IP Library Granted Patent US 12,664,271
Granted Patent B2
US 12,664,271 · App. 18/923,524 · Granted Jun 23, 2026

Protecting a computer device from escalation of privilege attacks

Inventors: John Goodridge (Cheshire, GB); Thomas Couser (Lancashire, GB)
Assignee: Avecto Limited
G06F21/554G06F9/445G06F2221/033G06F2221/2101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,664,271
App. No.
18/923,524
Filed
Oct 22, 2024
Granted
Jun 23, 2026
Kind
B2
Art Unit
2436
USPC
726/23
Abstract

A computing device can receive a notification that a process has interacted with the operating system to perform a predetermined operation on the at least one computing device. In response to the notification, the computing device can capture a current access token from the process. The computing device can perform a comparison of the current access token captured from the process against a stored access token. The computing device can determine that an escalation of privilege attack has occurred based on the comparison of the current access token captured from the process against the stored access token.

Claims (49)

1 . A system, comprising:

a memory storing an operating system; and

at least one computing device in communication with the memory, the at least one computing device being configured to:

register one or more callbacks with the operating system to provide a notification;

receive, via the one or more callbacks, the notification that a process has interacted with the operating system to perform a predetermined operation on the at least one computing device;

in response to the notification via the one or more callbacks, capture an initial access token from the process and record the initial access token as a stored access token;

perform a comparison of a current access token captured from the process against the stored access token; and

determine that an escalation of privilege attack has occurred based on the comparison of the current access token captured from the process against the stored access token.

2 . The system of claim 1 , wherein the comparison comprises a determination that the current access token differs from the stored access token.

3 . The system of claim 1 , wherein performing the comparison comprises determining that at least one field of the current access token differs from at least one field of the stored access token.

4 . The system of claim 3 , wherein comparing the at least one field of the current access token to the at least one field of the stored access token comprises using a memory address to probe at least one of: the current access token or the stored access token.

5 . The system of claim 1 , wherein performing the comparison comprises determining that a privilege list of the current access token differs from a privilege list of the stored access token.

6 . The system of claim 1 , wherein performing the comparison comprises determining that a memory address of the current access token differs from a memory address of the stored access token.

7 . The system of claim 1 , wherein performing the comparison comprises determining that a security identifier of the current access token differs from a security identifier of the stored access token.

8 . A method, comprising:

registering, via one of one or more computing devices, one or more callbacks with an operating system to provide a notification;

receiving, via the one or more callbacks, the notification that a process requested that the operating system of one of the one or more computing devices perform a predetermined operation on the one of the one or more computing devices;

in response to the notification via the one or more callbacks, capturing, via one of the one or more computing devices, an initial access token from the process and record the initial access token as a stored access token;

performing, via one of the one or more computing devices, a comparison of a current access token captured from the process against the stored access token; and

determining, via one of the one or more computing devices, that an escalation of privilege attack has occurred based on the comparison of the current access token captured from the process against the stored access token.

9 . The method of claim 8 , further comprising:

recording, via one of the one or more computing devices, the current access token in cache.

10 . The method of claim 8 , wherein the stored access token is recorded in cache.

11 . The method of claim 8 , wherein the stored access token is captured prior to capturing the current access token.

12 . The method of claim 8 , further comprising receiving, via one of the one or more computing devices, a first notification associated with a first process prior to receiving the notification.

13 . The method of claim 12 , wherein the process is a child process of the first process.

14 . A non-transitory computer-readable medium embodying a program that, when executed by at least one computing device, cause the at least one computing device to:

register one or more callbacks with an operating system to provide a notification;

receive, via the one or more callbacks, the notification that a process has interacted with an operating system of the at least one computing device to perform a predetermined operation on the at least one computing device;

in response to the notification via the one or more callbacks, an initial access token from the process and record the initial access token as a stored access token;

perform a comparison of a current access token captured from the process against the stored access token; and

determine that an escalation of privilege attack has occurred based on the comparison of the current access token captured from the process against the stored access token.

15 . The non-transitory computer-readable medium of claim 14 , wherein the program further causes the at least one computing device to:

establish a set of trigger points with the operating system of the at least one computing device using one or more additional callbacks.

16 . The non-transitory computer-readable medium of claim 15 , wherein the trigger points comprise any one or more of:

creation of a child process of the process;

creation of a remote thread that runs in an address space of another process;

requesting access to a system registry managed by the operating system;

loading an image of executable code into a memory of the at least one computing device; and

requesting access to a file system of the at least one computing device.

17 . The non-transitory computer-readable medium of claim 15 , wherein the program further causes the at least one computing device to:

register the one or more additional callbacks with the operating system to provide a second notification; and

record the current access token in response to the second notification.

18 . The non-transitory computer-readable medium of claim 14 , wherein the program further causes the at least one computing device to:

suspend the process in response to determining that the escalation of privilege attack has occurred.

19 . The non-transitory computer-readable medium of claim 14 , wherein the program further causes the at least one computing device to:

perform an audit of the notification based on a policy file.

20 . The non-transitory computer-readable medium of claim 14 , wherein the program further causes the at least one computing device to:

present a custom message on a display associated with the at least one computing device in response to determining that the escalation of privilege attack has occurred.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2024
From: GOODRIDGE, JOHN; COUSER, THOMAS
To: AVECTO LIMITED
Reel/Frame 069095/0946 →
Priority Claims (1)
GB 1806289 · Apr 18, 2018 · national
Continuity (4)
Continuation 18331489 · Jun 8, 2023
Continuation 17729476 · Apr 26, 2022
Continuation 16382578 · Apr 12, 2019
Related Publication 20250045390A1 · Feb 6, 2025
References Cited (74)
US 5881225A · Worth · 1999 [cited by applicant]
US 5991542A · Han et al. · 1999 [cited by applicant]
US 6233618B1 · Shannon · 2001 [cited by applicant]
US 7133904B1 · Sohya et al. · 2006 [cited by applicant]
US 7219354B1 · Huang et al. · 2007 [cited by applicant]
US 8127316B1 · Binotto et al. · 2012 [cited by applicant]
US 8368640B2 · Dardinski et al. · 2013 [cited by applicant]
US 9158662B1 · Hanes et al. · 2015 [cited by applicant]
US 9769131B1 · Hartley et al. · 2017 [cited by applicant]
US 10565378B1 · Vincent · 2020 [cited by examiner]
US 10803499B1 · Davis et al. · 2020 [cited by applicant]
US 11321455B2 · Goodridge et al. · 2022 [cited by applicant]
US 11714901B2 · Goodridge et al. · 2023 [cited by applicant]
US 20020144137A1 · Harrah et al. · 2002 [cited by applicant]
US 20020174256A1 · Bonilla et al. · 2002 [cited by applicant]
US 20030212910A1 · Rowland · 2003 [cited by examiner]
US 20040210771A1 · Wood et al. · 2004 [cited by applicant]
US 20050188370A1 · Kouznetsov et al. · 2005 [cited by applicant]
US 20060089834A1 · Mowatt et al. · 2006 [cited by applicant]
US 20070180502A1 · Yadav et al. · 2007 [cited by applicant]
US 20070198933A1 · Van Der Bogert et al. · 2007 [cited by applicant]
US 20080060051A1 · Lim · 2008 [cited by applicant]
US 20080289026A1 · Abzarian et al. · 2008 [cited by applicant]
US 20090070442A1 · Kacin et al. · 2009 [cited by applicant]
US 20100274366A1 · Fata et al. · 2010 [cited by applicant]
US 20110030045A1 · Beauregard et al. · 2011 [cited by applicant]
US 20110173251A1 · Sandhu et al. · 2011 [cited by applicant]
US 20110196842A1 · Timashev et al. · 2011 [cited by applicant]
US 20110239288A1 · Cross et al. · 2011 [cited by applicant]
US 20110251992A1 · Bethlehem et al. · 2011 [cited by applicant]
US 20120047259A1 · Krasser et al. · 2012 [cited by applicant]
US 20120054744A1 · Singh et al. · 2012 [cited by applicant]
US 20120066512A1 · Kass et al. · 2012 [cited by applicant]
US 20120226742A1 · Momchilov et al. · 2012 [cited by applicant]
US 20130057561A1 · Nave et al. · 2013 [cited by applicant]
US 20130339313A1 · Blaine et al. · 2013 [cited by applicant]
US 20140279600A1 · Chait · 2014 [cited by applicant]
US 20140281528A1 · Dubey et al. · 2014 [cited by applicant]
US 20150040181A1 · Cook et al. · 2015 [cited by applicant]
US 20150058839A1 · Madanapalli et al. · 2015 [cited by applicant]
US 20150074828A1 · Beauregard et al. · 2015 [cited by applicant]
US 20150128250A1 · Lee et al. · 2015 [cited by applicant]
US 20160203313A1 · El-Moussa et al. · 2016 [cited by applicant]
US 20160217159A1 · Dahan et al. · 2016 [cited by applicant]
US 20160378962A1 · Austin · 2016 [cited by applicant]
US 20170011220A1 · Efremov et al. · 2017 [cited by applicant]
US 20170026379A1 · Lu · 2017 [cited by examiner]
US 20170048259A1 · Dodge et al. · 2017 [cited by applicant]
US 20170054760A1 · Barton et al. · 2017 [cited by applicant]
US 20170111368A1 · Hibbert et al. · 2017 [cited by applicant]
US 20180024895A1 · Kumarasamy et al. · 2018 [cited by applicant]
US 20180302409A1 · Hope et al. · 2018 [cited by applicant]
US 20190121631A1 · Hua et al. · 2019 [cited by applicant]
US 20190268152A1 · Sandoval · 2019 [cited by examiner]
US 20190311115A1 · Lavi · 2019 [cited by examiner]
EP 2750035A1 · 2014 [cited by applicant]
GB 2486528B · 2016 [cited by applicant]
GB 2538518A · 2016 [cited by applicant]
GB 2563066A · 2018 [cited by applicant]
KR 101308859B1 · 2013 [cited by applicant]
WO 2006101549A2 · 2006 [cited by applicant]
WO 2007089786A2 · 2007 [cited by applicant]
WO 2015183493A1 · 2015 [cited by applicant]
WO 2018174990A1 · 2018 [cited by applicant]
Combined Examination and Search Report for United Kingdom Patent Application No. GB1708824.6, dated Dec. 1, 2017, 1 Page. [cited by applicant]
Combined Examination and Search Report for United Kingdom Patent Application No. GB1714489.0, dated Feb. 6, 2018, 7 Pages. [cited by applicant]
Combined Examination and Search Report for United Kingdom Patent Application No. GB1802241.8, dated Aug. 1, 2018, 7 Pages. [cited by applicant]
Combined Examination and Search Report for United Kingdom Patent Application No. GB1808380.8, dated Nov. 16, 2018, 7 Pages. [cited by applicant]
Combined Examination and Search Report for United Kingdom Patent Application No. GB1814798.3, dated Mar. 6, 2019, 9 Pages. [cited by applicant]
Davi L., et al., “Privilege Escalation Attacks on Android,” Information Security Lecture Notes in Computer Science, Editors—Burmester M., Tsudik G., Magliveras S., Springer, Berlin, Heidelberg, Oct. 2010, vol. 6531, pp.… [cited by applicant]
Examination Report for United Kingdom Patent Application No. GB1600738.7, dated Jun. 14, 2019, 5 Pages. [cited by applicant]
Examination Report for United Kingdom Patent Application No. GB1715628.2, dated Apr. 29, 2020, 4 Pages. [cited by applicant]
Hoffman C., et al., “How to Install Applications on a Mac: Everything You Need to Know,” How-To Geek, Jul. 20, 2017, 10 Pages, Retrieved from URL: https://www.howtogeek.com/177619/how-to-install-applications-on-a-mac-ev… [cited by applicant]
Hoffman C., “How to Disable System Integrity Protection on a Mac (and Why You Shouldn't),” How-To Geek, Jul. 5, 2017, 6 Pages, Retrieved from URL: https://www.howtogeek.com/230424/how-to-disable-system-integrity-protect… [cited by applicant]