Advanced detection of identity-based attacks to assure identity fidelity in information technology environments
A system and method for the detection and mitigation of Kerberos golden ticket, silver ticket, and related identity-based cyberattacks by passively monitoring and analyzing Kerberos and authentication operations within the network. The system and method provide real-time detections of identity attacks using time-series data and data pipelines, and by transforming the stateless Kerberos protocol into stateful protocol. A packet capturing agent is deployed on the network where captured time-series Kerberos and related event and log information is processed in distributed computational graph (DCG) stages where declarative rules determine if an attack is being carried out and what type of attack it is.
1 . A system for detection of network cybersecurity events using stateful authentication, comprising:
a memory storing instructions to be executed by one or more hardware processors; and
one or more hardware processors configured to execute the instructions stored in the memory, wherein the instructions, when executed by the one or more hardware processors, cause the system to:
retrieve a plurality of cyber-physical information associated with a network, wherein the cyber-physical information comprises authentication event data associated with an authentication protocol transaction for one or more clients, services, individuals, users, physical devices, or key distribution centers;
create a knowledge graph representing the network based on the retrieved cyber-physical information, wherein the knowledge graph comprises:
nodes representing the clients, services, individuals, users, physical devices or key distribution centers associated with the network; and
edges connecting two or more nodes, wherein the edges represent the authentication event data associated with the authentication protocol transaction between the two or more nodes connected by the respective edge;
maintain a ledger of exchanges that occur as part of the authentication protocol transactions, wherein entries in the ledger link steps of the authentication protocol transactions such that state of the authentication protocol transactions is detectable; and
identify cybersecurity attacks by detecting the state of the authentication protocol transactions based on the plurality of cyber-physical information in the knowledge graph.
2 . The system of claim 1 , wherein the instructions, when executed by the one or more hardware processors, further cause the system to:
build a subgraph for each individual or user within the knowledge graph;
determine a pattern of authentications for each individual or user based on the respective subgraph; and
identify credential theft by comparing a current individual or user authentication transaction against the pattern of authentications for the current individual or user to detect anomalous authentication behavior.
3 . The system of claim 1 , wherein the cyber-physical information further comprises reachability properties for each node in the knowledge graph.
4 . The system of claim 3 , wherein the reachability properties for each node are represented as an edge connecting a first node to one or more other nodes based on the reachability properties.
5 . The system of claim 1 , wherein the instructions, when executed by the one or more hardware processors, further cause the system to:
create a graph of networks, wherein the graph of networks comprises network nodes representing entire networks and edges representing events that occur between and among network nodes; and
wherein the knowledge graph is represented as a node in the graph of networks.
6 . The system of claim 1 , wherein a distributed computational graph is employed for event-driven and stream-processing detection of the state of the authentication protocol transaction.
7 . The system of claim 1 , wherein the edges further comprise time and date information associated with the authentication protocol transaction between the two or more nodes connected by the respective edge.
8 . The system of claim 1 , wherein the edges further comprise Internet Protocol (IP) information associated with the authentication protocol transaction between the two or more nodes connected by the respective edge.
9 . The system of claim 1 , wherein the edges further comprise hash and encryption information associated with the authentication protocol transaction between the two or more nodes connected by the respective edge.
10 . A method for detection of network cybersecurity events using stateful authentication, comprising the steps of:
retrieving a plurality of cyber-physical information associated with a network, wherein the cyber-physical information comprises authentication event data associated with an authentication protocol transaction for one or more clients, services, individuals, users, physical devices, or key distribution centers;
creating a knowledge graph representing the network based on the retrieved cyber-physical information, wherein the knowledge graph comprises:
nodes representing the clients, services, individuals, users, physical devices or key distribution centers associated with the network; and
edges connecting two or more nodes, wherein the edges represent the authentication event data associated with the authentication protocol transaction between the two or more nodes connected by the respective edge;
maintaining a ledger of exchanges that occur as part of the authentication protocol transactions, wherein entries in the ledger link steps of the authentication protocol transactions such that state of the authentication protocol transactions is detectable; and
identifying cybersecurity attacks by detecting the state of the authentication protocol transactions based on the plurality of cyber-physical information in the knowledge graph.
11 . The method of claim 10 , further comprising the steps of:
building a subgraph for each individual or user within the knowledge graph;
determining a pattern of authentications for each individual or user based on the respective subgraph; and
identifying credential theft by comparing a current individual or user authentication transaction against the pattern of authentications for the current individual or user to detect anomalous authentication behavior.
12 . The method of claim 10 , wherein the cyber-physical information further comprises reachability properties for each node in the knowledge graph.
13 . The method of claim 12 , wherein the reachability properties for each node are represented as an edge connecting a first node to one or more other nodes based on the reachability properties.
14 . The method of claim 10 , further comprising the steps of:
creating a graph of networks, wherein the graph of networks comprises network nodes representing entire networks and edges representing events that occur between and among network nodes; and
wherein the knowledge graph is represented as a node in the graph of networks.
15 . The method of claim 10 , wherein a distributed computational graph is employed for event-driven and stream-processing detection of the state of the authentication protocol transaction.
16 . The method of claim 10 , wherein the edges further comprise time and date information associated with the authentication protocol transaction between the two or more nodes connected by the respective edge.
17 . The method of claim 10 , wherein the edges further comprise Internet Protocol (IP) information associated with the authentication protocol transaction between the two or more nodes connected by the respective edge.
18 . The method of claim 10 , wherein the edges further comprise hash and encryption information associated with the authentication protocol transaction between the two or more nodes connected by the respective edge.