IP Library Granted Patent US 10,984,098
Granted Patent B2
US 10,984,098 · App. 15/967,356 · Granted Apr 20, 2021

Process privilege escalation protection in a computing environment

Inventors: Yaron Lavi (Tel-Aviv, IL); Eldar Aharoni (Holon, IL); Elad Wexler (Givatym, IL)
Assignee: Palo Alto Networks, Inc.
G06F21/54G06F21/44G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,984,098
App. No.
15/967,356
Granted
Apr 20, 2021
Kind
B2
Abstract

Techniques for privilege escalation protection are disclosed. In some embodiments, a system/process/computer program product for privilege escalation protection includes monitoring a process executed on a computing device, detecting an unauthorized change in a token value associated with the process, and performing an action based on a policy (e.g., a kernel protection security policy/rule(s), which can include a whitelisted set of processes and/or configured actions/responses to perform for other/non-whitelisted processes) in response to an unauthorized change in the token value associated with the process.

Claims (47)

1. A system, comprising:

a processor configured to:

monitor a process executed on a computing device;

detect an unauthorized change in a token value associated with the process, wherein the token value corresponds to an identifier of the process, and wherein the detecting of the unauthorized change in the token value comprises to:

cache an initial token value associated with the process; and

check for token value changes in response to a trigger event, comprising to:

compare the cached initial token value with another token value associated with another process; and

in response to a determination that the cached initial token value matches the other token value, determine that the token value has changed; and

perform an action based on a policy in response to the unauthorized change in the token value associated with the process, wherein the policy comprises a whitelisted set of processes, and wherein the performing of the action comprises to:

compare the process with one or more processes of the whitelisted set of processes; and

in response to a determination that the process matches the one or more processes, omit performing the action; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein the processor is further configured to:

detect an attempt to change the token value associated with the process to a value that is associated with another process executed on the computing device.

3. The system of claim 1 , wherein the

other process has kernel privileges.

4. The system of claim 1 , wherein

the trigger event includes a new process creation, a thread creation, a registry operation, a file operation, or any combination thereof.

5. The system of claim 1 , wherein the processor is further configured to:

perform a protection action based on the policy in response to the unauthorized change in the token value associated with the process.

6. The system of claim 1 , wherein the processor is further configured to:

kill the process based on the policy in response to the unauthorized change in the token value associated with the process.

7. The system of claim 1 , wherein the processor is further configured to:

generate an alert based on the policy in response to the unauthorized change in the token value associated with the process.

8. A method, comprising:

monitoring a process executed on a computing device;

detecting an unauthorized change in a token value associated with the process, wherein the token value corresponds to an identifier of the process, and wherein the detecting of the unauthorized change in the token value comprises:

caching an initial token value associated with the process; and

checking for token value changes in response to a trigger event, comprising:

comparing the cached initial token value with another token value associated with another process; and

in response to a determination that the cached initial token value matches the other token value, determining that the token value has changed; and

performing an action based on a policy in response to the unauthorized change in the token value associated with the process, wherein the policy comprises a whitelisted set of processes, and wherein the performing of the action comprises:

comparing the process with one or more processes of the whitelisted set of processes; and

in response to a determination that the process matches the one or more processes, omitting to perform the action.

9. The method of claim 8 , wherein the other process has kernel privileges.

10. The method of claim 8 , wherein the trigger event includes a new process creation, a thread creation, a registry operation, a file operation, or any combination thereof.

11. A computer program product, the computer program product being embodied in a non-transitory tangible computer readable storage medium and comprising computer instructions for:

monitoring a process executed on a computing device;

detecting an unauthorized change in a token value associated with the; process, wherein the token value corresponds to an identifier of the process, and wherein the detecting of the unauthorized change in the token value comprises:

caching an initial token value associated with the process; and

checking for token value changes in response to a trigger event, comprising:

comparing the cached initial token value with another token value associated with another process; and

in response to a determination that the cached initial token value matches the other token value, determining that the token value has changed; and

performing an action based on a policy in response to the unauthorized change in the token value associated with the process, wherein the policy comprises a whitelisted set of processes, and wherein the performing of the action comprises:

comparing the process with one or more processes of the whitelisted set of processes; and

in response to a determination that the process matches the one or more processes, omitting to perform the action.

12. The computer program product recited in claim 11 , wherein the other process has kernel privileges.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2018
From: LAVI, YARON; AHARONI, ELDAR; WEXLER, ELAD
To: PALO ALTO NETWORKS, INC.
Reel/Frame 046504/0242 →
Continuity (2)
Provisional Application 62654026 · Apr 6, 2018
Related Publication 20190311115A1 · Oct 10, 2019
Cited By (11)
US 12,443,720 US 12,489,781 US 12,495,049 US 12,505,200 US 12,506,755 US 12,524,550 US 12,531,881 US 12,547,765 US 12,579,251 US 12,645,785 US 12,688,277