The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Mar. 30, 2021

Filed:

Jun. 04, 2020
Applicant:

Cyberark Software Ltd., Petach-Tikva, IL;

Inventor:

Eran Shimony, Petach-Tikva, IL;

Assignee:

CyberArk Software Ltd., Petach-Tikva, IL;

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/62 (2013.01); G06F 21/57 (2013.01); G06F 21/56 (2013.01);
U.S. Cl.
CPC ...
G06F 21/6218 (2013.01); G06F 21/565 (2013.01); G06F 21/568 (2013.01); G06F 21/577 (2013.01);
Abstract

Disclosed embodiments relate to systems and methods for dynamically identifying potential file system privilege escalation and manipulation vulnerabilities. Techniques include monitoring a file system of a computing system; detecting a privileged file operation involving the file system; determining that a target of the path is writable by a non-privileged identity; and determining whether the target of the path is a dynamic link library. If the target of the path is a dynamic link library, techniques may further include creating a semi-malicious dynamic link library. If the target of the path is not a dynamic link library, techniques may further include creating an object manager symbolic link in a protected file.


Find Patent Forward Citations

Loading…