首页> 外国专利> Protecting a computer device from escalation of privilege attacks

Protecting a computer device from escalation of privilege attacks

机译:保护计算机设备免受特权攻击的升级

摘要

A computer device has a kernel driver in a kernel mode of the operating system which records an access token as initially associated with a user process. Later, the user process presents its access token when requesting certain operations through the operating system. The kernel driver detects that the user process has been subject to an escalation of privilege attack by evaluating the access token in its presented form as against the initially recorded access token and, in response, performs a mitigation action such as suspending the user process.
机译:计算机设备在操作系统的内核模式下具有内核驱动程序,该内核驱动程序将访问令牌记录为最初与用户进程相关联。稍后,当通过操作系统请求某些操作时,用户进程将显示其访问令牌。内核驱动程序通过相对于最初记录的访问令牌评估其呈现形式的访问令牌来检测用户进程是否受到特权攻击,并作为响应执行缓解操作,如暂停用户进程。

著录项

  • 公开/公告号GB201806289D0

    专利类型

  • 公开/公告日2018-05-30

    原文格式PDF

  • 申请/专利权人 AVECTO LIMITED;

    申请/专利号GB20180006289

  • 发明设计人

    申请日2018-04-18

  • 分类号G06F21/55;G06F21/57;

  • 国家 GB

  • 入库时间 2022-08-21 12:32:31

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号