IP Library Granted Patent US 12,107,895
Granted Patent B2
US 12,107,895 · App. 17/362,590 · Granted Oct 1, 2024

Privilege assurance of enterprise computer network environments using attack path detection and prediction

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO); Richard Kelley (Woodbridge, VA)
Assignee: QOMPLX LLC
H04L63/20G06F16/2477G06F16/951H04L63/1425H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,107,895
App. No.
17/362,590
Granted
Oct 1, 2024
Kind
B2
Abstract

A system and method for the privilege assurance of enterprise computer network environments using attack path detection and prediction. The system uses local session monitors to monitor logon sessions within a network, track session details, and log session and network host details. Cyber-physical graphs are produced and used to identify paths within the network based on the logged information, and to apply risk weighting to the identified paths and determine likely attack paths an attacker may use.

Claims (37)

1. A system for privilege assurance of enterprise computer network environments using attack path detection and prediction, comprising:

a local session monitor comprising a first plurality of programming instructions stored in a memory of, and operating on a processor of, a first computing device within a computer network operating a directory access protocol, wherein the first plurality of programming instructions, when operating on the processor of the first computing device, cause the first computing device to:

receive a plurality of session-based details for an authentication session for a user;

log the plurality of session-based details;

retrieve a plurality of host details about the first computing device;

log the plurality of host details;

monitor activity of the authentication session;

generate an event log based on the monitored activity;

send the event log to a graph engine;

a graph engine comprising a second plurality of programming instructions stored in a memory of, and operating on a processor of, a second computing device, wherein the second plurality of programming instructions, when operating on the processor of the second computing device, cause the second computing device to:

receive the event log;

retrieve the logged session-based details and host details;

create and store a cyber-physical graph of the computer network using the event log and the logged session-based details and the logged host details, wherein the vertices or nodes of the cyber-physical graph represent directory access protocol objects and the edges of the cyber-physical graph represent the relationships between those objects;

perform a plurality of queries over time on the cyber-physical graph to identify paths between the nodes;

receive results of the plurality of queries; analyze the plurality of results to determine a plurality of risk attributes associated with each of a plurality of the nodes in the graph, the risk attributes for each node being based at least in part on a determined value of the node and the node's connectivity to other nodes within any identified paths; and

create and store an attack path map comprising a plurality of identified paths that each exceed a plurality of stored risk conditions.

2. The system of claim 1 , wherein the plurality of session-based details comprises information about a user's granted privilege levels.

3. The system of claim 1 , wherein the plurality of session-based details comprises historical user activity within the network.

4. The system of claim 1 , wherein the risk attributes further comprise a context-based risk attribute.

5. The system of claim 4 , wherein the context-based risk attribute for a node within an identified path is based on a plurality of risk attributes of other nodes within the identified path.

6. A method for privilege assurance of enterprise computer network environments using attack path detection and prediction, comprising the steps of:

receiving, by a first computing device within a computer network operating a directory access protocol, a plurality of session-based details for an authentication session for a user;

logging the plurality of session-based details;

retrieving a plurality of host details about the first computing device;

logging the plurality of host details;

monitoring activity of the authentication session;

generating an event log based on the monitored activity;

sending the event log to a graph engine operating in a second computing device;

creating and storing, using the graph engine, a cyber-physical graph of the computer network using the event log and the logged session-based details and the logged host details, wherein the vertices or nodes of the cyber-physical graph represent directory access protocol objects and the edges of the cyber-physical graph represent the relationships between those objects;

performing a plurality of queries over time on the cyber-physical graph to identify paths between the nodes;

receiving results of the plurality of queries;

analyzing the plurality of results to determine a plurality of risk attributes associated with each of a plurality of the nodes in the graph, the risk attributes for each node being based at least in part on a determined value of the node and the node's connectivity to other nodes within any identified paths; and

creating and storing an attack path map comprising a plurality of identified paths that each exceed a plurality of stored risk conditions.

7. The method of claim 6 , wherein the plurality of session-based details comprises information about a user's granted privilege levels.

8. The method of claim 6 , wherein the plurality of session-based details comprises historical user activity within the network.

9. The method of claim 6 , wherein the risk attributes further comprise a context-based risk attribute.

10. The method of claim 9 , wherein the context-based risk attribute for a node within an identified path is based on a plurality of risk attributes of other nodes within the identified path.

Assignments (5)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2022
From: KELLEY, RICHARD; SELLERS, ANDREW; CRABTREE, JASON
To: QOMPLX, INC.
Reel/Frame 059744/0186 →
Continuity (58)
Continuation In Part 17330893 · May 26, 2021
Continuation In Part 17008276 · Aug 31, 2020
Continuation In Part 17000504 · Aug 24, 2020
Continuation In Part 16855724 · Apr 22, 2020
Continuation In Part 16836717 · Mar 31, 2020
Continuation In Part 15887496 · Feb 2, 2018
Continuation In Part 15823285 · Nov 27, 2017
Continuation In Part 15788718 · Oct 19, 2017
Continuation In Part 15788002 · Oct 19, 2017
Continuation In Part 15787601 · Oct 17, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 15818733 · Nov 20, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 16777270 · Jan 30, 2020
Continuation In Part 16720383 · Dec 19, 2019
Continuation 15823363 · Nov 27, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 16412340 · May 14, 2019
Continuation In Part 16267893 · Feb 5, 2019
Continuation In Part 16248133 · Jan 15, 2019
Continuation In Part 15849901 · Dec 21, 2017
Continuation In Part 15835436 · Dec 7, 2017
Continuation In Part 15790457 · Oct 23, 2017
Continuation In Part 15790327 · Oct 23, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15835312 · Dec 7, 2017
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15813097 · Nov 14, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15806697 · Nov 8, 2017
Continuation In Part 15376657 · Dec 13, 2016
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15343209 · Nov 4, 2016
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15229476 · Aug 5, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15673368 · Aug 9, 2017
Continuation In Part 15376657 · Dec 13, 2016
Continuation In Part 16945743 · Jul 31, 2020
Continuation 15655113 · Jul 20, 2017
Provisional Application 62568312 · Oct 4, 2017
Provisional Application 62568305 · Oct 4, 2017
Provisional Application 62568307 · Oct 4, 2017
Provisional Application 62568291 · Oct 4, 2017
Provisional Application 62568298 · Oct 4, 2017
Related Publication 20220060507A1 · Feb 24, 2022