IP Library Granted Patent US 11,818,150
Granted Patent B2
US 11,818,150 · App. 17/975,548 · Granted Nov 14, 2023

System and methods for detecting and mitigating golden SAML attacks against federated services

Inventors: Randy Clayton (Frederick, MD); Jason Crabtree (Vienna, VA); Luka Jurukovski (Arlington, VA); Richard Kelley (Woodbridge, VA); Angadbir Singh Salaria (Herndon, VA); Andrew Sellers (Monument, CO); Farooq Israr Ahmed Shaikh (Reston, VA)
Assignee: QOMPLX LLC
H04L63/1416H04L63/0876H04L63/1425H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,818,150
App. No.
17/975,548
Granted
Nov 14, 2023
Kind
B2
Abstract

A system and methods for detecting and mitigating golden SAML attacks against federated services is provided, comprising an authentication object inspector configured to observe a new authentication object generated by an identity provider, and retrieve the new authentication object; and a hashing engine configured to create a security cookie for each valid authentication session; wherein subsequent access requests accompanied by authentication objects are validated by checking for a valid security cookie.

Claims (38)

1. A system for detecting and mitigating golden Security Assertion Markup Language (SAML) attacks against federated services, comprising:

a computing device comprising a memory and a processor;

an authentication object inspector comprising a first plurality of programming instructions stored in the memory which, when operating on the processor, causes the computing device to:

receive network traffic comprising a plurality of network packets, the plurality of network packets comprising a first authentication object for a user of a federated service, the first authentication object comprising a first identification string known to be generated by an identity provider associated with the federated service;

store a record of the first authentication object, with attached metadata comprising a timestamp of when the first authentication object was received, in a time-series database;

generate a security cookie for the first authentication object;

provide the security cookie to the identity provider from which the first authentication object was generated for inclusion in additional authentication objects issued to the user;

receive a request for access to the federated service by the user accompanied by a second authentication object comprising a second identification string and the security cookie;

compare a value of the second identification string of the second authentication object against a value of the second identification string of the stored record of the first authentication object;

check the second authentication object for the security cookie; and

generate an authentication failure if the security cookie is missing or invalid.

2. The system of claim 1 , further comprising a hashing engine comprising a second plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the second plurality of programmable instructions, when operating on the processor, cause the computing device to:

receive authentication objects from the authentication object inspector;

calculate security cookies for authentication objects received by performing a plurality of calculations and transformations on each authentication object received; and

return the security cookies for authentication objects received to the authentication object inspector.

3. The system of claim 1 , wherein the authentication object inspector is operated by the identity provider.

4. The system of claim 2 , wherein the authentication object inspector is operated by the identity provider.

5. The system of claim 1 , wherein the authentication object inspector is operated by a client device communicating with the identity provider over a network.

6. The system of claim 2 , wherein the authentication object inspector is operated by a client device communicating with the identity provider over a network.

7. A method for detecting and mitigating golden Security Assertion Markup Language (SAML) attacks against federated services, comprising:

using an authentication object inspector operating on a computing device comprising a memory and a processor to:

receive network traffic comprising a plurality of network packets, the plurality of network packets comprising a first authentication object for a user of a federated service, the first authentication object comprising a first identification string known to be generated by an identity provider associated with the federated service;

store a record of the first authentication object, with attached metadata comprising a timestamp of when the first authentication object was received, in a time-series database;

generate a security cookie for the first authentication object;

provide the security cookie to the identity provider from which the first authentication object was generated for inclusion in additional authentication objects issued to the user;

receive a request for access to the federated service by the user accompanied by a second authentication object comprising a second identification string and the security cookie;

compare a value of the second identification string of the second authentication object against a value of the second identification string of the stored record of the first authentication object;

check the second authentication object for the security cookie; and

generate an authentication failure if the security cookie is missing or invalid.

8. The method of claim 7 , further comprising the steps of:

using a hashing engine operating on a computing device comprising a memory and a processor to:

receive authentication objects from the authentication object inspector;

calculate security cookies for authentication objects received by performing a plurality of calculations and transformations on each authentication object received; and

return the security cookies for authentication objects received to the authentication object inspector.

9. The method of claim 7 , wherein the authentication object inspector is operated by the identity provider.

10. The method of claim 8 , wherein the authentication object inspector is operated by the identity provider.

11. The method of claim 7 , wherein the authentication object inspector is operated by a client device communicating with the identity provider over a network.

12. The method of claim 8 , wherein the authentication object inspector is operated by a client device communicating with the identity provider over a network.

Assignments (6)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY DATA PREVIOUSLY RECORDED ON REEL 064428 FRAME 0917. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 18, 2024
From: CLAYTON, RANDY; CRABTREE, JASON; JURUKOVSKI, LUKA; KELLEY, RICHARD; SALARIA, ANGADBIR SINGH; SELLERS, ANDREW; SHAIKH, FAROOQ ISRAR AHMED
To: QOMPLX, INC.
Reel/Frame 066343/0533 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2023
From: CLAYTON, RANDY; CRABTREE, JASON; JURUKOVSKI, LUKA; KELLY, RICHARD; SALARIA, ANGADBIR SINGH; SELLERS, ANDREW; SHAIKH, FAROOQ ISRAR AHMED
To: QOMPLX, INC.
Reel/Frame 064428/0917 →
Continuity (17)
Continuation 17163073 · Jan 29, 2021
Continuation In Part 15837845 · Dec 11, 2017
Continuation In Part 15825350 · Nov 29, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 14925974 · Oct 28, 2015
Provisional Application 62596105 · Dec 7, 2017
Related Publication 20230118726A1 · Apr 20, 2023