.

9 . An arrangement for privilege escalation detection in a computer or computer network, the arrangement comprising:

at least one computer comprising circuitry configured to:

examine which executables are running in a target host,

search, from a behavioral data source, behavioral information of the executables running in the target host,

include, in a first list, identification information of executables running in the target host which the behavioral information indicates are known to run with a first- or a higher-level privilege,

include, in a second list, identification information of sensitive resources loaded or executed by the executables included in the first list,

examine the sensitive resources included in the second list to determine whether that resource is writable by an executable running at a privilege level lower than the first level by examining resources existing in the target host, and comparing the examined resources with the sensitive resources in the second list to determine which ones of the resources existing in the target host may be vulnerable, and

provide an indication of every resource that is loaded by the first- or higher-level privilege executable but is writable by the executable running at a privilege level lower than the first level as a potential vulnerability.

10 . The arrangement according to claim 9 , wherein the at least one computer is further configured to:

include, in the first list, identification information of every executable file run by a high privileged executable, every dynamic link library loaded by a privileged executable, and every registry key value read and executed by a privileged executable.

11 . A non-transitory computer-readable medium comprising a computer program comprising instructions which, when executed by a computer, cause the computer to:

examine which executables are running in a target host;

search, from a behavioral data source, behavioral information of the executables running in the target host;

include, in a first list, identification information of executables running in the target host which the behavioral information indicates are known to run with a first- or a higher-level privilege;

include, in a second list, identification information of sensitive resources loaded or executed by the executables included in the first list;

examine the sensitive resources included in the second list to determine whether that resource is writable by an executable running at a privilege level lower than the first level by examining resources existing in the target host, and comparing the examined resources with the sensitive resources in the second list to determine which ones of the resources existing in the target host may be vulnerable; and

provide an indication of every resource that is loaded by the first- or higher-level privilege executable but is writable by the executable running at a privilege level lower than the first level as a potential vulnerability.

12 . An apparatus for privilege escalation detection in a computer or computer network, the apparatus comprising:

one or more processors configured to:

examine which executables are running in a target host,

search, from a behavioral data source, behavioral information of the executables running in the target host,

include, in a first list identification, information of executables running in the target host which the behavioral information indicates are known to run with a first- or a higher-level privilege,

include, in a second list identification, information of sensitive resources loaded or executed by the executables included in the first list,

examine the sensitive resources included in the second list to determine whether that resource is writable by an executable running at a privilege level lower than the first level by examining resources existing in the target host, and comparing the examined resources with the sensitive resources in the second list to determine which ones of the resources existing in the target host may be vulnerable, and

provide an indication of every resource that is loaded by the first- or higher-level privilege executable but is writable by the executable running at a privilege level lower than the level first as a potential vulnerability.

13 . The apparatus according to claim 12 , wherein the one or more processors is configured to include, in the first list, identification information of every executable file run by a high privileged executable, every dynamic link library loaded by a privileged executable, and every registry key value read and executed by a privileged executable.

Assignments (2)
CHANGE OF NAME Recorded Feb 23, 2023
From: F-SECURE CORPORATION
To: WITHSECURE CORPORATION
Reel/Frame 062837/0255 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 22, 2023
From: NIEMELÄ, JARNO
To: F-SECURE CORPORATION
Reel/Frame 062770/0783 →
Priority Claims (1)
GB 2202482 · Feb 23, 2022 · national
Continuity (1)
Related Publication 20230269261A1 · Aug 24, 2023
References Cited (42)
US 7437766B2 · Cohen · 2008 [cited by examiner]
US 8601531B1 · Zolfonoon · 2013 [cited by examiner]
US 9106689B2 · Steinbrecher · 2015 [cited by examiner]
US 9392007B2 · Giokas · 2016 [cited by examiner]
US 9411955B2 · Jakobsson · 2016 [cited by examiner]
US 9432393B2 · Bartos · 2016 [cited by examiner]
US 9921937B2 · Seto · 2018 [cited by examiner]
US 10454934B2 · Parimi · 2019 [cited by examiner]
US 10592678B1 · Ismael · 2020 [cited by examiner]
US 10963583B1 · Shimony · 2021 [cited by examiner]
US 11301235B1 · Erdogan · 2022 [cited by examiner]
US 11314859B1 · Singh · 2022 [cited by examiner]
US 11516222B1 · Srinivasan · 2022 [cited by examiner]
US 11822670B2 · Hecht · 2023 [cited by examiner]
US 11995038B2 · Gopalakrishnan · 2024 [cited by examiner]
US 20070083912A1 · Lambert et al. · 2007 [cited by applicant]
US 20090271863A1 · Govindavajhala et al. · 2009 [cited by applicant]
US 20140205099A1 · Christodorescu · 2014 [cited by examiner]
US 20160004869A1 · Ismael · 2016 [cited by examiner]
US 20160006756A1 · Ismael · 2016 [cited by examiner]
US 20160065594A1 · Srivastava · 2016 [cited by examiner]
US 20160085970A1 · Rebelo · 2016 [cited by examiner]
US 20160092677A1 · Patel · 2016 [cited by examiner]
US 20160142410A1 · Mazzara, Jr. · 2016 [cited by examiner]
US 20160226904A1 · Bartos · 2016 [cited by examiner]
US 20170078315A1 · Allen · 2017 [cited by examiner]
US 20170116413A1 · Takacs · 2017 [cited by examiner]
US 20170295197A1 · Parimi · 2017 [cited by examiner]
US 20180005243A1 · Zovi · 2018 [cited by examiner]
US 20180248889A1 · Deninno · 2018 [cited by examiner]
US 20180375891A1 · Juncker · 2018 [cited by examiner]
US 20190166126A1 · Lazarovitz et al. · 2019 [cited by applicant]
US 20190207953A1 · Klawe · 2019 [cited by examiner]
US 20190273754A1 · Ting · 2019 [cited by examiner]
US 20200067971A1 · Chiu · 2020 [cited by examiner]
US 20200076819A1 · Spurlock · 2020 [cited by examiner]
US 20200137104A1 · Hassanzadeh · 2020 [cited by examiner]
US 20220060323A1 · Payne · 2022 [cited by examiner]
US 20230019180A1 · de Nijs · 2023 [cited by examiner]
US 20230037069A1 · Sela · 2023 [cited by examiner]
US 20230259640A1 · Metzler · 2023 [cited by examiner]
US 20240022583A1 · Miserendino · 2024 [cited by examiner]