IP Library Granted Patent US 11,757,849
Granted Patent B2
US 11,757,849 · App. 17/361,715 · Granted Sep 12, 2023

Detecting and mitigating forged authentication object attacks in multi-cloud environments

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO)
Assignee: QOMPLX, INC.
H04L63/0428H04L9/3236H04L9/3239H04L63/0807H04L63/0815H04L63/145H04L63/1425H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,757,849
App. No.
17/361,715
Filed
Jun 29, 2021
Granted
Sep 12, 2023
Kind
B2
Art Unit
2493
USPC
713/180
Abstract

A system for detecting and mitigating forged authentication object attacks in federated environments is provided, comprising an event inspector to monitor logs and detect vulnerable events, an authentication object inspector configured to observe a new authentication object generated by an identity provider, and intercept the new authentication object; and a hashing engine configured to calculate a cryptographic hash for the new authentication object, and store the cryptographic hash for the new authentication object in the SAML response; wherein subsequent access requests accompanied by authentication objects are validated by comparing hashes for each authentication object to previous generated hashes.

Claims (28)

1. A system for detecting and mitigating forged authentication object attacks in federated environments, comprising:

an authentication object inspector comprising a first plurality of programming instructions stored in a memory of, and operating on a processor of, a computing device, wherein the first plurality of programmable instructions, when operating on the processor, cause the computing device to:

receive an authentication object known to be generated by an identity provider;

calculate a cryptographic hash of the authentication object using a hashing engine;

store the cryptographic hash in the authentication object;

forward the authentication object to the service provider; and

where the hash of the authentication object does not exist in the authentication object received by the service provider, generate a notification that the authentication object may be forged; and

an event inspector comprising a second plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the third plurality of programmable instructions, when operating on the processor, cause the computing device to:

monitor a plurality of service provider logs for a successful login event or a certificate export event;

identify one or more entities associated with the successful login event or a certificate export event;

search a plurality of security event logs from the one or more associated entities for corresponding events to determine if the successful login event is legitimate; and

trigger the execution of one or more commands as dictated in a plurality of predefined rules upon detection of an illegitimate login event or a certificate export event.

2. The system of claim 1 , wherein, upon detection of an invalid authentication object, an administrative user is notified, and provided with access data associated with the invalid authentication object.

3. The system of claim 2 , wherein at least a portion of the access data comprises resources accessed by the owner of the invalid authentication object.

4. The system of claim 2 , wherein at least a portion of the access data comprises blast radius data associated with the owner of the invalid authentication object.

5. A method for detecting and mitigating forged authentication object attacks in federated environments, comprising the steps of:

receiving an authentication object known to be generated by an identity provider;

calculating a cryptographic hash of the authentication object using a hashing engine;

storing the cryptographic hashes in the authentication object;

forwarding the authentication object to the service provider

where the hash of the authentication object does not exist in the authentication object received by the service provider, generating a notification that the authentication object may be forged;

monitoring a plurality of service provider logs for a successful login event or a certificate export event;

identifying one or more entities associated with the successful login event or a certificate export event;

searching a plurality of security event logs from the one or more associated entities for corresponding events to determine if the successful login event is legitimate; and

triggering the execution of one or more commands as dictated in a plurality of predefined rules upon detection of an illegitimate login event or a certificate export event.

6. The method of claim 1 , wherein, upon detection of an invalid authentication object, an administrative user is notified, and provided with access data associated with the invalid authentication object.

7. The method of claim 6 , wherein at least a portion of the access data comprises resources accessed by the owner of the invalid authentication object.

8. The method of claim 6 , wherein at least a portion of the access data comprises blast radius data associated with the owner of the invalid authentication object.

Assignments (5)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 17, 2022
From: CRABTREE, JASON; SELLERS, ANDREW
To: QOMPLX, INC.
Reel/Frame 059924/0325 →
Continuity (17)
Continuation In Part 17245162 · Apr 30, 2021
Continuation 15837845 · Dec 11, 2017
Continuation In Part 15825350 · Nov 29, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Provisional Application 62596105 · Dec 7, 2017
Related Publication 20220060453A1 · Feb 24, 2022
Cited By (1)
US 12,242,602