首页> 外国专利> ADVANCED DETECTION OF IDENTITY-BASED ATTACKS TO ASSURE IDENTITY FIDELITY IN INFORMATION TECHNOLOGY ENVIRONMENTS

ADVANCED DETECTION OF IDENTITY-BASED ATTACKS TO ASSURE IDENTITY FIDELITY IN INFORMATION TECHNOLOGY ENVIRONMENTS

机译:基于身份的攻击的高级检测,以确保信息技术环境中的身份保真度

摘要

A system and method for the detection and mitigation of Kerberos golden ticket, silver ticket, and related identity-based cyberattacks by passively monitoring and analyzing Kerberos and authentication operations within the network. The system and method provide real-time detections of identity attacks using time-series data and data pipelines, and by transforming the stateless Kerberos protocol into stateful protocol. A packet capturing agent is deployed on the network where captured time-series Kerberos and related event and log information is processed in distributed computational graph (DCG) stages where declarative rules determine if an attack is being carried out and what type of attack it is.
机译:通过被动监视和分析网络内的kerberos和认证操作,通过被动监视和分析基于Kerberos Golditic票证,银票和基于相关的身份的网络攻击的系统和方法。系统和方法使用时间序列数据和数据流水线进行实时检测身份攻击,以及将无状态Kerberos协议转换为有状态协议。数据包捕获代理部署在网络上,其中捕获的时间序列Kerberos和相关事件和日志信息在分布式计算图(DCG)阶段中处理,其中声明性规则确定是否正在执行攻击以及它是什么类型的攻击。

著录项

  • 公开/公告号US2021084073A1

    专利类型

  • 公开/公告日2021-03-18

    原文格式PDF

  • 申请/专利权人 QOMPLX INC.;

    申请/专利号US202017000504

  • 发明设计人 JASON CRABTREE;ANDREW SELLERS;

    申请日2020-08-24

  • 分类号H04L29/06;G06F16/951;G06F16/2458;

  • 国家 US

  • 入库时间 2022-08-24 17:46:07

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号