IP Library Granted Patent US 12,506,715
Granted Patent B2
US 12,506,715 · App. 18/333,414 · Granted Dec 23, 2025

Network authentication toxicity assessment

Inventors: Jason Crabtree (Vienna, VA); Richard Kelley (Woodbridge, VA)
Assignee: QOMPLX LLC
H04L63/0428H04L9/3236H04L9/3239H04L63/0807H04L63/0815H04L63/1425H04L63/1433H04L63/145H04L9/0894H04L9/3213
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,506,715
App. No.
18/333,414
Granted
Dec 23, 2025
Kind
B2
Abstract

A system and method for scoring and enforcing authentication standards that actually enable zero trust network security principles when combined with stateful authentication object tracking, authentication object manipulation and forgery detection, and assessment of authentication and identity attack surface. The methodology involves gathering all authentication objects issued by a network, storing the authentication objects in a centralized location for use in stateful deterministic authentication object tracking, scoring the completeness of the authentication observations, assessing the quality of the authentication observations, and assigning organization-specific penalty functions.

Claims (58)

1 . A system for computer network authentication toxicity assessment, comprising:

a computing device comprising a memory, a processor, and a non-volatile data storage device;

a centralized authentication object database stored on the non-volatile data storage device;

an authentication object aggregator comprising a first plurality of programming instructions stored in the memory which, when operating on the processor, causes the computing device to:

gather authentication objects from one or more domain controllers; and

store the authentication objects in the centralized authentication object database; and

a scoring engine comprising a second plurality of programming instructions stored in the memory which, when operating on the processor, causes the computing device to:

determine the total amount of authentication objects gathered;

determine what portion of the authentication objects are bad authentication objects;

output a network toxicity report comprising the number of bad authentication objects as a proportion of the total amount of authentication objects gathered; and

where the proportion meets or exceeds a threshold, issue a warning to a network administrator that the network's toxicity has exceeded the threshold.

2 . The system of claim 1 , wherein the bad authentication objects comprise bad authentication objects selected from the list of known fraudulent authentication objects, suspected fraudulent bad authentication objects, and authentication objects issued by the New Technology LAN Manager (NTML) network security protocol.

3 . The system of claim 1 , wherein the scoring engine is further configured to perform a completeness analysis of the gathered objects comprising a determination of the number and type of authentication objects actually collected versus the number and type of authentication objects expected to be collected.

4 . The system of claim 1 , wherein the scoring engine is further configured to determine what proportion of authentication objects use a weak network security protocol or configuration.

5 . The system of claim 1 , wherein the scoring engine is further configured to apply organization-specific or network-specific bonuses and penalties to the network toxicity report.

6 . The system of claim 1 , wherein the authentication object aggregator is further configured to cause the computing device to:

receive a first authentication object requesting access to a first resource of the computer network;

identify the purported issuance of the first authentication object's from information contained in the first authentication object;

search the centralized authentication object database for a copy of the purported issuance for the first authentication object;

approve access to the first resource where the copy of the purported issuance is found in the centralized authentication object database; and

deny access to the first resource where the copy of the purported issuance is not found in the centralized authentication object database.

7 . The system of claim 1 , wherein the authentication object aggregator is further configured to:

store a complete record of every authentication object issued by the network in the centralized authentication object database;

track each presentation of an authentication object for access to network resources; and

deterministically identify forged authentication objects by detecting when a presented authentication object lacks a corresponding issuance record in the centralized authentication object database.

8 . The system of claim 1 , wherein the scoring engine employs stateful deterministic detection that verifies each authentication object against issuance records in the centralized authentication object database and heuristic detection that analyzes authentication patterns and behaviors to identify anomalous authentication activity.

9 . The system of claim 1 , wherein the scoring engine applies protocol-specific penalties when calculating the network toxicity report, comprising negative scoring for authentication objects using NTLM protocol, negative scoring for authentication objects using weak encryption including RC4, positive scoring for authentication objects using Kerberos with stateful validation, and positive scoring for authentication objects using SAML with stateful validation.

10 . The system of claim 1 , wherein the authentication object aggregator is further configured to continuously gather authentication objects in real-time as they are issued and used within the network wherein the centralized authentication object database maintains a real-time ledger of all valid authentication credentials and the scoring engine provides continuous monitoring of network toxicity levels to enable detection of authentication-based attacks.

11 . A method for computer network authentication toxicity assessment, comprising the steps of:

storing a centralized authentication object database stored on a non-volatile data storage device of a computing device comprising a memory, a processor, and the non-volatile data storage device;

using an authentication object aggregator operating on the computing device to:

gather authentication objects from one or more domain controllers; and

store the authentication objects in the centralized authentication object database; and

using a scoring engine operating on the computing device to:

determine the total amount of authentication objects gathered;

determine what portion of the authentication objects are bad authentication objects;

output a network toxicity report comprising the number of bad authentication objects as a proportion of the total amount of authentication objects gathered; and

where the proportion meets or exceeds a threshold, issue a warning to a network administrator that the network's toxicity has exceeded the threshold.

12 . The method of claim 11 , wherein the bad authentication objects comprise bad authentication objects selected from the list of known fraudulent authentication objects, suspected fraudulent bad authentication objects, and authentication objects issued by the New Technology LAN Manager (NTML) network security protocol.

13 . The method of claim 11 , further comprising the step of configuring the scoring to perform a completeness analysis of the gathered objects comprising a determination of the number and type of authentication objects actually collected versus the number and type of authentication objects expected to be collected.

14 . The method of claim 11 , further comprising the step of configuring the scoring engine to determine what proportion of authentication objects use a weak network security protocol or configuration.

15 . The method of claim 11 , further comprising the step of configuring the scoring to apply organization-specific or network-specific bonuses and penalties to the network toxicity report.

16 . The method of claim 11 , further comprising the step of configuring the authentication object aggregator to:

receive a first authentication object requesting access to a first resource of the computer network;

identify the purported issuance of the first authentication object's from information contained in the first authentication object;

search the centralized authentication object database for a copy of the purported issuance for the first authentication object;

approve access to the first resource where the copy of the purported issuance is found in the centralized authentication object database; and

deny access to the first resource where the copy of the purported issuance is not found in the centralized authentication object database.

17 . The method of claim 11 , further comprising the steps of configuring the authentication object aggregator to:

store a complete record of every authentication object issued by the network in the centralized authentication object database;

track each presentation of an authentication object for access to network resources; and

deterministically identify forged authentication objects by detecting when a presented authentication object lacks a corresponding issuance record in the centralized authentication object database.

18 . The method of claim 11 , wherein the scoring engine is further used to employ stateful deterministic detection that verifies each authentication object against issuance records in the centralized authentication object database and heuristic detection that analyzes authentication patterns and behaviors to identify anomalous authentication activity.

19 . The method of claim 11 , wherein the scoring engine is further used to apply protocol-specific penalties when calculating the network toxicity report, comprising negative scoring for authentication objects using NTLM protocol, negative scoring for authentication objects using weak encryption including RC4, positive scoring for authentication objects using Kerberos with stateful validation, and positive scoring for authentication objects using SAML with stateful validation.

20 . The method of claim 11 , further comprising:

continuously gathering authentication objects in real-time as they are issued and used within the network;

maintaining a real-time ledger of all valid authentication credentials in the centralized authentication object database; and

providing continuous monitoring of network toxicity levels using the scoring engine to enable detection of authentication-based attacks.

Assignments (6)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY DATA NAME: RICHARD KELLEY PREVIOUSLY RECORDED AT REEL: 064412 FRAME: 0673. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 18, 2024
From: CRABTREE, JASON; KELLEY, RICHARD
To: QOMPLX, INC.
Reel/Frame 066343/0764 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2023
From: CRABTREE, JASON; KELLY, RICHARD
To: QOMPLX, INC.
Reel/Frame 064412/0673 →
Continuity (55)
Continuation In Part 18297500 · Apr 7, 2023
Continuation In Part 18169203 · Feb 14, 2023
Continuation In Part 17986850 · Nov 14, 2022
Continuation In Part 17683242 · Feb 28, 2022
Continuation In Part 17567060 · Dec 31, 2021
Continuation In Part 17389863 · Jul 30, 2021
Continuation In Part 17245162 · Apr 30, 2021
Continuation In Part 17169924 · Feb 8, 2021
Continuation In Part 17170288 · Feb 8, 2021
Continuation In Part 17105025 · Nov 25, 2020
Continuation In Part 17102561 · Nov 24, 2020
Continuation In Part 16896764 · Jun 9, 2020
Continuation 16836717 · Mar 31, 2020
Continuation 16792754 · Feb 17, 2020
Continuation In Part 16779801 · Feb 3, 2020
Continuation In Part 16777270 · Jan 30, 2020
Continuation In Part 16720383 · Dec 19, 2019
Continuation 16191054 · Nov 14, 2018
Continuation In Part 15887496 · Feb 2, 2018
Continuation In Part 15837845 · Dec 11, 2017
Continuation 15837845 · Dec 11, 2017
Continuation In Part 15825350 · Nov 29, 2017
Continuation 15823363 · Nov 27, 2017
Continuation In Part 15823285 · Nov 27, 2017
Continuation In Part 15818733 · Nov 20, 2017
Continuation 15790457 · Oct 23, 2017
Continuation In Part 15790327 · Oct 23, 2017
Continuation In Part 15788718 · Oct 19, 2017
Continuation In Part 15788002 · Oct 19, 2017
Continuation In Part 15787601 · Oct 18, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 14925974 · Oct 28, 2015
Provisional Application 62596105 · Dec 7, 2017
Provisional Application 62568298 · Oct 4, 2017
Provisional Application 62568312 · Oct 4, 2017
Provisional Application 62568305 · Oct 4, 2017
Provisional Application 62568291 · Oct 4, 2017
Provisional Application 62568307 · Oct 4, 2017
Related Publication 20230362141A1 · Nov 9, 2023
References Cited (83)
US 5669000A · Jessen et al. · 1997 [cited by applicant]
US 6256544B1 · Weissinger · 2001 [cited by applicant]
US 6477572B1 · Elderton et al. · 2002 [cited by applicant]
US 7739653B2 · Venolia · 2010 [cited by applicant]
US 8006303B1 · Dennerline et al. · 2011 [cited by applicant]
US 8132260B1 · Mayer et al. · 2012 [cited by applicant]
US 8516594B2 · Bennett et al. · 2013 [cited by applicant]
US 8516596B2 · Sandoval et al. · 2013 [cited by applicant]
US 8583639B2 · Chitnis et al. · 2013 [cited by applicant]
US 8595240B1 · Otey et al. · 2013 [cited by applicant]
US 8677473B2 · Dennerline et al. · 2014 [cited by applicant]
US 8725597B2 · Mauseth et al. · 2014 [cited by applicant]
US 8726393B2 · Macy et al. · 2014 [cited by applicant]
US 8949960B2 · Berkman et al. · 2015 [cited by applicant]
US 9141360B1 · Chen et al. · 2015 [cited by applicant]
US 9210185B1 · Wood et al. · 2015 [cited by applicant]
US 9306965B1 · Grossman et al. · 2016 [cited by applicant]
US 9319430B2 · Bell, Jr. et al. · 2016 [cited by applicant]
US 9602530B2 · Ellis et al. · 2017 [cited by applicant]
US 9672355B2 · Titonis et al. · 2017 [cited by applicant]
US 9712553B2 · Nguyen et al. · 2017 [cited by applicant]
US 9774616B2 · Flores et al. · 2017 [cited by applicant]
US 10061635B2 · Ellwein · 2018 [cited by applicant]
US 10185832B2 · Cam · 2019 [cited by applicant]
US 10210470B2 · Ray · 2019 [cited by applicant]
US 10212184B2 · Sweeney et al. · 2019 [cited by applicant]
US 10248910B2 · Crabtree et al. · 2019 [cited by applicant]
US 10320828B1 · Derbeko et al. · 2019 [cited by applicant]
US 10367829B2 · Huang et al. · 2019 [cited by applicant]
US 10462112B1 · Makmel et al. · 2019 [cited by applicant]
US 11005824B2 · Crabtree et al. · 2021 [cited by applicant]
US 20030041254A1 · Challener · 2003 [cited by examiner]
US 20030145225A1 · Bruton et al. · 2003 [cited by applicant]
US 20050289072A1 · Sabharwal · 2005 [cited by applicant]
US 20070036314A1 · Kloberdans et al. · 2007 [cited by applicant]
US 20070150744A1 · Cheng et al. · 2007 [cited by applicant]
US 20080270203A1 · Holmes et al. · 2008 [cited by applicant]
US 20090182672A1 · Doyle · 2009 [cited by examiner]
US 20090199002A1 · Erickson · 2009 [cited by applicant]
US 20090222562A1 · Liu et al. · 2009 [cited by applicant]
US 20100125900A1 · Dennerline et al. · 2010 [cited by applicant]
US 20110087888A1 · Rennie · 2011 [cited by applicant]
US 20110185432A1 · Sandoval et al. · 2011 [cited by applicant]
US 20110302640A1 · Liu et al. · 2011 [cited by applicant]
US 20120137367A1 · Dupont et al. · 2012 [cited by applicant]
US 20120266244A1 · Green et al. · 2012 [cited by applicant]
US 20130055404A1 · Khalili · 2013 [cited by applicant]
US 20130097706A1 · Titonis et al. · 2013 [cited by applicant]
US 20130219472A1 · Hsu · 2013 [cited by examiner]
US 20130347116A1 · Flores et al. · 2013 [cited by applicant]
US 20140156806A1 · Karpistsenko et al. · 2014 [cited by applicant]
US 20140279762A1 · Xaypanya et al. · 2014 [cited by applicant]
US 20150149979A1 · Talby et al. · 2015 [cited by applicant]
US 20150169294A1 · Brock et al. · 2015 [cited by applicant]
US 20150195192A1 · Vasseur et al. · 2015 [cited by applicant]
US 20150281225A1 · Schoen · 2015 [cited by examiner]
US 20150317481A1 · Gardner et al. · 2015 [cited by applicant]
US 20150365437A1 · Bell, Jr. et al. · 2015 [cited by applicant]
US 20150379424A1 · Dirac et al. · 2015 [cited by applicant]
US 20160004858A1 · Chen et al. · 2016 [cited by applicant]
US 20160028758A1 · Ellis et al. · 2016 [cited by applicant]
US 20160072845A1 · Chiviendacz et al. · 2016 [cited by applicant]
US 20160078361A1 · Brueckner et al. · 2016 [cited by applicant]
US 20160099960A1 · Gerritz et al. · 2016 [cited by applicant]
US 20160275123A1 · Lin et al. · 2016 [cited by applicant]
US 20160364307A1 · Garg et al. · 2016 [cited by applicant]
US 20170019678A1 · Kim et al. · 2017 [cited by applicant]
US 20170032130A1 · Durairaj et al. · 2017 [cited by applicant]
US 20170034133A1 · Korondi · 2017 [cited by examiner]
US 20170126712A1 · Crabtree et al. · 2017 [cited by applicant]
US 20170139763A1 · Ellwein · 2017 [cited by applicant]
US 20170149802A1 · Huang et al. · 2017 [cited by applicant]
US 20170193110A1 · Crabtree et al. · 2017 [cited by applicant]
US 20170279844A1 · Bower, III et al. · 2017 [cited by applicant]
US 20170322959A1 · Tidwell et al. · 2017 [cited by applicant]
US 20170323089A1 · Duggal et al. · 2017 [cited by applicant]
US 20180288087A1 · Hittel et al. · 2018 [cited by applicant]
US 20180300930A1 · Kennedy et al. · 2018 [cited by applicant]
US 20190082305A1 · Proctor · 2019 [cited by applicant]
US 20200235935A1 · Cerna, Jr. · 2020 [cited by applicant]
CN 105302532B · 2018 [cited by applicant]
WO 2014159150A1 · 2014 [cited by applicant]
WO 2017075543A1 · 2017 [cited by applicant]