IP Library Granted Patent US 12,113,831
Granted Patent B2
US 12,113,831 · App. 17/363,866 · Granted Oct 8, 2024

Privilege assurance of enterprise computer network environments using lateral movement detection and prevention

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO); Richard Kelley (Woodbridge, VA)
Assignee: QOMPLX LLC
H04L63/20G06F16/2477G06F16/951H04L63/1425H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,113,831
App. No.
17/363,866
Filed
Jun 30, 2021
Granted
Oct 8, 2024
Kind
B2
Art Unit
2493
USPC
726/22
Abstract

A system and method for the privilege assurance of enterprise computer network environments using lateral movement detection and prevention. The system uses local session monitors to monitor logon sessions within a network, generating and verifying event logs and authentication records to ensure the legitimacy of authenticated user sessions and to revoke credentials when an illicit session is detected, halting lateral movement in real-time.

Claims (34)

1. A system for privilege assurance of enterprise computer network environments using lateral movement detection and prevention, comprising:

a local session monitor comprising a first plurality of programming instructions stored in a memory of, and operating on a processor of, a first computing device within a computer network operating a directory access protocol, wherein the first plurality of programming instructions, when operating on the processor of the first computing device, cause the first computing device to:

receive a first plurality of session-based details for an authentication session for a user;

check the validity of the first plurality of session-based details, using a stored session configuration;

log the first plurality of session-based details;

receive a second plurality of session details;

compare the first and second pluralities of session details against a stored expected pattern to identify any mismatched data;

where invalid or mismatched information is identified in the first or second plurality of session-based details or in the comparison against a stored expected pattern, revoke authentication credentials for the authentication session and generate an event log indicating the particular session-based details that contain the invalid or mismatched information;

send the event log to a graph engine;

a graph engine comprising a second plurality of programming instructions stored in a memory of, and operating on a processor of, a second computing device, wherein the second plurality of programming instructions, when operating on the processor of the second computing device, cause the second computing device to:

receive the event log;

create and store a cyber-physical graph of the computer network using the event log, wherein the vertices of the cyber-physical graph represent directory access protocol objects and the edges of the cyber-physical graph represent the relationships between those objects;

perform a plurality of queries over time on the cyber-physical graph to identify a cyberattack parameter of interest;

receive results of the plurality of queries;

analyze the results to determine a plurality of high-risk hosts, the high-risk hosts being determined based on the number and value of user accounts associated with each object in the cyber-physical graph and its connections to neighboring objects; and

create and store a lateral movement path map comprising a plurality of identified paths involving each of the plurality of high-risk nodes.

2. The system of claim 1 , wherein the first plurality and the second plurality of session-based details comprise information about the user's granted privilege levels.

3. The system of claim 1 , wherein the first plurality and the second plurality of session-based details comprise historical user activity within the computer network.

4. A method for privilege assurance of enterprise computer network environments using lateral movement detection and prevention, comprising the steps of:

receiving a first plurality of session-based details for an authentication session for a user;

checking the validity of the first plurality of session-based details, using a stored session configuration;

logging the first plurality of session-based details;

receiving a second plurality of session details;

comparing the first and second pluralities of session details against a stored expected pattern to identify any mismatched data;

where invalid or mismatched information is identified in the first or second plurality of session-based details or in the comparison against a stored expected pattern, revoking authentication credentials for the session and generating an event log indicating the particular session-based details that contain the invalid or mismatched information;

sending the event log to a graph engine;

receiving the event log;

creating and store a cyber-physical graph of a computer network using the event log, wherein the vertices of the cyber-physical graph represent directory access protocol objects and the edges of the cyber-physical graph represent the relationships between those objects;

performing a plurality of queries over time on the cyber-physical graph to identify a cyberattack parameter of interest;

receiving results of the plurality of queries;

analyzing the results to determine a plurality of high-risk hosts, the high-risk hosts being determined based on the number and value of user accounts associated with each object in the cyber-physical graph and its connections to neighboring objects; and

creating and storing a lateral movement path map comprising a plurality of identified paths involving each of the plurality of high-risk nodes.

5. The method of claim 4 , wherein the first plurality and the second plurality of session-based details comprise information about the user's granted privilege levels.

6. The method of claim 4 , wherein the first plurality and the second plurality of session-based details comprise historical user activity within the computer network.

Assignments (5)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 7, 2022
From: CRABTREE, JASON; KELLEY, RICHARD; SELLERS, ANDREW
To: QOMPLX, INC.
Reel/Frame 059865/0671 →
Continuity (47)
Continuation In Part 17362590 · Jun 29, 2021
Continuation In Part 17330893 · May 26, 2021
Continuation In Part 17008276 · Aug 31, 2020
Continuation In Part 17000504 · Aug 24, 2020
Continuation In Part 16945743 · Jul 31, 2020
Continuation In Part 16855724 · Apr 22, 2020
Continuation In Part 16836717 · Mar 31, 2020
Continuation In Part 16777270 · Jan 30, 2020
Continuation In Part 16720383 · Dec 19, 2019
Continuation In Part 16412340 · May 14, 2019
Continuation In Part 16267893 · Feb 5, 2019
Continuation In Part 16248133 · Jan 15, 2019
Continuation In Part 15887496 · Feb 2, 2018
Continuation In Part 15849901 · Dec 21, 2017
Continuation In Part 15835436 · Dec 7, 2017
Continuation In Part 15835312 · Dec 7, 2017
Continuation 15823363 · Nov 27, 2017
Continuation In Part 15823285 · Nov 27, 2017
Continuation In Part 15818733 · Nov 20, 2017
Continuation In Part 15813097 · Nov 14, 2017
Continuation In Part 15806697 · Nov 8, 2017
Continuation In Part 15790457 · Oct 23, 2017
Continuation In Part 15790327 · Oct 23, 2017
Continuation In Part 15788718 · Oct 19, 2017
Continuation In Part 15788002 · Oct 19, 2017
Continuation In Part 15787601 · Oct 18, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15673368 · Aug 9, 2017
Continuation 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15376657 · Dec 13, 2016
Continuation In Part 15343209 · Nov 4, 2016
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15229476 · Aug 5, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Provisional Application 62568298 · Oct 4, 2017
Provisional Application 62568312 · Oct 4, 2017
Provisional Application 62568305 · Oct 4, 2017
Provisional Application 62568291 · Oct 4, 2017
Provisional Application 62568307 · Oct 4, 2017
Related Publication 20220060509A1 · Feb 24, 2022