IP Library Granted Patent US 12,641,123
Granted Patent B2
US 12,641,123 · App. 17/960,081 · Granted May 26, 2026

Advanced detection of identity-based attacks to assure identity fidelity in information technology environments

Inventors: Jason Crabtree (Vienna, VA); Richard Kelley (Woodbridge, VA)
Assignee: QOMPLX LLC
H04L63/20G06F16/2477G06F16/951H04L63/1425H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,641,123
App. No.
17/960,081
Granted
May 26, 2026
Kind
B2
Abstract

A system and method for the detection and mitigation of Kerberos golden ticket, silver ticket, and related identity-based cyberattacks by passively monitoring and analyzing Kerberos and authentication operations within the network. The system and method provide real-time detections of identity attacks using time-series data and data pipelines, and by transforming the stateless Kerberos protocol into stateful protocol. A packet capturing agent is deployed on the network where captured time-series Kerberos and related event and log information is processed in distributed computational graph (DCG) stages where declarative rules determine if an attack is being carried out and what type of attack it is.

Claims (42)

1 . A system for detection of network cybersecurity events using stateful authentication, comprising:

a memory storing instructions to be executed by one or more hardware processors; and

one or more hardware processors configured to execute the instructions stored in the memory, wherein the instructions, when executed by the one or more hardware processors, cause the system to:

retrieve a plurality of cyber-physical information associated with a network, wherein the cyber-physical information comprises authentication event data associated with an authentication protocol transaction for one or more clients, services, individuals, users, physical devices, or key distribution centers;

create a knowledge graph representing the network based on the retrieved cyber-physical information, wherein the knowledge graph comprises:

nodes representing the clients, services, individuals, users, physical devices or key distribution centers associated with the network; and

edges connecting two or more nodes, wherein the edges represent the authentication event data associated with the authentication protocol transaction between the two or more nodes connected by the respective edge;

maintain a ledger of exchanges that occur as part of the authentication protocol transactions, wherein entries in the ledger link steps of the authentication protocol transactions such that state of the authentication protocol transactions is detectable; and

identify cybersecurity attacks by detecting the state of the authentication protocol transactions based on the plurality of cyber-physical information in the knowledge graph.

2 . The system of claim 1 , wherein the instructions, when executed by the one or more hardware processors, further cause the system to:

build a subgraph for each individual or user within the knowledge graph;

determine a pattern of authentications for each individual or user based on the respective subgraph; and

identify credential theft by comparing a current individual or user authentication transaction against the pattern of authentications for the current individual or user to detect anomalous authentication behavior.

3 . The system of claim 1 , wherein the cyber-physical information further comprises reachability properties for each node in the knowledge graph.

4 . The system of claim 3 , wherein the reachability properties for each node are represented as an edge connecting a first node to one or more other nodes based on the reachability properties.

5 . The system of claim 1 , wherein the instructions, when executed by the one or more hardware processors, further cause the system to:

create a graph of networks, wherein the graph of networks comprises network nodes representing entire networks and edges representing events that occur between and among network nodes; and

wherein the knowledge graph is represented as a node in the graph of networks.

6 . The system of claim 1 , wherein a distributed computational graph is employed for event-driven and stream-processing detection of the state of the authentication protocol transaction.

7 . The system of claim 1 , wherein the edges further comprise time and date information associated with the authentication protocol transaction between the two or more nodes connected by the respective edge.

8 . The system of claim 1 , wherein the edges further comprise Internet Protocol (IP) information associated with the authentication protocol transaction between the two or more nodes connected by the respective edge.

9 . The system of claim 1 , wherein the edges further comprise hash and encryption information associated with the authentication protocol transaction between the two or more nodes connected by the respective edge.

10 . A method for detection of network cybersecurity events using stateful authentication, comprising the steps of:

retrieving a plurality of cyber-physical information associated with a network, wherein the cyber-physical information comprises authentication event data associated with an authentication protocol transaction for one or more clients, services, individuals, users, physical devices, or key distribution centers;

creating a knowledge graph representing the network based on the retrieved cyber-physical information, wherein the knowledge graph comprises:

nodes representing the clients, services, individuals, users, physical devices or key distribution centers associated with the network; and

edges connecting two or more nodes, wherein the edges represent the authentication event data associated with the authentication protocol transaction between the two or more nodes connected by the respective edge;

maintaining a ledger of exchanges that occur as part of the authentication protocol transactions, wherein entries in the ledger link steps of the authentication protocol transactions such that state of the authentication protocol transactions is detectable; and

identifying cybersecurity attacks by detecting the state of the authentication protocol transactions based on the plurality of cyber-physical information in the knowledge graph.

11 . The method of claim 10 , further comprising the steps of:

building a subgraph for each individual or user within the knowledge graph;

determining a pattern of authentications for each individual or user based on the respective subgraph; and

identifying credential theft by comparing a current individual or user authentication transaction against the pattern of authentications for the current individual or user to detect anomalous authentication behavior.

12 . The method of claim 10 , wherein the cyber-physical information further comprises reachability properties for each node in the knowledge graph.

13 . The method of claim 12 , wherein the reachability properties for each node are represented as an edge connecting a first node to one or more other nodes based on the reachability properties.

14 . The method of claim 10 , further comprising the steps of:

creating a graph of networks, wherein the graph of networks comprises network nodes representing entire networks and edges representing events that occur between and among network nodes; and

wherein the knowledge graph is represented as a node in the graph of networks.

15 . The method of claim 10 , wherein a distributed computational graph is employed for event-driven and stream-processing detection of the state of the authentication protocol transaction.

16 . The method of claim 10 , wherein the edges further comprise time and date information associated with the authentication protocol transaction between the two or more nodes connected by the respective edge.

17 . The method of claim 10 , wherein the edges further comprise Internet Protocol (IP) information associated with the authentication protocol transaction between the two or more nodes connected by the respective edge.

18 . The method of claim 10 , wherein the edges further comprise hash and encryption information associated with the authentication protocol transaction between the two or more nodes connected by the respective edge.

Assignments (5)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 17, 2023
From: CRABTREE, JASON; KELLEY, RICHARD
To: QOMPLX, INC.
Reel/Frame 064282/0648 →
Continuity (67)
Continuation In Part 17567060 · Dec 31, 2021
Continuation In Part 17389863 · Jul 30, 2021
Continuation 16792754 · Feb 17, 2020
Continuation In Part 16779801 · Feb 3, 2020
Continuation In Part 16777270 · Jan 30, 2020
Continuation In Part 16720383 · Dec 19, 2019
Continuation 15823363 · Nov 27, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 17170288 · Feb 8, 2021
Continuation In Part 17169924 · Feb 8, 2021
Continuation In Part 15837845 · Dec 11, 2017
Continuation In Part 15825350 · Nov 29, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 17102561 · Nov 24, 2020
Continuation 15790457 · Oct 23, 2017
Continuation In Part 15790327 · Oct 23, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 17000504 · Aug 24, 2020
Continuation In Part 16855724 · Apr 22, 2020
Continuation In Part 16836717 · Mar 31, 2020
Continuation In Part 15887496 · Feb 2, 2018
Continuation In Part 15823285 · Nov 27, 2017
Continuation In Part 15788718 · Oct 19, 2017
Continuation In Part 15788002 · Oct 19, 2017
Continuation In Part 15787601 · Oct 18, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15818733 · Nov 20, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 16777270 · Jan 30, 2020
Continuation In Part 16412340 · May 14, 2019
Continuation In Part 16267893 · Feb 5, 2019
Continuation In Part 16248133 · Jan 15, 2019
Continuation In Part 15849901 · Dec 21, 2017
Continuation In Part 15835436 · Dec 7, 2017
Continuation In Part 15790457 · Oct 23, 2017
Continuation In Part 15835312 · Dec 7, 2017
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15813097 · Nov 14, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15806697 · Nov 8, 2017
Continuation In Part 15376657 · Dec 13, 2016
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15343209 · Nov 4, 2016
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15229476 · Aug 5, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15673368 · Aug 9, 2017
Continuation In Part 15376657 · Dec 13, 2016
Provisional Application 62596105 · Dec 7, 2017
Provisional Application 62568291 · Oct 4, 2017
Provisional Application 62568298 · Oct 4, 2017
Provisional Application 62568312 · Oct 4, 2017
Provisional Application 62568305 · Oct 4, 2017
Provisional Application 62568307 · Oct 4, 2017
Related Publication 20230113332A1 · Apr 13, 2023
References Cited (55)
US 5669000A · Jessen et al. · 1997 [cited by applicant]
US 6256544B1 · Weissinger · 2001 [cited by applicant]
US 7072863B1 · Phillips et al. · 2006 [cited by applicant]
US 7657406B2 · Tolone et al. · 2010 [cited by applicant]
US 7698213B2 · Lancaster · 2010 [cited by applicant]
US 7739653B2 · Venolia · 2010 [cited by applicant]
US 8065257B2 · Kuecuekyan · 2011 [cited by applicant]
US 8145761B2 · Liu et al. · 2012 [cited by applicant]
US 8281121B2 · Nath et al. · 2012 [cited by applicant]
US 8615800B2 · Baddour et al. · 2013 [cited by applicant]
US 8788306B2 · Delurgio et al. · 2014 [cited by applicant]
US 8793758B2 · Raleigh et al. · 2014 [cited by applicant]
US 8914878B2 · Burns et al. · 2014 [cited by applicant]
US 8997233B2 · Green et al. · 2015 [cited by applicant]
US 9134966B2 · Brock et al. · 2015 [cited by applicant]
US 9141360B1 · Chen et al. · 2015 [cited by applicant]
US 9602530B2 · Ellis et al. · 2017 [cited by applicant]
US 9654495B2 · Hubbard et al. · 2017 [cited by applicant]
US 9672355B2 · Titonis et al. · 2017 [cited by applicant]
US 9762443B2 · Dickey · 2017 [cited by applicant]
US 9807104B1 · Sarra · 2017 [cited by applicant]
US 9887933B2 · Lawrence, III · 2018 [cited by applicant]
US 9916133B2 · Jubran et al. · 2018 [cited by applicant]
US 9946517B2 · Talby et al. · 2018 [cited by applicant]
US 10015175B2 · Kent et al. · 2018 [cited by applicant]
US 10061635B2 · Ellwein · 2018 [cited by applicant]
US 10102480B2 · Dirac et al. · 2018 [cited by applicant]
US 10205735B2 · Apostolopoulos · 2019 [cited by applicant]
US 10210246B2 · Stojanovic et al. · 2019 [cited by applicant]
US 10210255B2 · Crabtree et al. · 2019 [cited by applicant]
US 10248910B2 · Crabtree et al. · 2019 [cited by applicant]
US 10318882B2 · Brueckner et al. · 2019 [cited by applicant]
US 10367829B2 · Huang et al. · 2019 [cited by applicant]
US 10387631B2 · Duggal et al. · 2019 [cited by applicant]
US 10515366B1 · Gorelik et al. · 2019 [cited by applicant]
US 10742667B1 · Stern et al. · 2020 [cited by applicant]
US 20050289072A1 · Sabharwal · 2005 [cited by applicant]
US 20100082493A1 · Agrawal et al. · 2010 [cited by applicant]
US 20100115276A1 · Betouin et al. · 2010 [cited by applicant]
US 20130304623A1 · Kumar et al. · 2013 [cited by applicant]
US 20140279762A1 · Xaypanya et al. · 2014 [cited by applicant]
US 20140380427A1 · Srinivasan et al. · 2014 [cited by applicant]
US 20150249669A1 · Gamage et al. · 2015 [cited by applicant]
US 20160004858A1 · Chen et al. · 2016 [cited by applicant]
US 20160065565A1 · Plotnik et al. · 2016 [cited by applicant]
US 20160099960A1 · Gerritz et al. · 2016 [cited by applicant]
US 20160140519A1 · Trepca et al. · 2016 [cited by applicant]
US 20160275123A1 · Lin et al. · 2016 [cited by applicant]
US 20160330233A1 · Hart · 2016 [cited by applicant]
US 20160364307A1 · Garg et al. · 2016 [cited by applicant]
US 20170124464A1 · Crabtree et al. · 2017 [cited by applicant]
US 20170244730A1 · Sancheti et al. · 2017 [cited by applicant]
US 20170364450A1 · Struttmann · 2017 [cited by examiner]
US 20200014659A1 · Chasman et al. · 2020 [cited by applicant]
US 20230113332A1 · Crabtree · 2023 [cited by examiner]