IP Library Granted Patent US 12,375,475
Granted Patent B2
US 12,375,475 · App. 18/699,540 · Granted Jul 29, 2025

Confining lateral traversal within a computer network

Inventors: Jeromy Scott Statia (Arlington, WA); Jeffrey Ryan Bacon (Bellevue, WA); Darrin Earl Curtis (Everett, WA); Aaron Richard Davis (Bellevue, WA); Douglas Anthony Rasler (Sammamish, WA); Elizabeth Anne Phippen (Bothell, WA); Satish Devan (Redmond, WA); Bum Su Jung (Redmond, WA); Daniel James Dawson (Peirson, FL); George Kenneth Ringer (Mercer Island, WA)
Assignee: Microsoft Technology Licensing, LLC
H04L63/083G06F21/335G06F21/55H04L9/3213H04L9/40H04L63/0807H04L63/10H04L63/104H04L63/145G06F2221/2125
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,375,475
App. No.
18/699,540
Granted
Jul 29, 2025
Kind
B2
Abstract

Confining lateral traversal within a network. An authorization request identifies a credential, a protected first resource, and an identifier of a protected second resource for which authorization is requested. A lateral traversal policy associated with the second resource is identified, which constrains access to the second resource to only resources that belong to a subset of resources including the second resource. When it is determined that the credential is configured for access to the second resource, and when it is determined that the first resource belongs to the subset of resources including the second resource, an authorization token is issued, which authorizes the credential to access the second resource via the first resource. Alternatively, when it is determined that the credential is granted access to the second resource, and when it is determined that the first resource is outside of the particular subset of resources, the authorization request is denied.

Claims (47)

1. A method, implemented at a computer system that includes a processor, for confining lateral traversal within a computer network, the method comprising:

receiving an authorization request that includes (a) an authentication token that identifies a credential and a first protected resource within the computer network, and (b) an identifier of a second protected resource within the computer network for which authorization is requested;

determining, based on a capability of the credential, that the credential is configured for access to the second protected resource and is valid for accessing the second protected resource, wherein the capability of the credential is a group membership associated with the credential;

identifying a lateral traversal policy associated with the second protected resource, the lateral traversal policy:

defining the second protected resource to be part of a particular subset of resources to which the second protected resource belongs; and

constraining access to the second protected resource to only resources within the computer network that belong to the particular subset of resources to which the second protected resource belongs;

determining that the first protected resource does not belong to the particular subset of resources to which the second protected resource belongs; and

denying the authorization request based on the first protected resource not belonging to the particular subset of resources to which the second protected resource belongs, even though the credential is valid for accessing the second protected resource.

2. The method of claim 1 , further comprising logging denial of the authorization request, including logging the credential, the first protected resource, and the second protected resource.

3. The method of claim 1 , further comprising configuring a network to deny network communications from the first protected resource to the second protected resource.

4. The method of claim 1 , further comprising, prior to denying the authorization request, determining that no exception applies to a lateral traversal denial between the first protected resource and the second protected resource.

5. The method of claim 1 , wherein the authentication token is a ticket-granting ticket (TGT), and the authorization token is a client-to-server ticket issued by a ticket-granting service (TGS).

6. The method of claim 1 , wherein the credential is configured for access to the second protected resource just-in-time.

7. The method of claim 1 , wherein determining whether or not the first protected resource belongs to the particular subset of resources to which the second protected resource belongs comprises comparing a first subset membership attribute of the first protected resource with a second subset membership attribute of the second protected resource.

8. The method of claim 1 , wherein the authentication token also identifies one or more attributes of the first protected resource, and wherein the one or more attributes of the first protected resource are utilized for at least one of:

(a) the determining whether or not the credential is configured for access to the second protected resource, or

(b) the determining whether or not the first protected resource belongs to the particular subset of resources to which the second protected resource belongs.

9. The method of claim 1 , wherein the method further comprises determining the capability of the credential by performing a lookup in a directory.

10. A computer system for confining lateral traversal within a computer network, comprising:

a processor; and

a hardware storage device that stores computer-executable instructions that are executable by the processor to cause the computer system to at least:

receive an authorization request that includes (a) an authentication token that identifies a credential and a first protected resource within the computer network, and (b) an identifier of a second protected resource within the computer network for which authorization is requested;

determine, based on a capability of the credential, that the credential is configured for access to the second protected resource and is valid for accessing the second protected resource, wherein the capability of the credential is a group membership associated with the credential;

identify a lateral traversal policy associated with the second protected resource, the lateral traversal policy:

defining the second protected resource to be part of a particular subset of resources to which the second protected resource belongs; and

constraining access to the second protected resource to only resources within the computer network that belong to the particular subset of resources to which the second protected resource belongs;

determine that the first protected resource does not belong to the particular subset of resources to which the second protected resource belongs; and

deny the authorization request based on the first protected resource not belonging to the particular subset of resources to which the second protected resource belongs, even though the credential is valid for accessing the second protected resource.

11. The computer system of claim 10 , wherein the authentication token is a ticket-granting ticket (TGT), and the authorization token is a client-to-server ticket issued by a ticket-granting service (TGS).

12. The computer system of claim 10 , wherein the credential is configured for access to the second protected resource just-in-time.

13. The computer system of claim 10 , wherein the computer-executable instructions are also executable by the processor to cause the computer system to log denial of the authorization request, including logging the credential, the first protected resource, and the second protected resource.

14. The computer system of claim 10 , wherein the computer-executable instructions are also executable by the processor to cause the computer system to configure a network to deny network communications from the first protected resource to the second protected resource.

15. The computer system of claim 10 , wherein the computer-executable instructions are also executable by the processor to cause the computer system to, prior to denying the authorization request, determine that no exception applies to a lateral traversal denial between the first protected resource and the second protected resource.

16. The computer system of claim 10 , wherein determining whether or not the first protected resource belongs to the particular subset of resources to which the second protected resource belongs comprises comparing a first subset membership attribute of the first protected resource with a second subset membership attribute of the second protected resource.

17. The computer system of claim 10 , wherein the authentication token also identifies one or more attributes of the first protected resource, and wherein the one or more attributes of the first protected resource are utilized for at least one of:

(a) the determining whether or not the credential is configured for access to the second protected resource, or

(b) the determining whether or not the first protected resource belongs to the particular subset of resources to which the second protected resource belongs.

18. A computer readable hardware storage device that stores computer-executable instructions that are executable by a processor to cause a computer system to confine lateral traversal within a computer network, the computer-executable instructions including instructions that are executable by the processor to cause the computer system to at least:

receive an authorization request that includes (a) an authentication token that identifies a credential and a first protected resource within the computer network, and (b) an identifier of a second protected resource within the computer network for which authorization is requested;

determine, based on a capability of the credential, that the credential is configured for access to the second protected resource and is valid for accessing the second protected resource, wherein the capability of the credential is a group membership associated with the credential;

identify a lateral traversal policy associated with the second protected resource, the lateral traversal policy:

defining the second protected resource to be part of a particular subset of resources to which the second protected resource belongs; and

constraining access to the second protected resource to only resources within the computer network that belong to the particular subset of resources to which the second protected resource belongs;

determine that the first protected resource does not belong to the particular subset of resources to which the second protected resource belongs; and

deny the authorization request based on the first protected resource not belonging to the particular subset of resources to which the second protected resource belongs, even though the credential is valid for accessing the second protected resource.

19. The computer readable hardware storage device of claim 18 , wherein the instructions are also executable by the processor to cause the computer system to log denial of the authorization request, including logging the credential, the first protected resource, and the second protected resource.

20. The computer readable hardware storage device of claim 18 , wherein the instructions are also executable by the processor to cause the computer system to configure a network to deny network communications from the first protected resource to the second protected resource.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 17, 2024
From: STATIA, JEROMY SCOTT; BACON, JEFFREY RYAN; CURTIS, DARRIN EARL; DAVIS, AARON RICHARD; RASLER, DOUGLAS ANTHONY; PHIPPEN, ELIZABETH ANNE; DEVAN, SATISH; JUNG, BUM SU; DAWSON, DANIEL JAMES; RINGER, GEORGE KENNETH
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 067132/0903 →
Priority Claims (1)
LU 500755 · Oct 19, 2021 · national
Continuity (1)
Related Publication 20240267373A1 · Aug 8, 2024
References Cited (132)
US 8176533B1 · Violleau · 2012 [cited by examiner]
US 8544068B2 · Yates · 2013 [cited by applicant]
US 9185136B2 · Dulkin · 2015 [cited by examiner]
US 9264412B1 · Chao · 2016 [cited by examiner]
US 9412278B1 · Gong · 2016 [cited by examiner]
US 9591006B2 · Siva Kumar · 2017 [cited by examiner]
US 9716617B1 · Ahuja · 2017 [cited by examiner]
US 9787715B2 · Touboul · 2017 [cited by examiner]
US 9825978B2 · Siva Kumar · 2017 [cited by examiner]
US 10200369B1 · Roundy · 2019 [cited by examiner]
US 10225284B1 · Evans · 2019 [cited by examiner]
US 10333976B1 · Yudovich · 2019 [cited by examiner]
US 10333977B1 · Shamul · 2019 [cited by examiner]
US 10367835B1 · Raviv · 2019 [cited by examiner]
US 10419469B1 · Singh · 2019 [cited by examiner]
US 10958662B1 · Sole · 2021 [cited by examiner]
US 11134058B1 · Sole · 2021 [cited by examiner]
US 11323474B1 · Agrawal · 2022 [cited by examiner]
US 11368475B1 · Vashisht · 2022 [cited by examiner]
US 11425134B1 · Patimer · 2022 [cited by examiner]
US 11457040B1 · Sole · 2022 [cited by examiner]
US 11483339B1 · Kaimal · 2022 [cited by examiner]
US 11494046B2 · Han · 2022 [cited by examiner]
US 11831670B1 · Molls · 2023 [cited by examiner]
US 11985109B1 · Van Oort · 2024 [cited by examiner]
US 12001563B2 · Ross · 2024 [cited by examiner]
US 12003541B2 · Shulman · 2024 [cited by examiner]
US 20050149443A1 · Torvinen · 2005 [cited by examiner]
US 20070078574A1 · Davenport · 2007 [cited by examiner]
US 20090298316A1 · Maruyama · 2009 [cited by examiner]
US 20120074227A1 · Ferren · 2012 [cited by examiner]
US 20120280917A1 · Toksvig · 2012 [cited by examiner]
US 20130063611A1 · Papakipos · 2013 [cited by examiner]
US 20140059226A1 · Messerli et al. · 2014 [cited by applicant]
US 20140123228A1 · Brill · 2014 [cited by examiner]
US 20140123273A1 · Matus · 2014 [cited by examiner]
US 20140282871A1 · Rowland · 2014 [cited by examiner]
US 20150074615A1 · Han · 2015 [cited by examiner]
US 20150149042A1 · Cooper · 2015 [cited by examiner]
US 20150223890A1 · Miller · 2015 [cited by examiner]
US 20160065601A1 · Gong · 2016 [cited by examiner]
US 20160088000A1 · Siva Kumar · 2016 [cited by examiner]
US 20160294860A1 · Hathaway · 2016 [cited by examiner]
US 20160308884A1 · Kent · 2016 [cited by examiner]
US 20160359905A1 · Touboul · 2016 [cited by examiner]
US 20170126717A1 · Siva Kumar · 2017 [cited by examiner]
US 20170170973A1 · Gill · 2017 [cited by examiner]
US 20170289191A1 · Thioux · 2017 [cited by examiner]
US 20170337354A1 · Drey · 2017 [cited by examiner]
US 20180019802A1 · Teague · 2018 [cited by examiner]
US 20180088964A1 · Hussain · 2018 [cited by examiner]
US 20180097787A1 · Murthy · 2018 [cited by examiner]
US 20180097788A1 · Murthy · 2018 [cited by examiner]
US 20180097789A1 · Murthy · 2018 [cited by examiner]
US 20180115551A1 · Cole · 2018 [cited by examiner]
US 20180183766A1 · Crabtree · 2018 [cited by examiner]
US 20180191684A1 · Hoy · 2018 [cited by examiner]
US 20180234459A1 · Kung · 2018 [cited by examiner]
US 20180295154A1 · Crabtree · 2018 [cited by examiner]
US 20180337914A1 · Mohamad Abdul · 2018 [cited by examiner]
US 20180367548A1 · Stokes, III · 2018 [cited by examiner]
US 20190065739A1 · Manadhata · 2019 [cited by examiner]
US 20190065762A1 · Kim · 2019 [cited by examiner]
US 20190081963A1 · Waghorn · 2019 [cited by examiner]
US 20190089677A1 · Ashley · 2019 [cited by examiner]
US 20190089737A1 · Shayevitz · 2019 [cited by examiner]
US 20190097974A1 · Martz · 2019 [cited by examiner]
US 20190097977A1 · Martz · 2019 [cited by examiner]
US 20190098020A1 · Martz · 2019 [cited by examiner]
US 20190124112A1 · Thomas · 2019 [cited by examiner]
US 20190260751A1 · Kale · 2019 [cited by examiner]
US 20190297097A1 · Gong · 2019 [cited by examiner]
US 20190312836A1 · Phillips · 2019 [cited by examiner]
US 20190334928A1 · Sela · 2019 [cited by examiner]
US 20200050749A1 · Barboi · 2020 [cited by examiner]
US 20200052889A1 · Bendersky · 2020 [cited by examiner]
US 20200053096A1 · Bendersky · 2020 [cited by examiner]
US 20200104891A1 · Rule · 2020 [cited by examiner]
US 20200127994A1 · Kukreja · 2020 [cited by examiner]
US 20200145416A1 · Mitzimberg · 2020 [cited by examiner]
US 20200151611A1 · McGavran · 2020 [cited by examiner]
US 20200153846A1 · Srivastava · 2020 [cited by examiner]
US 20200236112A1 · Pularikkal · 2020 [cited by examiner]
US 20200252416A1 · Niv · 2020 [cited by examiner]
US 20200252422A1 · Davis · 2020 [cited by examiner]
US 20200280577A1 · Segal · 2020 [cited by examiner]
US 20200296139A1 · Fainberg · 2020 [cited by examiner]
US 20200322369A1 · Raghuramu · 2020 [cited by examiner]
US 20200356664A1 · Maor · 2020 [cited by examiner]
US 20200358804A1 · Crabtree · 2020 [cited by examiner]
US 20200358805A1 · Segal · 2020 [cited by examiner]
US 20210084073A1 · Crabtree · 2021 [cited by examiner]
US 20210112075A1 · Cunningham · 2021 [cited by examiner]
US 20210160237A1 · Rozner · 2021 [cited by examiner]
US 20210176260A1 · Pan · 2021 [cited by examiner]
US 20210211447A1 · Albero · 2021 [cited by examiner]
US 20210226982A1 · Marty · 2021 [cited by examiner]
US 20210226983A1 · Cunningham · 2021 [cited by examiner]
US 20210273957A1 · Boyer · 2021 [cited by examiner]
US 20210314250A1 · Laplante · 2021 [cited by examiner]
US 20210344723A1 · O'Neil · 2021 [cited by examiner]
US 20220006818A1 · Cunningham · 2022 [cited by examiner]
US 20220029962A1 · Teo · 2022 [cited by examiner]
US 20220058247A1 · Samineni · 2022 [cited by examiner]
US 20220060453A1 · Crabtree · 2022 [cited by examiner]
US 20220131901A1 · Akella · 2022 [cited by examiner]
US 20220159033A1 · Mizrahi · 2022 [cited by examiner]
US 20220200993A1 · Smith · 2022 [cited by examiner]
US 20220201041A1 · Keiser, Jr. · 2022 [cited by examiner]
US 20220239679A1 · Sircar · 2022 [cited by examiner]
US 20220263799A1 · Kaidi · 2022 [cited by examiner]
US 20220272117A1 · Maheve · 2022 [cited by examiner]
US 20220279045A1 · Movshovitz · 2022 [cited by examiner]
US 20220345457A1 · Jeffords · 2022 [cited by examiner]
US 20220368702A1 · Robbins · 2022 [cited by examiner]
US 20230018210A1 · Keiser, Jr. · 2023 [cited by examiner]
US 20230035189A1 · Mullin · 2023 [cited by examiner]
US 20230082699A1 · Voldsund · 2023 [cited by examiner]
EP 3422237A1 · 2019 [cited by applicant]
Johnson et al “A Graph Analytic Metric for Mitigating Advanced Persistent Threat,” IEEE, pp. 129-133 (Year: 2013). [cited by examiner]
Siadati et al “Detecting Malicious Logins in Enterprise Networks Using Visualization,” IEEE, pp. 1-8 (Year: 2016). [cited by examiner]
Al Hamin et al “Hidden Markov Model and Cyber Deception for the Prevention of Adversarial Lateral Movement,” IEEE, pp. 49662-49682 (Year: 2021). [cited by examiner]
Tian et al “Real-Time Lateral Movement Detection Based on Evidence Reasoning Network for Edge Computing Environment,” IEEE Transactions on Industrial Informatics, vol. 15, No. 7, pp. 4285-4294 (Year: 2019). [cited by examiner]
Tang et al “Policy-Based Network Access and Behavior Control Management,” 2020 IEEE 20th International Conference on Communication Technology, IEEE, pp. 1102-1106 (Year: 2020). [cited by examiner]
Zhi et al “Research on Policy-Based Access Control Model,” 2009 International Conference on Networks Security, Wireless Communications and Trusted Computing, IEEE Computer Society, pp. 164-167 (Year: 2009). [cited by examiner]
Yu et al “A Unifited Scheme for Resource Protection in Automated Trust Negotiation,” IEEE Computer Society, pp. 1-13 (Year: 2003). [cited by examiner]
Bowman et al “Detecting Lateral Movement in Enterprise Computer Networks with Unsupervised Graph AI,” pp. 257-268 (Year: 2020). [cited by examiner]
International Search Report and Written Opinion Issued in PCT Application No. PCT/US22/077966 (MS# 410539-WO-PCT), Mailed on Jan. 30, 2023, 14 Pages. [cited by applicant]
Jungles, et al., “Mitigating Pass-the-Hash (PtH) Attacks and Other Credential Theft Techniques”, Retrieved From: https://www.microsoft.com/en-in/download/details.aspx?id=36036, Jan. 1, 2012, 82 Pages. [cited by applicant]
Search Report Issued in Luxemburg Patent Application No. LU500755 (MS#410539-LU01), Jul. 7, 2022, 9 pages. [cited by applicant]
Communication Under Rule 71(3) EPC Received for European Application No. 22800977.5, (MS#410539-EP01-PCT) mailed on Jul. 17, 2024, 7 pages. [cited by applicant]
Decision to grant a European patent pursuant to Article 97(1) received in European Application No. 22800977.5, (MS# 410539-EP01-PCT) mailed on Nov. 21, 2024, 2 pages. [cited by applicant]