Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

25 results about "Privilege escalation" patented technology

Privilege escalation is the act of exploiting a bug, design flaw or configuration oversight in an operating system or software application to gain elevated access to resources that are normally protected from an application or user. The result is that an application with more privileges than intended by the application developer or system administrator can perform unauthorized actions.

Unauthorized vulnerability detection method, device and equipment and readable storage medium

The invention discloses an unauthorized vulnerability detection method, device and equipment and a readable storage medium, and is applied to the field of security detection, and the method comprises the steps: carrying out the semantic recognition of real business flow data through a large language model, and determining a to-be-detected interface; performing semantic analysis on the parameters of the to-be-detected interface by using a large language model to determine target parameters; extracting a parameter value with an unauthorized vulnerability risk in the target parameter from the historical real service flow data; generating a test effective load of the to-be-detected interface based on the target parameter and the parameter value by utilizing a large language model and a preset rule base; and performing unauthorized vulnerability detection on the to-be-detected interface by using the test payload, and determining a detection result. According to the method, the natural language understanding capability of a large language model is utilized, the limitation of traditional regularization preprocessing and effective load generation is broken through, and the method is adaptive to diversified scenes of a complex system.
Owner:HANGZHOU DBAPPSECURITY CO LTD

Power industrial control terminal network isolation method and system based on process security label binding

The application discloses a kind of power industrial control terminal network isolation method and system based on process security label binding;Belong to the technical field of power system network security, its operating steps include: decoupling physical network resources into independent partitions and mapping to independent user-mode network protocol stack instances;Through the bottom flow direction rule, the in-bound traffic is accurately delivered to the corresponding partition;Identify process security label at the application layer, establish the forced mapping of process and specific protocol stack instance and link;Through the controlled shared memory channel, realize the safe data interaction between partitions.The application realizes strong logical isolation on unified hardware, through the forced binding of process identity and network link, reduces the privilege promotion and horizontal penetration risk caused by traditional protocol stack sharing, while limiting the scope of failure impact, without relying on external physical isolation equipment, significantly improves the endogenous security protection capability of industrial control system network boundary.
Owner:NARI INFORMATION & COMM TECH

Privileged semi-containerized system services for developing and deploying embedded applications

Disclosed subject matter encompasses method operations performed by an embedded device. Exemplary deployments may include a BMC as the embedded device, but the embedded device is expressly not limited to BMCs. Disclosed subject matter enables partially-sandboxed execution environments (SSEEs) with an auditable framework supporting unrestricted or restricted system access via privilege elevation capabilities not generally permitted within conventional container solutions. Functional modularity is implemented without incurring the substantial overhead inherent in fully modular and isolated containers. Disclosed SSEEs require no intermediate runtime or the corresponding overhead. Disclosed subject matter may leverage sandboxing functionality native to at least some software package management utilities (SPMUs) including, as a non-limiting example, a Flatpak utility suitable for use in embodiments employing a Linux OS, to achieve footprint-efficient SSEEs.
Owner:DELL PROD LP

Computer system network security risk monitoring system and method

The invention relates to the technical field of information security, in particular to a computer system network security risk monitoring system and method.The method comprises the steps that a code analysis tool is used for extracting a plurality of code snippets capable of being independently executed from a source code, a binary file or a running environment, and a function attribute tag is added to each code snippet capable of being independently executed; setting at least one attack purpose according to a preset security threat type, wherein the security threat type comprises a permission enhancement attack, a data leakage attack, a service interruption attack, a supply chain attack or an identity authentication bypassing attack; based on the attack purpose and the code snippets capable of being independently executed, a genetic algorithm is adopted to generate a plurality of code combination paths, static fitness scoring is conducted on the code combination paths, and when a novel attack means does not appear, timely response is conducted, potential attack paths which are not utilized are found out, and blocking is conducted in advance.
Owner:BEIJING CHITIAN DINGSHENG TECHNOLOGY CO LTD

A cluster service proxy method and system

ActiveCN115865464BSecuring communicationProtocol ApplicationFile copying
The present application relates to the technical field of cluster service management, and provides a cluster service proxy method and system, the method of the present application comprising: according to a request of deleting a host from an execution party, backing up data of the corresponding host, and deleting the host from the cluster by a host management center in a proxy service layer; executing an execution command verified by an application layer and the proxy service layer inside cluster resources by a command execution module in the application layer; and copying a to-be-copied file verified by the application layer and the proxy service layer into the cluster resources by a file copying module in the application layer. The system of the present application comprises: an application layer, a proxy service layer, a storage layer, and a cluster layer. The cluster service proxy method and system of the exemplary embodiments of the present application can ensure that the cluster service is not affected before deleting a host; avoid executing file copying and command execution on resources without operation right by the execution party; and prevent command injection, privilege escalation, and other operations that threaten the security of the cluster resources.
Owner:CHINA ELECTRONICS CLOUD DIGITAL INTELLIGENCE TECH CO LTD

A method and system for mining privilege-related vulnerabilities in power monitoring systems

PendingCN122339727AData packData set
This invention discloses a method and system for mining permission-related vulnerabilities in power monitoring systems. First, it automates login to the target system to obtain valid test sessions. Then, it simulates user operations to trigger system function interfaces, capturing network request data during the interaction process and constructing an interface dataset. Data packets are filtered and analyzed, and sensitive traffic with abnormal permissions is identified based on a large language model. Cookies are replaced and replay tests are performed. The original response and the replay response are compared, and the presence of horizontal privilege escalation vulnerabilities is determined by calculating structural similarity. This invention effectively overcomes the shortcomings of traditional automated tools, such as high false positives and false negatives and poor flexibility due to a lack of dynamic decision-making capabilities, by constructing a complete closed-loop process of automated login, interface data collection, intelligent identification using a large language model, and cookie replacement and replay. This significantly improves the intelligence level of penetration testing and the accuracy of vulnerability mining.
Owner:NARI INFORMATION & COMM TECH

Vertical unauthorized protection method based on RBAC model

The invention relates to a vertical unauthorized protection method based on an RBAC model, and belongs to the field of data security. The method comprises the following steps: formulating a custom annotation for classes and methods of a WEB system; when the class or the method uses the custom annotation, all interfaces of the class or the interface of the method are associated with a menu specified by the attribute value of the attribute menu; when the user has the authority of any menu in the appointed menus, judging that the user has the authority to access a corresponding interface, otherwise, judging that the user is vertical unauthorized and intercepting; and performing protection verification on vertical unauthorized, judging whether all the menu lists with the authority of the user contain any menu in the menu lists specified in the user-defined annotations or not, and if so, releasing the interface request. According to the method, simplification and generalization of vertical unauthorized protection can be achieved in a user-defined annotation mode, and the development workload and the later maintenance cost are effectively reduced.
Owner:E SURFING VISION TECHNOLOGY CO LTD

Methods for non-invasive API discovery, monitoring and exploitation detection in third-party processes

System and method for non-invasive monitoring and exploitation detection in third-party software processes. The system includes modules for scanning process memory to identify sensitive credentials such as application programming interface (API) keys and tokens, monitoring opened file descriptors including files, sockets, and inter-process communication channels, and analyzing network activity including domain name system (DNS) requests and encrypted connections. Runtime metadata such as privileges, environment variables and resource usage is also collected. The system correlates these signals to detect indicators of exploitation, such as unauthorized access, privilege escalation, or injected payloads, without modifying or instrumenting the monitored process. Integration with external security systems may enhance detection accuracy. Alerts and reports are generated in real-time to support incident response and forensic analysis.
Owner:WALLARM INC

Arrangement and method of privilege escalation detection in a host

A privilege escalation risk detection in a host (1, Fig.1) applicable to a computer and / or network, comprising: examining which executables are running in a host (401) and searching for behavioural in
Owner:F SECURE CORP

Vulnerability correlation analysis method, system, device and storage medium

ActiveCN116436680BAttackPrivilege escalation
The application discloses a vulnerability correlation analysis method, system and device and a storage medium, and relates to the technical field of computers. The vulnerability correlation analysis method comprises the following steps: acquiring a system vulnerability list of a target system; classifying vulnerabilities in the system vulnerability list into corresponding privilege escalation categories based on a privilege escalation theory, wherein the privilege escalation categories comprise prerequisite privileges and result privileges; combining vulnerabilities in multiple privilege escalation categories to obtain multiple vulnerability attack chains; determining the scores of the vulnerability attack chains according to the influence degree quantitative values, the exploitability quantitative values and the privilege escalation span quantitative values of the vulnerability attack chains, and selecting an optimal vulnerability attack chain according to the scores of the vulnerability attack chains. The application can mine the privilege correlation between system vulnerabilities, select the optimal vulnerability attack chain based on the scores of the vulnerability attack chains, and is helpful to efficiently repairing system vulnerabilities.
Owner:GUANGZHOU UNIVERSITY

An intelligent network security threat detection method based on big data analysis

The application relates to the technical field of network security, and discloses a network security threat intelligent detection method based on big data analysis, which comprises the following steps: collecting network equipment flow log data, constructing a network behavior space-time fusion matrix, and calling the optimal threat detection algorithm; through an innovatively designed dynamic feature dimension alignment mechanism, the tensor structure mismatch problem caused by the difference between asset static data and network flow data sampling frequency in a traditional scheme is overcome; an adaptive tensor interpolation technology is used to realize the mapping of dynamic and static logs in the space-time dimension, reduce systematic deviation during feature fusion, and improve the accuracy of subsequent threat analysis; through the established network behavior space-time fusion matrix, asset service topology, vulnerability fingerprints and real-time flow behavior are three-dimensionally associated and modeled for the first time, the behavior chain characteristics of an attacker in the process of horizontal movement and privilege escalation are described, and the attack path restoration capability for advanced sustainable threats is improved.
Owner:余伟

Complex Application Attack Quantification, Testing, Detection and Prevention

An apparatus and method for cyber risk quantification calculated from the likelihood of a cyber-attack on the target enterprise and / or cyber ecosystem based on its security posture. The cyber-attack likelihood can be derived as a probability-based time-to-event (TTE) measure using survivor function analysis. The likelihood probability measure can also be passed to cyber risk frameworks to determine financial impacts of the cyber-attacks. Embodiments of the present invention also relate to an apparatus and method (1) to identify and validate application attack surfaces and protect web applications against business logic-based attacks, sensitive data leakage and privilege escalation attacks; and / or (2) that protects web applications against business logic-based attacks, sensitive data leakage and privilege escalation attacks. This can include implementing an intelligent learning loop using artificial intelligence that creates an ontology-based knowledge base from application request and response sequences. Stochastic probabilistic measures are preferably applied to a knowledge base for predicting malicious user actions in real time.
Owner:IVANTI INC

Method, device and storage medium for detecting lateral privilege escalation vulnerabilities

This application discloses a method, apparatus, and storage medium for detecting lateral privilege escalation vulnerabilities, belonging to the field of cloud computing. The method is applied to a computing device, which includes an application and a first data table of the application. The method includes: obtaining interface functions included in the application, each interface function including at least one first variable; obtaining a function call chain based on the interface functions, the function call chain including multiple functions in the application, the function call chain being used to access the first data table based on the at least one first variable; and detecting whether the application has a lateral privilege escalation vulnerability based on the function call chain. This application can improve the accuracy of detecting lateral privilege escalation vulnerabilities.
Owner:HUAWEI TECH CO LTD +1

Memory management method and electronic device

ActiveCN121598371BImprove continuous support capabilitiesSolve memory fragmentationResource allocationMemory adressing/allocation/relocationHeap overflowParallel computing
The application discloses a memory management method and electronic equipment, and relates to the technical field of system security. The method comprises the following steps: obtaining a kernel native heap memory allocation function and a heap memory release function; obtaining a vulnerability object allocation function; monitoring the kernel heap memory allocation function and the vulnerability object allocation function through dynamic extension of a kernel program, collecting memory pre-allocation data according to a monitoring result, and performing a write operation on the memory; comparing double-boundary memory write operation parameters with the memory pre-allocation data, and detecting heap overflow of the memory write operation according to a comparison result; and in response to a detection result of the heap overflow of the memory write operation being failed, releasing an original memory application through the heap memory release function, and reallocating the memory application through a dynamic cache pool algorithm. The application can block privilege escalation and kernel crash caused by memory heap overflow in real time, solve the problems of memory fragmentation and defense lag, and significantly improve the continuous guarantee capability of a key business scenario.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

A method and system for forensic analysis based on smart terminals

This invention proposes a forensic analysis method and system based on a smart terminal. The method includes the following steps: Step S1: Dynamic adaptation configuration, real-time monitoring of the target terminal's operating system version and hardware identifier, and automatic loading of a matching privilege escalation script and data parsing protocol; the privilege escalation script is configured with an injected parameterized kernel module, which is constructed using a combination of pre-compiled binary templates and runtime injected variables. The pre-compiled binary templates contain system call hijacking instructions and memory address redirection logic; the automated engineering loads a dynamic symbol parser in a sandbox environment, and generates a data extraction interface by intercepting application data encryption and decryption function call points; Step S2: Cloud-based collaborative forensics, constructing an authentication token and session key based on the target account's encrypted backup data on the terminal, and initiating a read-only data request to the cloud server through a communication protocol simulating a legitimate client.
Owner:XIAMEN MEIYA ZHONGMIN TECH CO LTD

A method and system for controlling the permission of a container cross-domain access to a host hardware service

The application provides a permission control method and system for a container to access a host hardware service across domains, determines the number of slots in a host system configuration file, and generates slot identifiers, hardware service context mapping rules, security enhanced Linux type definition files, access control permission rules, and cross-slot prohibition rules to compile the host system, to generate a host system image; modifies key functions in a hardware interface definition language base library on the container side and compiles them into a container system image; when any container is started, an idle slot is found from a slot allocation table, the corresponding slot identifier is allocated to the started container, and all processes in the container are controlled to run in a security domain of the idle slot; a verification hook function is registered in a hardware service manager of the host system to perform consistency verification on caller process information and slot information in a complete service name, to obtain a verification result; and the risk of out-of-bound access and privilege escalation is reduced.
Owner:HUNAN XIAOSUAN TECH INFORMATION CO LTD

Identity security protection methods, systems, and storage media based on Azure AD control capabilities

The application belongs to the technical field of computer network security, and particularly relates to a Kerberos protocol weak encryption and cloud dynamic strategy combined privilege escalation method. The method comprises the following steps: using SYSTEM level permission to access a target user object in AD, modifying a preset condition conforming to a cloud privilege dynamic group membership rule to obtain a tampered target user attribute; using an Azure AD Connect synchronization service to mark the tampered target user attribute as an attribute update event, and determining that abnormal data flow conforms to normal business synchronization characteristics; constructing a ticket by using a Kerberos client library according to an NTLM hash of a target user account to obtain a fake ticket; the target user account is dynamically added to an associated global administrator role group to obtain a target user account with a global administrator session token; and the target user account is logged in to a PTA service channel by using the fake ticket to obtain Azure AD control capability.
Owner:NO 15 INST OF CHINA ELECTRONICS TECH GRP

Techniques for utilizing a sensor in detecting privilege escalation

A system and method for detecting privilege escalation on a resource deployed in a computing environment is presented. The method includes configuring the resource to deploy thereon a sensor, the sensor configured to detect events on a data link layer of the resource; receiving from the sensor a detection indicating a permission-based event of a first actor, the permission-based event indicating a first permission set of the first actor; querying a database to detect a second permission set of the first actor; detecting that the first permission set includes a permission which is not in the second permission set; detecting a privilege escalation event in response to detecting that the first permission set includes a permission which is not in the second permission set; and initiating a mitigation action in response to detecting the privilege escalation event.
Owner:WIZ INC

Deleting method, system and device based on USB device plugging and unplugging records under operating system and medium

The invention provides a deleting method, system, device and medium based on USB device plug-pull records under an operating system, and belongs to the technical field of USB device plug-pull records, and the deleting method comprises the steps of registry permission privilege lifting, USB path data extraction, PID / VID rule establishment, and registry full quantum item traversal matching deletion. Exporting and replacing the system file, and after restarting, loading an old-version system file and deleting the old-version system file for the second time; identifying NK blocks based on an HIVE file format, screening target blocks which are in a deleted state and have names containing DISK / USB or matched PID / VID, and generating equal-length random character strings to cover name data; and finally, deleting the old file, associating the log and executing safe erasing of the residual space of the disk. By replacing a registry file, processing old file residues, covering multi-dimensional data and erasing a disk, the USB equipment plugging and unplugging record is thoroughly cleared, and anti-forensics recovery is effectively prevented.
Owner:中孚安全技术有限公司 +3

A firewall data processing method based on terminal security protection

PendingCN122316683ARate limitingPathPing
This invention relates to a firewall data processing method based on endpoint security protection. It establishes an endpoint connection management mechanism, maintains an active connection table and a state hook mapping table, and associates outbound connections with process identifiers, user identities, data payload summaries, and creation times to form state hooks. Hook verification is triggered when the endpoint state changes. If sensitive privilege escalation or behavior deviating from the initial digest is detected, the connection priority is dynamically adjusted, and rate limiting, blocking, or transition to observation mode is implemented. Access path consistency verification is performed on outbound connections, comparing DNS requests, process calls, and actual packet paths. If unexplained path offsets exist, the source is traced and the path is reconstructed. Connection behavior is periodically split according to operating system event granularity, and concurrent or abrupt behavior is logically redefined into multiple sub-sessions with corresponding policies applied. Transmission delays are applied to reversible connection operations, and action chain tracing is activated to determine whether to restore or terminate the connection.
Owner:LEADCHUANG ANDA (BEIJING) TECHNOLOGY CO LTD

Methods for non-invasive API discovery, monitoring and exploitation detection in third-party processes

System and method for non-invasive monitoring and exploitation detection in third-party software processes. The system includes modules for scanning process memory to identify sensitive credentials such as application programming interface (API) keys and tokens, monitoring opened file descriptors including files, sockets, and inter-process communication channels, and analyzing network activity including domain name system (DNS) requests and encrypted connections. Runtime metadata such as privileges, environment variables and resource usage is also collected. The system correlates these signals to detect indicators of exploitation, such as unauthorized access, privilege escalation, or injected payloads, without modifying or instrumenting the monitored process. Integration with external security systems may enhance detection accuracy. Alerts and reports are generated in real-time to support incident response and forensic analysis.
Owner:WALLARM INC

Multi-role intelligent customer service system supporting transaction emergency upgrade, dynamic privilege lifting and performance tracking

The invention discloses a multi-role intelligent customer service system supporting transaction emergency upgrade, dynamic privilege lifting and performance tracking, which relates to the technical field of enterprise service systems and comprises a transaction communication module, a transaction emergency degree judgment module, a privilege lifting module, a battle large-screen monitoring module, a mobile terminal and multi-terminal notification module and a performance tracking module. And multi-role cooperative processing of order and non-order transactions is realized. The system controls data intercommunication through an authority matrix, dynamically calculates the transaction emergency degree and triggers upgrading based on response delay, the state of a person in charge and the influence range, supports automatic privilege lifting of user application and rule triggering, monitors the global transaction state in real time through a large visual screen and allows mandatory intervention of an administrator, and improves the user experience. And meanwhile, the transaction progress is synchronously pushed across terminals, and a responsible person capability matrix is generated according to the response speed, the customer satisfaction, the circulation depth and the privilege lifting frequency, so that closed-loop performance management is realized, and the multi-role cooperation efficiency and the transaction processing intelligent level are comprehensively improved.
Owner:NANJING SONGLIN DIGITAL TECHNOLOGY CO LTD

A method, system, device and medium for deleting USB device plug-in recording based on an operating system

The application provides a USB device plug-in record deletion method, system, device and medium based on an operating system, belongs to the technical field of USB device plug-in records, and realizes complete deletion of the USB device plug-in record through registry permission privilege escalation, USB path data extraction, PID / VID rule establishment, full registry subentry matching deletion, export and replacement of a system file, loading of an old version system file after restart for secondary deletion, NK block identification based on a HIVE file format, screening of target blocks with a deleted state and a name containing DISK / USB or matching PID / VID, generation of an equal-length random string to cover name data, and final deletion of old files, associated logs and execution of disk remaining space safe erasure. Through replacement of a registry file, processing of old file residues, multi-dimensional data covering and disk erasure, complete deletion of the USB device plug-in record is realized, and anti-forensic recovery is effectively prevented.
Owner:中孚安全技术有限公司 +3

Arrangement and method of privilege escalation detection in a host

A method of privilege escalation risk detection in a host, such as a computer, and / or a network, such as a computer network, is disclosed. The method comprises: examining which executables are running in the host, searching, e.g. from a behavioral data source, behavioral information of the executables running in the host, performing a first identification phase for identifying executables running in the host which the behavioral information indicates are known to be run with an elevated privilege, performing a second identification phase by checking file access permissions to the executables identified in the first identification phase for identifying executables which are writable and / or modifiable by a privilege level lower than the elevated privilege, e.g. a privilege level other than administrator or system level privileges, and generating an alert for the executables identified in the second identification phase.
Owner:F SECURE CORP

Method and device for detecting and repairing privilege lifting vulnerability of login policy component

The invention relates to the technical field of network security, and discloses a method and a device for detecting and repairing a login policy component privilege lifting vulnerability. The method comprises the following steps: judging whether a login strategy component has a privilege lifting vulnerability caused by isolation deficiency of a main function parameter and an environment variable or not through detection logic injected into a login strategy component process; when it is detected that the right lifting vulnerability exists, the fault injection and repair binary program is injected into the login strategy component process with the right lifting vulnerability for hot repair. According to the application, the automation degree is high, the key authentication component in the system can be conveniently and quickly subjected to security screening and reinforcement, and the risk that the system is invaded, a prison breaks or a process is hijacked is effectively reduced, so that the overall security baseline of the generic Android operating system is remarkably enhanced.
Owner:CHINA FINANCIAL CERTIFICATION AUTHORITY