IP Library Patent Application 18297500
Patent Application
App. No. 18/297,500

DETECTING AND MITIGATING FORGED AUTHENTICATION ATTACKS USING AN ADVANCED CYBER DECISION PLATFORM

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/297,500
Filed
Apr 7, 2023
Art Unit
2493
USPC
713/180
Abstract

A system for detecting and mitigating forged authentication attacks is provided, comprising an authentication inspector configured to observe a new authentication object generated by an identity provider, and retrieve the new authentication object; and a hashing engine configured to retrieve the new authentication object from the authentication object inspector, calculate a cryptographic hash for the new authentication object, and store the cryptographic hash for the new authentication object in a data store; wherein subsequent access requests accompanied by authentication objects are validated by comparing hashes for each authentication object to previous generated hashes.

Claims (25)

1 . A system for detecting and mitigating forged authentication attacks, comprising:

an authentication inspector comprising a first plurality of programming instructions stored in a memory of, and operating on a processor of, a computing device, wherein the first plurality of programmable instructions, when operating on the processor, cause the computing device to:

receive a plurality of first authentication attributes associated with a network request;

calculate a cryptographic hash of each first authentication attribute using a hashing engine;

store the cryptographic hashes of the first authentication attributes in a database of hashes;

receive a request for access to a service accompanied by a plurality of second authentication attributes;

select a plurality of the second authentication attributes;

calculate a cryptographic hash of each of the selected second authentication attributes using the hashing engine;

determine whether the request for access is forged by comparing each hash of a second authentication attribute with the hashes of the first authentication attributes stored in the database of hashes to determine whether each hash of a second authentication attribute already exists in the database; and

where a hash of a second authentication attribute does not exist in the database, generate a notification that the request for access may be forged.

2 . The system of claim 1 , further comprising a rules engine comprising a second plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the second plurality of programmable instructions, when operating on the processor, cause the computing device to:

retrieve a plurality of predefined rules from a data store upon detection of a forged authentication attribute; and

execute commands as dictated in each retrieved predefined rule.

3 . A method for detecting and mitigating forged authentication attacks, comprising the steps of:

receiving a plurality of first authentication attributes associated with a network request;

calculating a cryptographic hash of each first authentication attribute using a hashing engine;

storing the cryptographic hashes of the first authentication attributes in a database of hashes;

receiving a request for access to a service accompanied by a plurality of second authentication attributes;

selecting a plurality of the second authentication attributes;

calculating a cryptographic hash of each of the selected second authentication attributes using the hashing engine;

determining whether the request for access is forged by comparing each hash of a second authentication attribute with the hashes of the first authentication attributes stored in the database of hashes to determine whether each hash of a second authentication attribute already exists in the database; and

where a hash of a second authentication attribute does not exist in the database, generating a notification that the request for access may be forged.

4 . The method of claim 3 , further comprising the steps of:

retrieving a plurality of predefined rules from a data store upon detection of a forged authentication attribute; and

executing commands as dictated in each retrieved predefined rule.

Assignments (6)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY DATA PREVIOUSLY RECORDED ON REEL 064412 FRAME 0517. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 18, 2024
From: CRABTREE, JASON; KELLEY, RICHARD
To: QOMPLX, INC.
Reel/Frame 066342/0885 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2023
From: CRABTREE, JASON; KELLY, RICHARD
To: QOMPLX, INC.
Reel/Frame 064412/0517 →