Executable Binary Traps for Privilege Escalation Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security breach detection techniques in computer networks are often slow, limited in scope, and prone to false positives, making it difficult to detect privilege escalation attempts in a timely manner, which can lead to costly data exfiltration and sabotage.

Innovation Solution

Deploying executable binaries with alerting beacons within computer networks as traps to identify vulnerable resources, which trigger notifications and allow for proactive preventative actions without alerting the attacker, thereby enhancing early detection and logging of malicious activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If traditional security breach detection techniques are used, then security monitoring is performed, but detection is slow (taking upwards of 200 days) and limited in scope

Engineering Contradiction:
Improvedetection timeVSAvoiddetection effectiveness
Core Design Contradiction:
Loss of timeVSProductivity

Solution Approach 1:

The patent deploys executable binaries with alerting beacons in advance throughout the network before any breach occurs. These binaries are positioned strategically to detect privilege escalation attempts as they happen, rather than waiting for traditional detection methods to identify a breach weeks or months later. The binaries are pre-placed in locations where attackers are likely to attempt exploitation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The executable binaries act as intermediary detection agents between the attacker's actions and the security monitoring system. When an attacker attempts privilege escalation, the binary intercepts the action and triggers an alerting beacon that communicates with the security management system, providing real-time detection without requiring the attacker to complete their malicious objective.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If detection techniques are deployed to monitor network activity, then security breaches can be identified, but false positives are common and noise is high

Engineering Contradiction:
Improvedetection accuracyVSAvoidfalse positives
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The executable binaries are designed with specialized local functionality tailored to detect specific privilege escalation techniques. Each binary is configured to monitor for particular suspicious behaviors and patterns relevant to its deployment location, rather than using generic detection rules that produce false positives. The binaries analyze local system calls and processes with context-aware detection logic.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The detection system dynamically adjusts monitoring parameters and alerting thresholds based on the specific network environment and observed behavior patterns. The executable binaries can modify their detection sensitivity and alerting behavior based on contextual information, reducing false positives while maintaining detection effectiveness for actual threats.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If monitoring systems are implemented to detect breaches, then security events can be logged, but the systems are often slow and fail to provide timely detection

Engineering Contradiction:
Improvedetection precisionVSAvoiddetection speed
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The executable binaries are self-contained detection agents that autonomously monitor their local environment and generate alerts without requiring constant communication with or processing by centralized monitoring systems. Each binary independently detects privilege escalation attempts on its host system and immediately triggers alerting beacons, enabling fast local detection that doesn't bottleneck at centralized analysis points.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The detection system is divided into multiple distributed executable binaries deployed across different network segments and systems. Each binary handles detection for its local area, parallelizing the detection process across many independent units rather than using a single centralized system. This segmentation enables simultaneous detection across the entire network with high speed and precision.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11611585B2Detection of privilege escalation attempts within a computer network
Publication Date: 2023.03.21 PAYPAL INC
  • US11611585B2 patent drawing
  • US11611585B2 patent drawing
  • US11611585B2 patent drawing

AI summary

Techniques are disclosed relating to computer network security. In some embodiments, a computing system generates a plurality of executable binaries that include alerting beacons for a computer network associated with a transaction service. The computing system then deploys, within the computer network, the plurality of executable binaries as traps to detect privilege escalation attempts within the computer network. In some embodiments, the computing system detects that one or more alerting beacons included in the plurality of executable binaries have been triggered. In response to the detecting, the computing system may transmit, to a security management system, a notification indicating the one or more triggered alerting beacons. The disclosed detection techniques may advantageously reduce breaches in network security, which in turn may reduce or prevent the loss of private data.