IP Library Granted Patent US 11,528,286
Granted Patent B2
US 11,528,286 · App. 15/931,285 · Granted Dec 13, 2022

Network vulnerability detection

Inventors: Jacques Louw (Helsinki, FI); Keith Kirton (Helsinki, FI)
Assignee: WITHSECURE CORPORATION
H04L63/1425H04L61/4523H04L63/1433H04L67/1097
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,528,286
App. No.
15/931,285
Granted
Dec 13, 2022
Kind
B2
Abstract

A method for monitoring a directory environment of a computer network to detect vulnerabilities. The method comprises, at a first computer on the computer network, changing a configuration of the directory environment and, with a replication service, replicating the change at a second computer on the computer network. The method further comprises extracting information relating to the change from the replication service and using the extracted information to detect a vulnerability in the directory environment.

Claims (60)

1. A method for monitoring a directory environment of a computer network to detect vulnerabilities, the method comprising:

at a first computer on the computer network changing a configuration of the directory environment;

with a replication service, replicating the change at a second computer on the computer network;

extracting information relating to the change from a single replication service, the single replication service comprising the replication service;

detecting a vulnerability in the directory environment from the extracted information; and

repeating the steps of:

changing the configuration,

replicating the change with the replication service,

extracting the information relating to the change from the replication service, and

detecting the vulnerability in the directory environment from the extracted information,

until the vulnerability is eliminated.

2. The method according to claim 1 , wherein the first computer is a first domain controller and wherein the second computer is a second domain controller.

3. The method according to claim 1 , wherein the step of extracting the information from the replication service is performed at intervals of 1-60 seconds, preferably at intervals of 1-5 seconds.

4. The method according to claim 1 , comprising generating a representation of the directory environment, and

wherein the step of detecting a vulnerability comprises updating the representation using the extracted information relating to the change.

5. The method according to claim 4 , wherein the step of generating the representation of the directory environment comprises extracting information relating to all directory objects in the directory environment at a first time before said step of changing a configuration is performed.

6. The method according to claim 1 , wherein:

the vulnerability is a control path in the directory environment; and

the vulnerability is eliminated when the change closes the control path.

7. The method according to claim 1 , wherein the step of extracting the information from the replication service is initiated by a backend system of a security service provider, and

wherein the step of detecting the vulnerability is performed by the backend system.

8. The method according to claim 7 , comprising displaying a warning at the backend system when the vulnerability is detected.

9. A system for monitoring a directory environment of a computer network to detect vulnerabilities, the system comprising:

one or more processors; and

one or more computer-readable memories storing computer program code, the one or more processors being configured to execute the computer program code to cause the one or more processors at least to:

send instructions to one or more computers on the computer network to extract and return from a replication service information relating to a change of a configuration of the directory environment,

detect a vulnerability in the directory environment from extracted information from a single replication service, the single replication service comprising the replication service,

repeat the steps of:

changing the configuration,

replicating the change with the replication service,

extracting the information relating to the change from the replication service, and

detecting the vulnerability in the directory environment from the extracted information,

until the vulnerability is eliminated.

10. The system according to claim 9 , wherein the instructions cause the one or more computers to extract and return the information from the replication service at intervals of 1-60 seconds, preferably at intervals of 1-5 seconds.

11. The system according to claim 9 , wherein the computer program code further causes the one or more processors to perform a step of generating a representation of the directory environment, and

wherein the step of detecting a vulnerability comprises updating the representation using the extracted information relating to the change.

12. The system according to claim 9 , wherein the computer program code further causes the one or more processors to perform a step of sending instructions to the one or more computers to extract and return information relating to all directory objects in the directory environment at a first time before the change of the configuration.

13. The system according to claim 9 , wherein:

the vulnerability is a control path in the directory environment; and

the vulnerability is eliminated when the change closes the control path.

14. The system according to claim 9 , wherein:

the one or more processors; and

the one or more computer-readable memories are provided as a backend system of a security service provider.

15. The system according to claim 14 , wherein the computer program code further causes the one or more processors to cause a warning to be displayed at the backend system when the vulnerability is detected.

16. A system for extracting and returning information from a replication service, the system comprising:

one or more processors; and

one or more computer-readable memories storing computer program code, the one or more processors being configured to execute the computer program code to cause the one or more processors at least to:

extract from the replication service information relating to a change of a configuration of a directory environment,

detect a vulnerability in the directory environment from extracted information from a single replication service, the single replication service comprising the replication service,

repeat the steps of:

changing the configuration,

replicating the change with the replication service,

extracting the information relating to the change from the replication service, and

detecting the vulnerability in the directory environment from the extracted information,

until the vulnerability is eliminated.

17. The system according to claim 16 , wherein:

the one or more processors; and

the one or more computer-readable memories are provided as a client-side system of a security service provider.

18. The system according to claim 17 , wherein the computer program code further causes the one or more processors to cause a warning to be displayed at the client-side system responsive to detecting the vulnerability in the directory environment.

19. The method according to claim 1 , wherein the directory environment is an active directory environment.

Assignments (2)
CHANGE OF NAME Recorded Jun 7, 2022
From: F-SECURE CORPORATION (A/K/A F-SECURE CORPORATION OYJ)
To: WITHSECURE CORPORATION (A/K/A WITHSECURE OYJ)
Reel/Frame 060302/0690 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2021
From: LOUW, JACQUES; KIRTON, KEITH
To: F-SECURE CORPORATION
Reel/Frame 057349/0715 →
Priority Claims (1)
GB 1906770 · May 14, 2019 · national
Continuity (1)
Related Publication 20200366695A1 · Nov 19, 2020