IP Library Granted Patent US 12,401,664
Granted Patent B2
US 12,401,664 · App. 17/989,591 · Granted Aug 26, 2025

System and method for continuous collection, analysis and reporting of attack paths choke points in a directory services environment

Inventors: Andrew Robbins (Alexandria, VA); Rohan Vazarkar (Alexandria, VA); John Hopper (Alexandria, VA)
H04L63/1416G06F16/212
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,401,664
App. No.
17/989,591
Granted
Aug 26, 2025
Kind
B2
Abstract

A system and method for analyzing directory service environment attack path choke points for an enterprise may continuously collect data about the attack paths and provide alerts.

Claims (23)

1. An apparatus for analyzing choke points in a directory services system, the apparatus comprising:

a graph database that stores one or more continuously collected directory services data for one or more assets in a data center of an infrastructure of an enterprise that uses the directory services system to manage access permissions of the one or more assets to a critical directory services asset;

a computer system having a processor that executes a plurality of lines of instructions that configures the computer system to:

access the one or more continuously collected directory services data from the graph database;

perform a breadth search of the continuously collected directory services data to identify one or more choke points, wherein each choke points is an asset that has direct access to the critical directory services asset;

perform, for each particular choke points, a depth based search to determine a quantity of assets within an environment that are able to access the critical directory services asset using the particular choke point;

determine one or more choke points from the breadth and depth based searches;

build a dependency graph for each asset that can access Tier 0 critical directory services assets of the determined choke points, wherein the Tier 0 critical directory services assets represents highly critical assets and users within the environment;

perform a subsequent search using the dependency graph and if a preexisting reference is found, a shortcut to the preexisting reference is recorded;

identify one or more choke points based on the recorded preexisting reference; and

reidentify the one or more choke points in response to a modification of the directory services system.

2. The apparatus of claim 1 wherein the computer system is further configured to,

analyze, using the dependency graph, the choke points to determine how much of the environment can utilize each of the determined suspect access points to attack critical Directory Services assets.

3. The apparatus of claim 2 wherein the computer system is further configured to,

continue the search using the dependency graph until completion, for each of the determined suspect access points that are connected to Tier 0 critical directory services assets.

4. The apparatus of claim 1 wherein the computer system is further configured to,

compile references in dependency order to procure access cardinality for each traversed asset.

5. The apparatus of claim 4 wherein the computer system is further configured to,

generate a list of the one or more determined suspect access points and a risk assessment percentage number using the cardinality for each traversed asset.

6. The apparatus of claim 5 wherein the computer system is further configured to,

identify and list the suspect access points with a highest risk assessment percentage as the one or more choke points.

7. The apparatus of claim 1 , wherein the directory services system is one of a distributed directory services system.

8. The apparatus of claim 1 , wherein the one or more assets further comprises a domain controller, a domain computer and a security information and event system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 22, 2022
From: ROBBINS, ANDREW; VAZARKAR, ROHAN; HOPPER, JOHN
To: SPECTER OPS, INC.
Reel/Frame 061854/0023 →
Continuity (4)
Continuation In Part 17473370 · Sep 13, 2021
Continuation In Part 17144789 · Jan 8, 2021
Continuation 16857039 · Apr 23, 2020
Related Publication 20230078044A1 · Mar 16, 2023
References Cited (25)
US 6574737B1 · Kingsford et al. · 2003 [cited by applicant]
US 9100430B1 · Seiver et al. · 2015 [cited by applicant]
US 11032298B1 · Robbins et al. · 2021 [cited by applicant]
US 11159556B2 · Gerber, Jr. · 2021 [cited by applicant]
US 11170334B1 · Orzechowski et al. · 2021 [cited by applicant]
US 11184385B2 · Hadar et al. · 2021 [cited by applicant]
US 20060021046A1 · Cook · 2006 [cited by applicant]
US 20130347116A1 · Flores et al. · 2013 [cited by applicant]
US 20150172309A1 · Zandani et al. · 2015 [cited by applicant]
US 20160088000A1 · Siva Kumar et al. · 2016 [cited by applicant]
US 20170093910A1 · Gukal et al. · 2017 [cited by applicant]
US 20170302685A1 · Ladnai et al. · 2017 [cited by applicant]
US 20170302691A1 · Singh et al. · 2017 [cited by applicant]
US 20180316704A1 · Joseph Durairaj et al. · 2018 [cited by applicant]
US 20190124104A1 · Apostolopoulos · 2019 [cited by applicant]
US 20190334928A1 · Sela et al. · 2019 [cited by applicant]
US 20200356664A1 · Maor · 2020 [cited by applicant]
US 20200358805A1 · Segal et al. · 2020 [cited by applicant]
US 20200396240A1 · Flaherty et al. · 2020 [cited by applicant]
US 20210021629A1 · Dani et al. · 2021 [cited by applicant]
US 20210099490A1 · Crabtree et al. · 2021 [cited by applicant]
US 20210110047A1 · Fang · 2021 [cited by applicant]
US 20210336971A1 · Robbins et al. · 2021 [cited by applicant]
“Active Directory Administrative Tier Model,” Microsoft Docs, Securing Privileged Access Reference Material, Feb. 14, 2019, 32 pages, Retrieved from URL: https://docs.microsoft.com/en-us/windows-server/identity/securing… [cited by applicant]
“GitHub-BloodHoundAD/BloodHound: Six Degrees of Domain Admin,” Apr. 23, 2020, 2 Pages, Retrieved from URL: https://github.com/BloodHoundAD/BloodHound. [cited by applicant]