Privilege Elevation Graph for Network Security Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Privilege elevation flaws in computer systems are difficult to locate and diagnose, as modern operating systems lack feedback on the effectiveness of privilege and access control functionalities, making them vulnerable to security breaches through accidental identity crossings and interdependencies introduced by new software installations.

Innovation Solution

A privilege elevation flaw detection analysis is performed on a host system, generating a graph that illustrates account nodes and edges representing detected privilege elevations, allowing users to identify potential security risks and compare system states before and after software installations to detect new vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If modern operating systems provide privilege and access control functionality, then security management capability is improved, but the system becomes vulnerable to privilege elevation flaws due to lack of feedback on effectiveness

Engineering Contradiction:
Improvesecurity management capabilityVSAvoidprivilege elevation flaws
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback by analyzing system configurations, software installations, and account relationships to detect privilege elevation pathways. The system provides feedback to administrators about potential security flaws, enabling them to understand and mitigate risks in the privilege structure.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary analysis of privilege configurations and software installations to identify potential elevation pathways before they can be exploited. By detecting flaws in advance through configuration analysis and relationship mapping, the system enables proactive security management.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If new software programs are installed to enhance system functionality, then system versatility is improved, but new privilege elevation flaws are introduced into the system

Engineering Contradiction:
Improvesystem functionalityVSAvoidnew privilege elevation flaws
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary analysis of software configurations and account relationships before they can be exploited. By detecting privilege elevation pathways in advance through configuration analysis, the system enables proactive security management alongside functionality enhancement.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors and analyzes the impact of new software installations on privilege structures. By providing feedback about newly introduced elevation pathways, administrators can assess security implications before deploying software updates.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If privilege elevation analyses are performed on multiple network systems, then detection capability is improved, but analysis complexity and time consumption increase

Engineering Contradiction:
Improvedetection capabilityVSAvoidanalysis time consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the network analysis into individual host system analyses. Each host is analyzed separately for its privilege elevation pathways, and results are then integrated into a comprehensive network-wide view. This segmentation enables manageable analysis of complex multi-system environments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses a universal analysis framework that can be applied across multiple network systems with consistent methodology. By establishing standardized analysis procedures and data structures, the system efficiently handles multi-system analysis without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8020194B2Analyzing cross-machine privilege elevation pathways in a networked computing environment
Publication Date: 2011.09.13 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8020194B2 patent drawing
  • US8020194B2 patent drawing
  • US8020194B2 patent drawing

AI summary

A privilege elevation flaw detection analysis is performed on a host system on a network. In addition, accounts on the host system are identified that have access to, or corresponding accounts on, other systems on the network. Privilege elevation analyses are performed on one or more of the network systems corresponding to the identified accounts. A privilege elevation graph is generated of the host system from the privilege elevation analysis. The graph includes account nodes and edges illustrating the detected privilege elevations between the accounts on the host system. In addition, nodes for the network systems are added to the graphs along with edges connecting to the nodes corresponding to the accounts identified as having access to the particular network systems. The user may then select a particular network system node and view its detected privilege elevations in relation to the host system.