IP Library › Granted Patent US 12,273,357
Granted Patent B2
US 12,273,357 · App. 18/888,947 · Granted Apr 8, 2025

System and method for detecting lateral movement using SSH private keys

Inventors: Avi Tal Lichtenstein (Tel Aviv, IL); Ami Luttwak (Binyamina, IL); Yinon Costica (Tel Aviv, IL)
Assignee: Wiz, Inc.
H04L63/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,273,357
App. No.
18/888,947
Granted
Apr 8, 2025
Kind
B2
Abstract

A system and method for detecting lateral movement based on an exposed cryptographic network protocol (CNP) key in a cloud computing environment. The method includes: inspecting a first workload for a private CNP key, the private CNP key associated with a hash of a public CNP key; detecting in a security database a representation of the public CNP key; generating a lateral movement path, the lateral movement path including an identifier of a second workload, the second workload represented by a representation connected to the representation of the public CNP key.

Claims (67)

1. A method for detecting lateral movement based on an exposed cryptographic network protocol (CNP) key in a cloud computing environment, comprising:

inspecting a first workload for a private CNP key, the private CNP key associated with a hash of a public CNP key;

detecting a user identifier associated with the private CNP key;

detecting in a security database a representation of the public CNP key;

detecting in the security database a representation of a second workload connected to the representation of a second private CNP key; and

generating a lateral movement path, the lateral movement path including an identifier of the second workload, in response to detecting that the representation of the second private CNP key is connected to the representation of the public CNP key; and

generating a visual graph based on the generated lateral movement path and the detected user identifier.

2. The method of claim 1 , further comprising:

generating in the security database a representation of any one of: the private CNP key, the public CNP key, the first workload, the user identifier, and a combination thereof.

3. The method of claim 1 , further comprising:

storing in the representation of the private CNP key a hash of the private CNP key.

4. The method of claim 1 , further comprising:

determining that the hash of the public CNP key associated with the private CNP key matches a public key hash represented in the security database by a public CNP key node.

5. The method of claim 4 , further comprising:

determining that the hash of the public CNP key associated with the private CNP key matches the public CNP key hash.

6. The method of claim 5 , further comprising:

connecting in the security database the representation of the private CNP key to the representation of the public CNP key in response to determining that hash of the public CNP key associated with the private CNP key matches the public CNP key hash.

7. The method of claim 1 , further comprising:

detecting that the private CNP key is stored as any one of: cleartext, and plaintext.

8. The method of claim 1 , wherein the workload is a secure shell (SSH) server deployed in a cloud computing environment.

9. The method of claim 1 , wherein the private CNP key is stored in any one of: a PKCS format, or an OpenSSH format.

10. The method of claim 1 , further comprising:

generating a user representation representing a user account associated with the user identifier in the security database; and

connecting the user representation to the representation of the private CNP key.

11. The method of claim 1 , wherein the second workload is exposed to a network external to the cloud computing environment.

12. The method of claim 11 , further comprising:

determining that the private CNP key is exposed, in response to detecting that the second workload is exposed to the network.

13. A non-transitory computer-readable medium storing a set of instructions for detecting lateral movement based on an exposed cryptographic network protocol (CNP) key in a cloud computing environment, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a device, cause the device to:

inspect a first workload for a private CNP key, the private CNP key associated with a hash of a public CNP key;

detect a user identifier associated with the private CNP key;

detect in a security database a representation of the public CNP key;

detect in the security database a representation of a second workload connected to the representation of a second private CNP key; and

generate a lateral movement path, the lateral movement path including an identifier of the second workload, in response to detecting that the representation of the second private CNP key is connected to the representation of the public CNP key; and

generate a visual graph based on the generated lateral movement path and the detected user identifier.

14. A system for detecting lateral movement based on an exposed cryptographic network protocol (CNP) key in a cloud computing environment comprising:

a processing circuitry;

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

inspect a first workload for a private CNP key, the private CNP key associated with a hash of a public CNP key;

detect a user identifier associated with the private CNP key;

detect in a security database a representation of the public CNP key;

detect in the security database a representation of a second workload connected to the representation of a second private CNP key; and

generate a lateral movement path, the lateral movement path including an identifier of the second workload, in response to detecting that the representation of the second private CNP key is connected to the representation of the public CNP key; and

generate a visual graph based on the generated lateral movement path and the detected user identifier.

15. The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate in the security database a representation of any one of:

the private CNP key, the public CNP key, the first workload, the user identifier, and a combination thereof.

16. The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

store in the representation of the private CNP key a hash of the private CNP key.

17. The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

determine that the hash of the public CNP key associated with the private CNP key matches a public key hash represented in the security database by a public CNP key node.

18. The system of claim 17 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

determine that the hash of the public CNP key associated with the private CNP key matches the public CNP key hash.

19. The system of claim 18 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

connect in the security database the representation of the private CNP key to the representation of the public CNP key in response to determining that hash of the public CNP key associated with the private CNP key matches the public CNP key hash.

20. The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect that the private CNP key is stored as any one of:

cleartext, and plaintext.

21. The system of claim 14 , wherein the workload is a secure shell (SSH) server deployed in a cloud computing environment.

22. The system of claim 14 , wherein the private CNP key is stored in any one of:

a PKCS format, or an OpenSSH format.

23. The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate a user representation representing a user account associated with the user identifier in the security database; and

connect the user representation to the representation of the private CNP key.

24. The system of claim 14 , wherein the second workload is exposed to a network external to the cloud computing environment.

25. The system of claim 24 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

determine that the private CNP key is exposed, in response to detecting that the second workload is exposed to the network.

Continuity (7)
Continuation 18887706 · Sep 17, 2024
Continuation 18798397 · Aug 8, 2024
Continuation 18588981 · Feb 27, 2024
Continuation 18457752 · Aug 29, 2023
Continuation 17657495 · Mar 31, 2022
Provisional Application 63170123 · Apr 2, 2021
Related Publication 20250016175A1 · Jan 9, 2025
References Cited (35)
US 8595822B2 · Schrecker et al. · 2013 [cited by applicant]
US 8984610B2 · Spiers · 2015 [cited by examiner]
US 9825978B2 · Siva Kumar et al. · 2017 [cited by applicant]
US 10397185B1 · Sandholm et al. · 2019 [cited by applicant]
US 10476898B2 · Muddu et al. · 2019 [cited by applicant]
US 10691480B2 · Do · 2020 [cited by examiner]
US 11184392B2 · Thomas et al. · 2021 [cited by applicant]
US 11258590B1 · Tsarfati et al. · 2022 [cited by applicant]
US 11606378B1 · Delpont · 2023 [cited by examiner]
US 11799874B1 · Lichtenstein · 2023 [cited by examiner]
US 11811786B1 · Lichtenstein · 2023 [cited by examiner]
US 11811787B1 · Lichtenstein · 2023 [cited by examiner]
US 11916926B1 · Lichtenstein · 2024 [cited by examiner]
US 12095776B2 · Lichtenstein · 2024 [cited by examiner]
US 20020161996A1 · Koved · 2002 [cited by examiner]
US 20140059541A1 · Heninger et al. · 2014 [cited by applicant]
US 20140075013A1 · Agrawal et al. · 2014 [cited by applicant]
US 20140089658A1 · Raghuram et al. · 2014 [cited by applicant]
US 20150121078A1 · Fu et al. · 2015 [cited by applicant]
US 20160127353A1 · Thomas · 2016 [cited by examiner]
US 20170026355A1 · Mathaiyan · 2017 [cited by examiner]
US 20180367548A1 · Stokes, III · 2018 [cited by examiner]
US 20190297112A1 · Yu · 2019 [cited by examiner]
US 20200177617A1 · Hadar · 2020 [cited by examiner]
US 20200177619A1 · Hadar · 2020 [cited by examiner]
US 20200267552A1 · Lee et al. · 2020 [cited by applicant]
US 20200356664A1 · Maor · 2020 [cited by examiner]
US 20210051137A1 · Ruiz · 2021 [cited by examiner]
US 20210120026A1 · Kondaveeti · 2021 [cited by examiner]
US 20210203684A1 · Maor · 2021 [cited by examiner]
US 20220060509A1 · Crabtree · 2022 [cited by examiner]
US 20220345483A1 · Shua · 2022 [cited by examiner]
US 20230011957A1 · Panse et al. · 2023 [cited by applicant]
US 20230164164A1 · Herzberg · 2023 [cited by examiner]
US 20230421573A1 · Lichtenstein · 2023 [cited by examiner]