IP Library Granted Patent US 12,438,906
Granted Patent B2
US 12,438,906 · App. 18/639,954 · Granted Oct 7, 2025

Detecting KERBEROS ticket attacks within a domain

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO)
Assignee: QOMPLX LLC
H04L63/1441G06F16/2474H04L63/123H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,438,906
App. No.
18/639,954
Granted
Oct 7, 2025
Kind
B2
Abstract

A system and methods for mitigating authentication ticket attacks within a domain is provided, comprising an authentication object inspector configured to observe a new authentication object generated by an identity provider, and retrieve the new authentication object; and a hashing engine configured to retrieve the new authentication object from the authentication object inspector, calculate a cryptographic hash for the new authentication object, and store the cryptographic hash for the new authentication object in a data store; wherein subsequent access requests accompanied by authentication objects are validated by near-real-time comparison of hashes for each authentication object to previously-generated hashes.

Claims (66)

1. A system for detecting and mitigating ticket-based attacks within a domain, comprising:

a computing system comprising a memory and a processor;

an authentication object inspector comprising a first plurality of programming instructions stored in the memory which, when operating on the processor, causes the computing system to:

receive network traffic via a first network connection, the network traffic comprising at least a plurality of first authentication objects known to be generated by an identity provider associated with an authentication domain;

store a record of each received first authentication object, with attached metadata comprising a timestamp of when each first authentication object was received, in a time-series database;

compute a unique identifier of each first authentication object;

store the unique identifier of each first authentication object in a database of unique identifiers for the identity provider;

receive a request for access to a network resource within the authentication domain accompanied by a second authentication object;

compute a unique identifier of the second authentication object;

determine if the second unique identifier exists in the database of unique identifiers for the authentication provider; and

where the unique identifier of the second authentication object does not exist in the database of unique identifiers:

analyze a plurality of the stored first authentication objects to determine a plurality of compromised accounts;

generate an incident report comprising results of the analyses of the plurality of stored first authentication objects and the plurality of stored network traffic records; and

transmit the incident report via a second network connection that is not connected to, or visible to, to the identity provider;

wherein each unique identifier is a cryptographic hash generated by performing a plurality calculations and transformations on the respective authentication object.

2. The system of claim 1 , wherein the authentication object inspector is operated by the identity provider.

3. The system of claim 1 , wherein the authentication object inspector is operated by a client device communicating with the identity provider over a network.

4. A method for detecting and mitigating ticket-based attacks within a domain, comprising the steps of:

using an authentication object inspector operating on a computing device comprising a memory and a processor to:

receive network traffic via a first network connection, the network traffic comprising at least a plurality of first authentication objects known to be generated by an identity provider associated with an authentication domain;

store a record of each received first authentication object, with attached metadata comprising a timestamp of when each first authentication object was received, in a time-series database;

compute a unique identifier of each first authentication object;

store the unique identifier of each first authentication object in a database of unique identifiers for the identity provider;

receive a request for access to a network resource within the authentication domain accompanied by a second authentication object;

compute a unique identifier of the second authentication object;

determine if the second unique identifier exists in the database of unique identifiers for the authentication provider; and

where the unique identifier of the second authentication object does not exist in the database of unique identifiers:

analyze a plurality of the stored first authentication objects to determine a plurality of compromised accounts;

analyze a plurality of the stored network traffic records to determine a plurality of access paths;

generate an incident report comprising results of the analyses of the plurality of stored first authentication objects and the plurality of stored network traffic records; and

transmit the incident report via a second network connection that is not connected to, or visible to, to the identity provider;

wherein each unique identifier is a cryptographic hash generated by performing a plurality of calculations and transformations on the respective authentication object.

5. The method of claim 4 , wherein the authentication object inspector is operated by the identity provider.

6. The method of claim 4 , wherein the authentication object inspector is operated by a client device communicating with the identity provider over a network.

7. Non-transitory, computer-readable storage media having computer-executable instructions embodied thereon that, when executed by one or more processors of a computing system employing an asset registry platform for detecting and mitigating ticket-based attacks within a domain, cause the computing system to:

receive network traffic via a first network connection, the network traffic comprising at least a plurality of first authentication objects known to be generated by an identity provider associated with an authentication domain;

store a record of each received first authentication object, with attached metadata comprising a timestamp of when each first authentication object was received, in a time-series database;

compute a unique identifier of each first authentication object;

store the unique identifier of each first authentication object in a database of unique identifiers for the identity provider;

receive a request for access to a network resource within the authentication domain accompanied by a second authentication object;

compute a unique identifier of the second authentication object;

determine if the second unique identifier exists in the database of unique identifiers for the authentication provider; and

where the unique identifier of the second authentication object does not exist in the database of unique identifiers:

analyze a plurality of the stored first authentication objects to determine a plurality of compromised accounts;

analyze a plurality of the stored network traffic records to determine a plurality of access paths;

generate an incident report comprising results of the analyses of the plurality of stored first authentication objects and the plurality of stored network traffic records; and

transmit the incident report via a second network connection that is not connected to, or visible to, to the identity provider;

wherein each unique identifier is a cryptographic hash generated by performing a plurality of calculations and transformations on the respective authentication object.

8. The non-transitory, computer-readable storage media of claim 7 , wherein the authentication object inspector is operated by the identity provider.

9. The non-transitory, computer-readable storage media of claim 7 , wherein the authentication object inspector is operated by a client device communicating with the identity provider over a network.

10. A system for detecting and mitigating ticket-based attacks within a domain employing an asset registry platform, comprising one or more computers with executable instructions that, when executed, cause the system to:

receive network traffic via a first network connection, the network traffic comprising at least a plurality of first authentication objects known to be generated by an identity provider associated with an authentication domain;

store a record of each received first authentication object, with attached metadata comprising a timestamp of when each first authentication object was received, in a time-series database;

compute a unique identifier of each first authentication object;

store the unique identifier of each first authentication object in a database of unique identifiers for the identity provider;

receive a request for access to a network resource within the authentication domain accompanied by a second authentication object;

compute a unique identifier of the second authentication object;

determine if the second unique identifier exists in the database of unique identifiers for the authentication provider; and

where the unique identifier of the second authentication object does not exist in the database of unique identifiers:

analyze a plurality of the stored first authentication objects to determine a plurality of compromised accounts;

analyze a plurality of the stored network traffic records to determine a plurality of access paths;

generate an incident report comprising results of the analyses of the plurality of stored first authentication objects and the plurality of stored network traffic records; and

transmit the incident report via a second network connection that is not connected to, or visible to, to the identity provider;

wherein each unique identifier is a cryptographic hash generated by performing a plurality of calculations and transformations on the respective authentication object.

11. The system of claim 10 , wherein the authentication object inspector is operated by the identity provider.

12. The system of claim 10 , wherein the authentication object inspector is operated by a client device communicating with the identity provider over a network.

Assignments (3)
CHANGE OF NAME Recorded Jul 8, 2024
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 067930/0619 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 6, 2024
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 068969/0262 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 5, 2024
From: CRABTREE, JASON; SELLERS, ANDREW
To: QOMPLX, INC.
Reel/Frame 067920/0209 →
Continuity (20)
Continuation 18489003 · Oct 18, 2023
Continuation 17973520 · Oct 25, 2022
Continuation In Part 17169924 · Feb 8, 2021
Continuation 17170288 · Feb 8, 2021
Continuation In Part 15837845 · Dec 11, 2017
Continuation In Part 15825350 · Nov 29, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 14925974 · Oct 28, 2015
Provisional Application 62596105 · Dec 7, 2017
Related Publication 20240267402A1 · Aug 8, 2024
References Cited (48)
US 6256544B1 · Weissinger · 2001 [cited by applicant]
US 7281125B2 · Challener et al. · 2007 [cited by applicant]
US 7702821B2 · Feinberg et al. · 2010 [cited by applicant]
US 8601554B2 · Gordon et al. · 2013 [cited by applicant]
US 9137131B1 · Sarukkai et al. · 2015 [cited by applicant]
US 9203829B1 · Levine et al. · 2015 [cited by applicant]
US 9253643B2 · Pattar et al. · 2016 [cited by applicant]
US 9292692B2 · Wallrabenstein · 2016 [cited by applicant]
US 9602530B2 · Ellis et al. · 2017 [cited by applicant]
US 9652604B1 · Johansson et al. · 2017 [cited by applicant]
US 9853977B1 · Laucius · 2017 [cited by examiner]
US 10038559B2 · Burrows et al. · 2018 [cited by applicant]
US 10050787B1 · Johansson et al. · 2018 [cited by applicant]
US 10061635B2 · Ellwein · 2018 [cited by applicant]
US 10237259B2 · Ronda et al. · 2019 [cited by applicant]
US 10248910B2 · Crabtree et al. · 2019 [cited by applicant]
US 10367829B2 · Huang et al. · 2019 [cited by applicant]
US 10410214B2 · Doyle · 2019 [cited by applicant]
US 10628578B2 · Eksten et al. · 2020 [cited by applicant]
US 10645086B1 · Hadler · 2020 [cited by applicant]
US 11005824B2 · Crabtree et al. · 2021 [cited by applicant]
US 11005827B2 · Wang · 2021 [cited by examiner]
US 11329980B2 · Callahan et al. · 2022 [cited by applicant]
US 11570204B2 · Crabtree et al. · 2023 [cited by applicant]
US 11570209B2 · Crabtree · 2023 [cited by examiner]
US 11799900B2 · Crabtree · 2023 [cited by examiner]
US 11818169B2 · Crabtree · 2023 [cited by examiner]
US 11968227B2 · Crabtree · 2024 [cited by examiner]
US 20030041254A1 · Challener et al. · 2003 [cited by applicant]
US 20030145225A1 · Bruton, III et al. · 2003 [cited by applicant]
US 20050210255A1 · Kirovski · 2005 [cited by applicant]
US 20070036314A1 · Kloberdans et al. · 2007 [cited by applicant]
US 20070136821A1 · Hershaft et al. · 2007 [cited by applicant]
US 20070150744A1 · Cheng et al. · 2007 [cited by applicant]
US 20080021866A1 · Hinton et al. · 2008 [cited by applicant]
US 20090182672A1 · Doyle · 2009 [cited by applicant]
US 20110087888A1 · Rennie · 2011 [cited by applicant]
US 20110302412A1 · Deng et al. · 2011 [cited by applicant]
US 20130117831A1 · Hook et al. · 2013 [cited by applicant]
US 20150128258A1 · Novozhenets · 2015 [cited by applicant]
US 20150281225A1 · Schoen · 2015 [cited by examiner]
US 20150317481A1 · Gardner et al. · 2015 [cited by applicant]
US 20160072845A1 · Chiviendacz et al. · 2016 [cited by applicant]
US 20160275123A1 · Lin et al. · 2016 [cited by applicant]
US 20200014680A1 · Gujarathi · 2020 [cited by applicant]
US 20210099868A1 · Damlaj et al. · 2021 [cited by applicant]
WO 2014159150A1 · 2014 [cited by applicant]
WO 2017075543A1 · 2017 [cited by applicant]